fix(security): validate bundle and clean runtime secrets
This commit is contained in:
@@ -23,12 +23,11 @@ read_secret_file() {
|
||||
cat "$1"
|
||||
}
|
||||
|
||||
# Read one value from the deployment bundle without putting the bundle itself in
|
||||
# a service environment. The parser is deliberately strict: one KEY=VALUE per
|
||||
# line, no duplicate keys, no unknown syntax, and no whitespace in credentials.
|
||||
read_bundle_secret() {
|
||||
# Validate the bundle without printing any value. Keep this parser aligned with
|
||||
# the backend loader: comments/blank lines are allowed, while syntax, allowlist,
|
||||
# duplicates, empty values, file size, and line size are fail-closed.
|
||||
validate_bundle() {
|
||||
bundle_path=$1
|
||||
bundle_key=$2
|
||||
if [ -L "$bundle_path" ] || [ ! -f "$bundle_path" ] || [ ! -r "$bundle_path" ] || [ ! -s "$bundle_path" ]; then
|
||||
echo "secret bundle must be a readable, non-empty regular file" >&2
|
||||
return 2
|
||||
@@ -38,20 +37,46 @@ read_bundle_secret() {
|
||||
/run/secrets/*:444|/run/secrets/*:400|/run/secrets/*:600|*:600|*:400) ;;
|
||||
*) echo "secret bundle must have mode 0600 or stricter (Docker secrets may be 0444)" >&2; return 2 ;;
|
||||
esac
|
||||
case "$bundle_key" in
|
||||
THT_[A-Z0-9_]*|PI_PROVIDER_API_KEY) ;;
|
||||
*) echo "invalid secret bundle key" >&2; return 2 ;;
|
||||
esac
|
||||
value=$(awk -v wanted="$bundle_key" '
|
||||
size=$(stat -c '%s' "$bundle_path" 2>/dev/null || stat -f '%z' "$bundle_path" 2>/dev/null) || return 2
|
||||
if [ "$size" -gt 65536 ]; then
|
||||
echo "secret bundle exceeds the 64KiB limit" >&2
|
||||
return 2
|
||||
fi
|
||||
awk '
|
||||
{ sub(/\r$/, "", $0) }
|
||||
length($0) > 16384 { exit 9 }
|
||||
/^[[:space:]]*$/ || /^[[:space:]]*#/ { next }
|
||||
/^[A-Z][A-Z0-9_]*=/ {
|
||||
key=$0; sub(/=.*/, "", key)
|
||||
val=$0; sub(/^[^=]*=/, "", val)
|
||||
if (key !~ /^(THT_MODEL_API_KEY|THT_DWH_API_KEY|THT_VEC_API_KEY|THT_VEC_WRITE_API_KEY|THT_CA|THT_SSL_CA|THT_VECTOR_BOOTSTRAP_PASSWORD|THT_VECTOR_MIGRATOR_PASSWORD|THT_VECTOR_READER_PASSWORD|THT_VECTOR_WRITER_PASSWORD|PI_PROVIDER_API_KEY)$/) exit 6
|
||||
if (val == "") exit 7
|
||||
if (++seen[key] > 1) exit 8
|
||||
if (val == "" || ++seen[key] > 1) exit 7
|
||||
next
|
||||
}
|
||||
{ exit 4 }
|
||||
' "$bundle_path" || {
|
||||
echo "secret bundle syntax is invalid" >&2
|
||||
return 2
|
||||
}
|
||||
}
|
||||
|
||||
# Read one value from the deployment bundle without putting the bundle itself in
|
||||
# a service environment. Values selected for credentials must contain no spaces.
|
||||
read_bundle_secret() {
|
||||
bundle_path=$1
|
||||
bundle_key=$2
|
||||
validate_bundle "$bundle_path" || return
|
||||
case "$bundle_key" in
|
||||
THT_[A-Z0-9_]*|PI_PROVIDER_API_KEY) ;;
|
||||
*) echo "invalid secret bundle key" >&2; return 2 ;;
|
||||
esac
|
||||
value=$(awk -v wanted="$bundle_key" '
|
||||
{ sub(/\r$/, "", $0) }
|
||||
/^[[:space:]]*$/ || /^[[:space:]]*#/ { next }
|
||||
/^[A-Z][A-Z0-9_]*=/ {
|
||||
key=$0; sub(/=.*/, "", key)
|
||||
val=$0; sub(/^[^=]*=/, "", val)
|
||||
if (key == wanted) {
|
||||
if (found) exit 3
|
||||
found=1; print val
|
||||
}
|
||||
next
|
||||
|
||||
Reference in New Issue
Block a user