feat(server): activate projected authentication safely

This commit is contained in:
User
2026-08-22 01:01:36 +02:00
parent 903c0b4de5
commit 3d9a9f0675
32 changed files with 1837 additions and 38 deletions
+5
View File
@@ -32,6 +32,8 @@ import (
"github.com/aritmolab/thothii/tools/tht/internal/workspaceops"
)
var requireRuntimeAuthProjectionReady = authconfig.RequireRuntimeAuthProjectionReady
const usage = `Usage: tht [--installation <absolute-path>/thothii-installation.yaml] <command>
When --installation is omitted, tht uses THOTHII_INSTALLATION or discovers one valid
@@ -192,6 +194,9 @@ func run(ctx context.Context, args []string, stdout, stderr io.Writer) int {
if len(commandArgs) != 1 || commandArgs[0] != "--check-only" {
return commandUsageError(stderr, "update currently requires --check-only")
}
if err := requireRuntimeAuthProjectionReady(installation); err != nil {
return lifecycleFailure(stderr, errors.New("runtime authentication projection is unavailable"), secretValues)
}
result, err = runner.Run(ctx, installation.ComposeArgs("config", "--quiet"), nil)
case "backup":
return backupCommand(ctx, installation, commandArgs, stdout, stderr)