feat(server): activate projected authentication safely
This commit is contained in:
@@ -28,6 +28,8 @@ const (
|
||||
|
||||
const probeTimeout = 5 * time.Second
|
||||
|
||||
var requireRuntimeAuthProjectionReady = authconfig.RequireRuntimeAuthProjectionReady
|
||||
|
||||
const registryValidationProgram = `const fs=require("node:fs");const path="/data/workspace-registry/state/active.json";const s=JSON.parse(fs.readFileSync(path,"utf8"));const hex=/^[0-9a-f]{40}$/;if(!hex.test(s.head)||!Array.isArray(s.revisions)||s.revisions.some((r)=>!r||typeof r.id!=="string"||!r.id||!hex.test(r.commit)||!hex.test(r.blob))){process.exit(1)}for(const r of s.revisions){fs.accessSync("/data/workspace-registry/snapshots/"+r.commit+"/"+r.id+".yaml",fs.constants.R_OK)}`
|
||||
|
||||
// Check is one named, redacted diagnostic outcome.
|
||||
@@ -118,6 +120,13 @@ func RunWithProbe(ctx context.Context, installation config.Installation, runner
|
||||
} else {
|
||||
add("files", StatusPassed, "declared host files have safe permissions")
|
||||
}
|
||||
if installation.HasRuntimeAuthProjection() {
|
||||
if err := requireRuntimeAuthProjectionReady(installation); err != nil {
|
||||
add("auth-projection", StatusFailed, "runtime authentication projection is unavailable")
|
||||
return finalize(report), nil
|
||||
}
|
||||
add("auth-projection", StatusPassed, "runtime authentication projection is ready and equal to canonical authentication")
|
||||
}
|
||||
if secretErr != nil {
|
||||
add("docker", StatusSkipped, "declared secret files are unavailable")
|
||||
add("compose", StatusSkipped, "declared secret files are unavailable")
|
||||
|
||||
@@ -27,6 +27,56 @@ func TestRunReportsUnavailableDockerWithoutReturningAnExecutionError(t *testing.
|
||||
}
|
||||
}
|
||||
|
||||
func TestRunReportsOneSanitizedRuntimeAuthProjectionFailureBeforeCompose(t *testing.T) {
|
||||
installation := doctorInstallation(t, "")
|
||||
installation.Profile = "server"
|
||||
installation.Authentication.RuntimeProjection = &config.RuntimeProjection{
|
||||
Directory: "/runtime-auth", UID: 10001, GID: 10001,
|
||||
}
|
||||
previous := requireRuntimeAuthProjectionReady
|
||||
requireRuntimeAuthProjectionReady = func(config.Installation) error {
|
||||
return errors.New("synthetic-runtime-projection-secret")
|
||||
}
|
||||
t.Cleanup(func() { requireRuntimeAuthProjectionReady = previous })
|
||||
|
||||
runner := &doctorRunner{services: healthyServices}
|
||||
report, err := Run(context.Background(), installation, runner)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
failures := 0
|
||||
for _, check := range report.Checks {
|
||||
if check.Name != "auth-projection" {
|
||||
continue
|
||||
}
|
||||
failures++
|
||||
if check.Status != StatusFailed || check.Detail != "runtime authentication projection is unavailable" {
|
||||
t.Fatalf("auth-projection check = %#v", check)
|
||||
}
|
||||
}
|
||||
if failures != 1 {
|
||||
t.Fatalf("auth-projection failures = %d, report = %#v", failures, report)
|
||||
}
|
||||
if strings.Contains(reportText(report), "synthetic-runtime-projection-secret") {
|
||||
t.Fatalf("runtime projection report leaked internal detail: %#v", report)
|
||||
}
|
||||
if len(runner.calls) != 0 {
|
||||
t.Fatalf("doctor reached Compose diagnostics after failed projection gate: %v", runner.calls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRunLeavesUnprojectedDoctorChecklistUnchanged(t *testing.T) {
|
||||
report, err := Run(context.Background(), doctorInstallation(t, ""), &doctorRunner{services: healthyServices})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
for _, check := range report.Checks {
|
||||
if check.Name == "auth-projection" {
|
||||
t.Fatalf("unprojected report unexpectedly contains auth-projection: %#v", report)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestValidateVolumesRequiresAuthState(t *testing.T) {
|
||||
legacy := `{"volumes":{"settings":{},"pi-state":{},"workspace-registry":{},"workspace-secrets":{},"sessions":{},"qdrant-data":{},"embedding-models":{}}}`
|
||||
if err := ValidateVolumes(legacy); err == nil || !strings.Contains(err.Error(), "auth-state") {
|
||||
|
||||
Reference in New Issue
Block a user