fix: complete diagnostic extension remediation

This commit is contained in:
2026-08-04 00:46:44 +02:00
parent 565e93a456
commit 49fa7030a5
6 changed files with 192 additions and 19 deletions
@@ -220,6 +220,9 @@ the model/dimensions response fields. Only `GET` and `POST`, `none`/`bearer`/`x-
authentication, origin-relative paths without a query or fragment, and identifier-shaped response
field names are accepted.
For `auth: none`, the binding resolver, runtime renderer, and diagnostic connector all omit the
API-key requirement. Credential-backed declarations retain their local secret-file requirement.
`vector_rest.reversible_probe`, when present, is an authenticated POST with a declared response
field that must echo each requested `create`/`remove` operation. It is called with a generated
diagnostic record create request and a matching remove request, with cleanup retried in `finally`.
@@ -330,7 +333,9 @@ trusted TLS-termination boundary.
SSH adapters verify the remote host against an explicit known-hosts file, open a temporary local
tunnel, and pass the resulting endpoint to the corresponding direct adapter, including its
verified private-CA-or-system-trust policy. Host-key checking cannot be disabled by the form.
verified private-CA-or-system-trust policy. The direct adapter connects to loopback but uses the
original `SSH_TARGET_HOST` as the TLS server name, so certificate hostname validation remains
bound to the remote target. Host-key checking cannot be disabled by the form.
Transport selection is installation-specific because a production server may connect directly while a laptop reaches the same logical resource through REST or SSH.
+8 -3
View File
@@ -19,8 +19,8 @@ belongs in the descriptor, this document, a generated `.env.example`, or diagnos
fragment. The client may use only the declared method, path, auth mode, and response-field names.
- `auth: none` sends no credential; `auth: bearer` reads a local file and sends
`Authorization: Bearer <file-content>`; `auth: x-api-key` sends `x-api-key: <file-content>`.
The resolver does not require or read an API-key file for an `auth: none` diagnostic. File
content is never logged or returned.
The resolver, rendered runtime endpoint, and diagnoser do not require or read an API-key file
for an `auth: none` diagnostic. File content is never logged or returned.
## Canonical descriptor additions
@@ -117,6 +117,10 @@ Both returned values must equal the descriptor's DWH database and schema.
with certificate verification; when absent, the native client still requires a valid certificate
chain from the runtime system trust store. Absence never disables TLS verification.
An SSH tunnel changes only the TCP peer to loopback. The forwarded PostgreSQL TLS connection sets
its server name to `<ROLE>_SSH_TARGET_HOST`, so certificate hostname validation remains against the
declared remote target rather than `127.0.0.1`.
For REST, the descriptor above declares the exact ping:
```text
@@ -142,7 +146,8 @@ collection, integer `dimensions`, and `distance` (`cosine`, `l2`, or `inner_prod
`semantic_index.vector_store`.
Their optional `*_TLS_CA_FILE` follows the same verified private-CA-or-system-trust rule as the
DWH diagnostic.
DWH diagnostic. For an SSH tunnel, their TLS server name is likewise the declared vector
`SSH_TARGET_HOST`, not the loopback listener.
For REST, the exact descriptor-declared request is, for example: