fix(deploy): reconcile local vector credentials safely
This commit is contained in:
@@ -53,3 +53,36 @@ the extension there. A clean-volume rerun passed.
|
||||
file-backed secrets and are never exposed to core.
|
||||
- The smoke intentionally refuses the operator project name `thothii` and removes only its unique
|
||||
project namespace and volumes.
|
||||
|
||||
## Follow-up hardening — credential reconciliation and cleanup ownership
|
||||
|
||||
Review findings were resolved in a separate follow-up:
|
||||
|
||||
- Replaced fresh-volume-only initialization with `vector-reconcile`, an idempotent one-shot that
|
||||
runs after database health and before `vector-migrate`. It authenticates with only the bootstrap
|
||||
admin secret, safely creates missing identities, reconciles role attributes and passwords on
|
||||
existing volumes, restores memberships/ownership, and leaves vector data untouched.
|
||||
- The migrator is explicitly `NOSUPERUSER NOCREATEDB NOCREATEROLE`. Schema/database ownership is
|
||||
sufficient for all packaged migrations because reconciliation creates the two group roles first.
|
||||
- The live smoke rotates migrator, reader, and writer secrets on the same populated volume, rejects
|
||||
the old reader credential, reruns migrations, recreates core with the new runtime credentials,
|
||||
and retrieves the record written before rotation and again after database/core restart.
|
||||
- Smoke project names are no longer caller-controlled. Each run creates a unique namespace and
|
||||
ownership token. Containers, networks, and volumes carry the ownership label; preflight refuses
|
||||
any collision and cleanup verifies every discovered resource before `down --volumes`.
|
||||
- Added a dynamic fake-Docker contract suite for caller override, collision, and mismatched cleanup
|
||||
labels, plus a real-Docker collision probe using a unique labeled volume.
|
||||
|
||||
Follow-up verification:
|
||||
|
||||
- `./scripts/local-vector-smoke.sh`: PASS, including live secret rotation and persisted retrieval
|
||||
- `./scripts/test-local-vector-smoke-safety.sh`: PASS
|
||||
- `./scripts/test-local-vector-smoke-live-collision.sh`: PASS
|
||||
- harness: 477 passed, 5 deselected
|
||||
- backend: 84 passed; TypeScript typecheck PASS
|
||||
- frontend: 226 passed; TypeScript typecheck PASS
|
||||
- Compose security, backend URL, config, shell syntax, and diff checks: PASS
|
||||
|
||||
Remaining operational constraint: the bootstrap admin secret must continue to match the PostgreSQL
|
||||
bootstrap account stored in the volume. Runtime migrator/reader/writer rotation is supported without
|
||||
data deletion; bootstrap-account password rotation is a distinct database-administration operation.
|
||||
|
||||
Reference in New Issue
Block a user