fix(deploy): align vector bootstrap identity policy
This commit is contained in:
@@ -32,6 +32,7 @@ export THT_VECTOR_READER_PASSWORD_SECRET_FILE="$secret_dir/reader"
|
||||
export THT_VECTOR_WRITER_PASSWORD_SECRET_FILE="$secret_dir/writer"
|
||||
export THT_VECTOR_READER_PASSWORD="smoke-reader-${smoke_project}"
|
||||
export THT_VECTOR_WRITER_PASSWORD="smoke-writer-${smoke_project}"
|
||||
export THT_VECTOR_BOOTSTRAP_USER=thoth_bootstrap_smoke
|
||||
export THOTH_SMOKE_OWNER="$smoke_owner"
|
||||
|
||||
compose() {
|
||||
@@ -167,7 +168,7 @@ migration_status=$(compose run --rm --no-deps vector-migrate)
|
||||
printf '%s\n' "$migration_status" | grep -q '"pending": \[\]'
|
||||
migrator_flags=$(compose run --rm --no-deps --entrypoint sh vector-reconcile -ec '
|
||||
export PGPASSWORD=$(cat /run/secrets/vector_bootstrap_password)
|
||||
psql -At --host vector-db --username postgres --dbname thoth \
|
||||
psql -At --host vector-db --username "$THT_VECTOR_BOOTSTRAP_USER" --dbname thoth \
|
||||
--command "SELECT (NOT rolcreaterole) AND (NOT rolcreatedb) AND (NOT rolsuper) FROM pg_roles WHERE rolname = '\''thoth_vector_migrator'\''"
|
||||
')
|
||||
test "$migrator_flags" = t
|
||||
@@ -199,6 +200,20 @@ old_bootstrap_password=$(cat "$secret_dir/bootstrap")
|
||||
printf '%s' "wrong-bootstrap-${smoke_project}" >"$secret_dir/bootstrap-wrong"
|
||||
printf '%s' "next-bootstrap-'quoted-${smoke_project}" >"$secret_dir/bootstrap-next"
|
||||
cp "$secret_dir/bootstrap" "$secret_dir/bootstrap-before-negative"
|
||||
printf 'invalid bootstrap password\n' >"$secret_dir/bootstrap-whitespace"
|
||||
if COMPOSE_PROJECT_NAME="$smoke_project" \
|
||||
./scripts/vector-rotate-bootstrap-password.sh \
|
||||
"$secret_dir/bootstrap" "$secret_dir/bootstrap-whitespace" \
|
||||
>/dev/null 2>&1; then
|
||||
echo "bootstrap rotation accepted whitespace in a secret" >&2
|
||||
exit 1
|
||||
fi
|
||||
cmp "$secret_dir/bootstrap" "$secret_dir/bootstrap-before-negative"
|
||||
compose run --rm --no-deps --entrypoint psql \
|
||||
-e PGPASSWORD="$old_bootstrap_password" vector-reconcile \
|
||||
--host vector-db --username "$THT_VECTOR_BOOTSTRAP_USER" --dbname thoth \
|
||||
--command 'SELECT 1' >/dev/null
|
||||
|
||||
if COMPOSE_PROJECT_NAME="$smoke_project" \
|
||||
./scripts/vector-rotate-bootstrap-password.sh \
|
||||
"$secret_dir/bootstrap-wrong" "$secret_dir/bootstrap-next" \
|
||||
@@ -215,14 +230,14 @@ new_bootstrap_password=$(cat "$secret_dir/bootstrap")
|
||||
test "$new_bootstrap_password" != "$old_bootstrap_password"
|
||||
if compose run --rm --no-deps --entrypoint psql \
|
||||
-e PGPASSWORD="$old_bootstrap_password" vector-reconcile \
|
||||
--host vector-db --username postgres --dbname thoth --command 'SELECT 1' \
|
||||
--host vector-db --username "$THT_VECTOR_BOOTSTRAP_USER" --dbname thoth --command 'SELECT 1' \
|
||||
>/dev/null 2>&1; then
|
||||
echo "old bootstrap credential still works after rotation" >&2
|
||||
exit 1
|
||||
fi
|
||||
compose run --rm --no-deps --entrypoint psql \
|
||||
-e PGPASSWORD="$new_bootstrap_password" vector-reconcile \
|
||||
--host vector-db --username postgres --dbname thoth --command 'SELECT 1' \
|
||||
--host vector-db --username "$THT_VECTOR_BOOTSTRAP_USER" --dbname thoth --command 'SELECT 1' \
|
||||
>/dev/null
|
||||
compose run --rm vector-reconcile
|
||||
bootstrap_rotation_status=$(compose run --rm --no-deps vector-migrate)
|
||||
|
||||
Reference in New Issue
Block a user