fix(deploy): align vector bootstrap identity policy
This commit is contained in:
@@ -20,6 +20,7 @@ THT_VEC_WRITE_API_KEY=
|
||||
|
||||
# Optional local-vector profile. Keep these secret files outside Git and readable by Docker.
|
||||
THT_VECTOR_DATABASE=thoth
|
||||
THT_VECTOR_BOOTSTRAP_USER=postgres
|
||||
THT_VECTOR_MIGRATOR_USER=thoth_vector_migrator
|
||||
THT_VECTOR_READER_USER=thoth_vector_reader
|
||||
THT_VECTOR_WRITER_USER=thoth_vector_writer
|
||||
|
||||
@@ -33,5 +33,10 @@ authentication or new-login verification fails, it exits without changing the de
|
||||
verification failure also attempts to restore the old database password over the still-open
|
||||
authenticated connection. After success, run the printed `vector-reconcile`/migration/core command.
|
||||
|
||||
`THT_VECTOR_BOOTSTRAP_USER` is authoritative for database initialization, reconciliation, and
|
||||
rotation; non-default bootstrap role names are supported. Bootstrap, migrator, reader, and writer
|
||||
secret files must be non-empty and contain no whitespace (including trailing newlines). Rotation
|
||||
rejects invalid files before contacting PostgreSQL or staging a deployment-file replacement.
|
||||
|
||||
Keep the staged new file on the same trusted host, mode `0600`, and retain a secure backup until the
|
||||
post-rotation reconciliation and application health checks pass.
|
||||
|
||||
@@ -1,19 +1,12 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
read_secret() {
|
||||
value=$(cat "/run/secrets/$1")
|
||||
if [ -z "$value" ] || printf '%s' "$value" | grep -q '[[:space:]]'; then
|
||||
echo "$1 must be non-empty and contain no whitespace" >&2
|
||||
exit 2
|
||||
fi
|
||||
printf '%s' "$value"
|
||||
}
|
||||
. /opt/thoth/secret-policy.sh
|
||||
|
||||
export PGPASSWORD=$(read_secret vector_bootstrap_password)
|
||||
migrator_password=$(read_secret vector_migrator_password)
|
||||
reader_password=$(read_secret vector_reader_password)
|
||||
writer_password=$(read_secret vector_writer_password)
|
||||
export PGPASSWORD=$(read_secret_file /run/secrets/vector_bootstrap_password vector_bootstrap_password)
|
||||
migrator_password=$(read_secret_file /run/secrets/vector_migrator_password vector_migrator_password)
|
||||
reader_password=$(read_secret_file /run/secrets/vector_reader_password vector_reader_password)
|
||||
writer_password=$(read_secret_file /run/secrets/vector_writer_password vector_writer_password)
|
||||
|
||||
psql --set=ON_ERROR_STOP=1 \
|
||||
--set=migrator_user="$THT_VECTOR_MIGRATOR_USER" \
|
||||
|
||||
@@ -12,9 +12,9 @@ from psycopg2 import sql
|
||||
|
||||
|
||||
def read_secret(path: str) -> str:
|
||||
value = Path(path).read_text().rstrip("\r\n")
|
||||
if not value or "\x00" in value:
|
||||
raise ValueError("secret must be non-empty and contain no NUL bytes")
|
||||
value = Path(path).read_text()
|
||||
if not value or "\x00" in value or any(character.isspace() for character in value):
|
||||
raise ValueError("secret must be non-empty and contain no whitespace or NUL bytes")
|
||||
return value
|
||||
|
||||
|
||||
|
||||
Executable
+19
@@ -0,0 +1,19 @@
|
||||
#!/bin/sh
|
||||
|
||||
validate_secret_file() {
|
||||
secret_path=$1
|
||||
secret_name=$2
|
||||
if [ ! -f "$secret_path" ] || [ ! -r "$secret_path" ] || [ ! -s "$secret_path" ]; then
|
||||
echo "$secret_name must be a readable, non-empty regular file" >&2
|
||||
return 2
|
||||
fi
|
||||
if LC_ALL=C grep -q '[[:space:]]' "$secret_path"; then
|
||||
echo "$secret_name must contain no whitespace" >&2
|
||||
return 2
|
||||
fi
|
||||
}
|
||||
|
||||
read_secret_file() {
|
||||
validate_secret_file "$1" "$2" || return
|
||||
cat "$1"
|
||||
}
|
||||
Reference in New Issue
Block a user