fix(auth): complete Task 13 deployment review
This commit is contained in:
@@ -68,11 +68,20 @@ for (const serviceName of ["embedding", "embedding-model-init"]) {
|
||||
throw new Error(`${serviceName} image must be pinned by version and digest`);
|
||||
}
|
||||
}
|
||||
for (const serviceName of ["qdrant", "embedding", "embedding-model-init"]) {
|
||||
for (const serviceName of ["embedding", "embedding-model-init"]) {
|
||||
if ((config.services[serviceName].ports || []).length !== 0) {
|
||||
throw new Error(`${serviceName} must not publish a host port`);
|
||||
}
|
||||
}
|
||||
const qdrantPorts = config.services.qdrant.ports || [];
|
||||
if (profile === "local") {
|
||||
if (qdrantPorts.length !== 1 || qdrantPorts[0].host_ip !== "127.0.0.1"
|
||||
|| Number(qdrantPorts[0].published) !== 6333 || Number(qdrantPorts[0].target) !== 6333) {
|
||||
throw new Error("local qdrant may publish only 127.0.0.1:6333");
|
||||
}
|
||||
} else if (qdrantPorts.length !== 0) {
|
||||
throw new Error("server qdrant must not publish a host port");
|
||||
}
|
||||
if ((config.services.qdrant.expose || []).join(",") !== "6333") throw new Error("qdrant must expose only 6333");
|
||||
if ((config.services.embedding.expose || []).join(",") !== "11434") throw new Error("embedding must expose only 11434");
|
||||
if (!config.services.qdrant.healthcheck) throw new Error("qdrant must define a healthcheck");
|
||||
@@ -155,6 +164,7 @@ assert_remote_required() {
|
||||
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git \
|
||||
PI_AUTH_FILE=/dev/null \
|
||||
THT_SECRETS_FILE=/dev/null \
|
||||
THT_AUTH_CONFIG_ROOT=/tmp/thothii-auth \
|
||||
docker compose -f compose.yaml config --format json >"$tmp/base.json"
|
||||
node - "$tmp/base.json" <<'NODE'
|
||||
const fs = require("fs");
|
||||
|
||||
@@ -428,7 +428,7 @@ EOF
|
||||
chmod 0600 "$TASK13_OIDC_KEY"
|
||||
chmod 0644 "$TASK13_OIDC_CERT"
|
||||
cat >"$TASK13_OIDC_SERVER" <<'EOF'
|
||||
import { createPublicKey, generateKeyPairSync } from "node:crypto";
|
||||
import { generateKeyPairSync } from "node:crypto";
|
||||
import { readFileSync } from "node:fs";
|
||||
import https from "node:https";
|
||||
|
||||
@@ -436,7 +436,7 @@ const origin = "https://task13-fake-oidc:9443";
|
||||
const issuer = `${origin}/application/o/task13/`;
|
||||
const expectedToken = process.env.TASK13_AUTHENTIK_API_TOKEN;
|
||||
const { publicKey } = generateKeyPairSync("rsa", { modulusLength: 2048 });
|
||||
const jwk = { ...createPublicKey(publicKey).export({ format: "jwk" }), kid: "task13", use: "sig", alg: "RS256" };
|
||||
const jwk = { ...publicKey.export({ format: "jwk" }), kid: "task13", use: "sig", alg: "RS256" };
|
||||
const send = (response, status, body) => {
|
||||
const payload = JSON.stringify(body);
|
||||
response.writeHead(status, { "content-type": "application/json", "content-length": Buffer.byteLength(payload) });
|
||||
@@ -1104,7 +1104,7 @@ task13_assert_server_runtime() {
|
||||
status="$TASK13_TMP/server-auth-status.json"
|
||||
task13_run_logged "server static OIDC status" "$TASK13_THT" --installation "$TASK13_INSTALLATION" auth status --json
|
||||
"$TASK13_THT" --installation "$TASK13_INSTALLATION" auth status --json >"$status"
|
||||
node -e 'const value=JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")); if(value.mode!=="oidc"||typeof value.configRevision!=="string"||value.configRevision.length!==64) process.exit(1)' "$status" \
|
||||
node -e 'const value=JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")); if(value.mode!=="oidc"||!/^sha256:[0-9a-f]{64}$/.test(value.configRevision)) process.exit(1)' "$status" \
|
||||
|| task13_fail "server static OIDC status was not valid"
|
||||
diagnostics="$TASK13_TMP/server-auth-diagnostics.json"
|
||||
task13_run_logged "server live OIDC diagnostics" "$TASK13_THT" --installation "$TASK13_INSTALLATION" auth check --json
|
||||
|
||||
Reference in New Issue
Block a user