feat(server): activate projected authentication safely

This commit is contained in:
User
2026-08-22 01:01:36 +02:00
parent 903c0b4de5
commit 3d9a9f0675
32 changed files with 1837 additions and 38 deletions
+5
View File
@@ -10,6 +10,7 @@ import (
"strings"
"time"
"github.com/aritmolab/thothii/tools/tht/internal/authconfig"
"github.com/aritmolab/thothii/tools/tht/internal/compose"
"github.com/aritmolab/thothii/tools/tht/internal/config"
)
@@ -17,6 +18,7 @@ import (
const healthTimeout = 5 * time.Minute
var healthPollInterval = time.Second
var requireRuntimeAuthProjectionReady = authconfig.RequireRuntimeAuthProjectionReady
// HealthFailure identifies the last non-ready service after a bounded health wait.
type HealthFailure struct {
@@ -41,6 +43,9 @@ func Start(ctx context.Context, installation config.Installation, runner compose
if runner == nil {
return errors.New("start requires a Docker command runner")
}
if err := requireRuntimeAuthProjectionReady(installation); err != nil {
return errors.New("runtime authentication projection is unavailable")
}
if build {
if err := runCompose(ctx, installation, runner, "build"); err != nil {
return fmt.Errorf("image build: %w", err)