fix(security): validate bundle and clean runtime secrets

This commit is contained in:
2026-07-12 11:52:02 +02:00
parent 385646d574
commit 449a333365
5 changed files with 94 additions and 20 deletions
+16
View File
@@ -74,6 +74,22 @@ if grep -q 'must-not-leak' "$tmp/legacy-model.err"; then
echo "legacy model credential leaked through entrypoint diagnostics" >&2
exit 1
fi
printf 'THT_VECTOR_READER_PASSWORD=one\nTHT_VECTOR_READER_PASSWORD=two\n' >"$tmp/invalid-bundle"
chmod 0600 "$tmp/invalid-bundle"
if THT_SECRETS_FILE="$tmp/invalid-bundle" ./docker/core-entrypoint.sh doctor \
>"$tmp/invalid-bundle.out" 2>"$tmp/invalid-bundle.err"; then
echo "entrypoint accepted an invalid secret bundle" >&2
exit 1
fi
grep -q 'THT_SECRETS_FILE points to an invalid secret bundle' "$tmp/invalid-bundle.err"
if grep -q 'THT_VECTOR_READER_PASSWORD' "$tmp/invalid-bundle.err"; then
echo "invalid bundle diagnostics leaked key material" >&2
exit 1
fi
before_tmp=$(find "${TMPDIR:-/tmp}" -maxdepth 1 -type d -name 'thothii-secrets.*' -print | sort)
THT_SECRETS_FILE="$bundle" ./docker/core-entrypoint.sh doctor >/dev/null 2>&1 || true
after_tmp=$(find "${TMPDIR:-/tmp}" -maxdepth 1 -type d -name 'thothii-secrets.*' -print | sort)
test "$before_tmp" = "$after_tmp"
if grep -Eq 'THT_VECTOR_(BOOTSTRAP|MIGRATOR|READER|WRITER)_PASSWORD_FILE|target: vector_(bootstrap|migrator|reader|writer)_password|dwh_api_key|model_api_key|THT_[A-Z0-9_]+_SECRET_FILE' "$tmp/production.yaml"; then
echo "production external config contains local direct vector secrets" >&2
exit 1