feat(server): activate projected authentication safely

This commit is contained in:
User
2026-08-22 01:01:36 +02:00
parent 903c0b4de5
commit 3d9a9f0675
32 changed files with 1837 additions and 38 deletions
+9
View File
@@ -28,6 +28,8 @@ const (
const probeTimeout = 5 * time.Second
var requireRuntimeAuthProjectionReady = authconfig.RequireRuntimeAuthProjectionReady
const registryValidationProgram = `const fs=require("node:fs");const path="/data/workspace-registry/state/active.json";const s=JSON.parse(fs.readFileSync(path,"utf8"));const hex=/^[0-9a-f]{40}$/;if(!hex.test(s.head)||!Array.isArray(s.revisions)||s.revisions.some((r)=>!r||typeof r.id!=="string"||!r.id||!hex.test(r.commit)||!hex.test(r.blob))){process.exit(1)}for(const r of s.revisions){fs.accessSync("/data/workspace-registry/snapshots/"+r.commit+"/"+r.id+".yaml",fs.constants.R_OK)}`
// Check is one named, redacted diagnostic outcome.
@@ -118,6 +120,13 @@ func RunWithProbe(ctx context.Context, installation config.Installation, runner
} else {
add("files", StatusPassed, "declared host files have safe permissions")
}
if installation.HasRuntimeAuthProjection() {
if err := requireRuntimeAuthProjectionReady(installation); err != nil {
add("auth-projection", StatusFailed, "runtime authentication projection is unavailable")
return finalize(report), nil
}
add("auth-projection", StatusPassed, "runtime authentication projection is ready and equal to canonical authentication")
}
if secretErr != nil {
add("docker", StatusSkipped, "declared secret files are unavailable")
add("compose", StatusSkipped, "declared secret files are unavailable")