From 12d257056fe8293d1f0e4e3e613feba41c5f76a7 Mon Sep 17 00:00:00 2001 From: mptyl Date: Wed, 26 Aug 2026 00:44:30 +0200 Subject: [PATCH] fix(deploy): project server session secrets in smoke --- scripts/unified-deployment-smoke.sh | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/scripts/unified-deployment-smoke.sh b/scripts/unified-deployment-smoke.sh index c2c58d5e..9e42c1f3 100755 --- a/scripts/unified-deployment-smoke.sh +++ b/scripts/unified-deployment-smoke.sh @@ -1031,19 +1031,24 @@ task13_prepare_local_application_secrets() { --entrypoint sh \ --volume "$TASK13_SECRETS:/source/thothii.secrets:ro" \ --volume "$TASK13_SESSION_RUNTIME_PASSWORD:/source/task13-runtime-password:ro" \ + --volume "$TASK13_SESSION_CA:/source/session_ca.pem:ro" \ --volume "$TASK13_APPLICATION_SECRETS_VOLUME:/target" \ "$TASK13_CORE_IMAGE" -ceu ' test -f /source/thothii.secrets && test ! -L /source/thothii.secrets test -f /source/task13-runtime-password && test ! -L /source/task13-runtime-password + test -f /source/session_ca.pem && test ! -L /source/session_ca.pem test -z "$(find /target -mindepth 1 -maxdepth 1 -print -quit)" - cp /source/thothii.secrets /source/task13-runtime-password /target/ + cp /source/thothii.secrets /source/task13-runtime-password /source/session_ca.pem /target/ + cp /source/task13-runtime-password /target/session_runtime_password chown 0:0 /target - chown 10001:10001 /target/thothii.secrets /target/task13-runtime-password + chown 10001:10001 /target/thothii.secrets /target/task13-runtime-password /target/session_runtime_password /target/session_ca.pem chmod 0755 /target - chmod 0600 /target/thothii.secrets /target/task13-runtime-password + chmod 0600 /target/thothii.secrets /target/task13-runtime-password /target/session_runtime_password /target/session_ca.pem test "$(stat -c "%u:%g:%a" /target)" = 0:0:755 test "$(stat -c "%u:%g:%a" /target/thothii.secrets)" = 10001:10001:600 test "$(stat -c "%u:%g:%a" /target/task13-runtime-password)" = 10001:10001:600 + test "$(stat -c "%u:%g:%a" /target/session_runtime_password)" = 10001:10001:600 + test "$(stat -c "%u:%g:%a" /target/session_ca.pem)" = 10001:10001:600 ' } @@ -2513,6 +2518,7 @@ task13_self_test_source_contract() { local auth_runtime_mount auth_root_mount auth_projection auth_runtime_owner local pi_auth_bind pi_projection registry_runtime_mount registry_root_mount registry_projection local application_secret_bind application_secret_mount application_secret_projection + local application_session_ca_source application_session_password_projection local application_secret_parent_owner application_secret_file_owner local image_evidence_environment image_evidence_initialization local server_auth_projection_override server_auth_projection_descriptor @@ -2537,7 +2543,9 @@ task13_self_test_source_contract() { application_secret_mount='application-secrets:/run/''secrets:ro' application_secret_projection='task13_prepare_local_application_''secrets' application_secret_parent_owner='chown 0:''0 /target' - application_secret_file_owner='chown 10001:''10001 /target/thothii.secrets /target/task13-runtime-password' + application_session_ca_source='$TASK13_SESSION_''CA:/source/session_ca.pem:ro' + application_session_password_projection='cp /source/task13-runtime-password /target/session_''runtime_password' + application_secret_file_owner='chown 10001:''10001 /target/thothii.secrets /target/task13-runtime-password /target/session_runtime_password /target/session_ca.pem' image_evidence_environment='TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}''/task13-images.json' image_evidence_initialization='TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/''.artifacts/task-15/unified-docker-images.json}"' server_auth_projection_override='deploy/compose.auth-runtime-''projection.yaml' @@ -2587,6 +2595,10 @@ task13_self_test_source_contract() { || task13_fail "the local application-secret projection must be defined and invoked once" grep -Fq -- "$application_secret_parent_owner" "$root/scripts/unified-deployment-smoke.sh" \ || task13_fail "the local application-secret mount root must remain root-owned" + grep -Fq -- "$application_session_ca_source" "$root/scripts/unified-deployment-smoke.sh" \ + || task13_fail "the local application-secret projection must include the session CA" + grep -Fq -- "$application_session_password_projection" "$root/scripts/unified-deployment-smoke.sh" \ + || task13_fail "the local application-secret projection must expose the session password name" grep -Fq -- "$application_secret_file_owner" "$root/scripts/unified-deployment-smoke.sh" \ || task13_fail "the projected application secrets must remain readable only by the core UID" grep -Eq '^TASK13_BAD_CANDIDATE_IMAGE="[^"[:space:]]+@sha256:[0-9a-f]{64}"$' \