fix(auth): complete Task 13 deployment review

This commit is contained in:
2026-08-17 22:15:41 +02:00
parent 7e52df2702
commit 0d0c15b4b8
11 changed files with 228 additions and 50 deletions
+11 -1
View File
@@ -68,11 +68,20 @@ for (const serviceName of ["embedding", "embedding-model-init"]) {
throw new Error(`${serviceName} image must be pinned by version and digest`);
}
}
for (const serviceName of ["qdrant", "embedding", "embedding-model-init"]) {
for (const serviceName of ["embedding", "embedding-model-init"]) {
if ((config.services[serviceName].ports || []).length !== 0) {
throw new Error(`${serviceName} must not publish a host port`);
}
}
const qdrantPorts = config.services.qdrant.ports || [];
if (profile === "local") {
if (qdrantPorts.length !== 1 || qdrantPorts[0].host_ip !== "127.0.0.1"
|| Number(qdrantPorts[0].published) !== 6333 || Number(qdrantPorts[0].target) !== 6333) {
throw new Error("local qdrant may publish only 127.0.0.1:6333");
}
} else if (qdrantPorts.length !== 0) {
throw new Error("server qdrant must not publish a host port");
}
if ((config.services.qdrant.expose || []).join(",") !== "6333") throw new Error("qdrant must expose only 6333");
if ((config.services.embedding.expose || []).join(",") !== "11434") throw new Error("embedding must expose only 11434");
if (!config.services.qdrant.healthcheck) throw new Error("qdrant must define a healthcheck");
@@ -155,6 +164,7 @@ assert_remote_required() {
THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git \
PI_AUTH_FILE=/dev/null \
THT_SECRETS_FILE=/dev/null \
THT_AUTH_CONFIG_ROOT=/tmp/thothii-auth \
docker compose -f compose.yaml config --format json >"$tmp/base.json"
node - "$tmp/base.json" <<'NODE'
const fs = require("fs");
+3 -3
View File
@@ -428,7 +428,7 @@ EOF
chmod 0600 "$TASK13_OIDC_KEY"
chmod 0644 "$TASK13_OIDC_CERT"
cat >"$TASK13_OIDC_SERVER" <<'EOF'
import { createPublicKey, generateKeyPairSync } from "node:crypto";
import { generateKeyPairSync } from "node:crypto";
import { readFileSync } from "node:fs";
import https from "node:https";
@@ -436,7 +436,7 @@ const origin = "https://task13-fake-oidc:9443";
const issuer = `${origin}/application/o/task13/`;
const expectedToken = process.env.TASK13_AUTHENTIK_API_TOKEN;
const { publicKey } = generateKeyPairSync("rsa", { modulusLength: 2048 });
const jwk = { ...createPublicKey(publicKey).export({ format: "jwk" }), kid: "task13", use: "sig", alg: "RS256" };
const jwk = { ...publicKey.export({ format: "jwk" }), kid: "task13", use: "sig", alg: "RS256" };
const send = (response, status, body) => {
const payload = JSON.stringify(body);
response.writeHead(status, { "content-type": "application/json", "content-length": Buffer.byteLength(payload) });
@@ -1104,7 +1104,7 @@ task13_assert_server_runtime() {
status="$TASK13_TMP/server-auth-status.json"
task13_run_logged "server static OIDC status" "$TASK13_THT" --installation "$TASK13_INSTALLATION" auth status --json
"$TASK13_THT" --installation "$TASK13_INSTALLATION" auth status --json >"$status"
node -e 'const value=JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")); if(value.mode!=="oidc"||typeof value.configRevision!=="string"||value.configRevision.length!==64) process.exit(1)' "$status" \
node -e 'const value=JSON.parse(require("fs").readFileSync(process.argv[1], "utf8")); if(value.mode!=="oidc"||!/^sha256:[0-9a-f]{64}$/.test(value.configRevision)) process.exit(1)' "$status" \
|| task13_fail "server static OIDC status was not valid"
diagnostics="$TASK13_TMP/server-auth-diagnostics.json"
task13_run_logged "server live OIDC diagnostics" "$TASK13_THT" --installation "$TASK13_INSTALLATION" auth check --json