fix(ci): project private application secrets
This commit is contained in:
@@ -7,9 +7,12 @@ import { renderRuntimeConfig } from "../backend/src/workspaces/runtime-renderer.
|
||||
const requireFromBackend = createRequire(new URL("../backend/package.json", import.meta.url));
|
||||
const { parse } = requireFromBackend("yaml") as { parse: (value: string) => any };
|
||||
|
||||
const [renderedPath, workspacePath, profile] = process.argv.slice(2);
|
||||
if (!renderedPath || !workspacePath || (profile !== "local" && profile !== "server")) {
|
||||
throw new Error("usage: task13-runtime-fixture-check RENDERED_JSON WORKSPACE_YAML local|server");
|
||||
const [renderedPath, workspacePath, profile, bundleSource, runtimePasswordSourceInput] = process.argv.slice(2);
|
||||
if (!renderedPath || !workspacePath || (profile !== "local" && profile !== "server")
|
||||
|| !bundleSource || !runtimePasswordSourceInput) {
|
||||
throw new Error(
|
||||
"usage: task13-runtime-fixture-check RENDERED_JSON WORKSPACE_YAML local|server BUNDLE PASSWORD",
|
||||
);
|
||||
}
|
||||
|
||||
const config = JSON.parse(readFileSync(renderedPath, "utf8"));
|
||||
@@ -105,27 +108,37 @@ if (workspace.semantic_index?.embedding?.dimensions !== 1024) {
|
||||
throw new Error("fixture workspace embedding dimension changed");
|
||||
}
|
||||
|
||||
const bundle = config.secrets?.thothii_secrets;
|
||||
const bundleSource = bundle?.file;
|
||||
if (typeof bundleSource !== "string" || !statSync(bundleSource).isFile()) {
|
||||
if (!statSync(bundleSource).isFile()) {
|
||||
throw new Error("fixture secret bundle source is not a regular file");
|
||||
}
|
||||
accessSync(bundleSource, constants.R_OK);
|
||||
const coreBundle = (core.secrets || []).filter(
|
||||
(secret: any) => secret.source === "thothii_secrets" && secret.target === "thothii.secrets",
|
||||
);
|
||||
if (coreBundle.length !== 1) throw new Error("core lacks exactly one runtime secret bundle mount");
|
||||
if (profile === "local") {
|
||||
if (coreBundle.length !== 0) throw new Error("local core retained the host-owned secret bundle mount");
|
||||
} else if (coreBundle.length !== 1) {
|
||||
throw new Error("server core lacks exactly one runtime secret bundle mount");
|
||||
}
|
||||
if ((frontend.secrets || []).length !== 0) throw new Error("frontend received a runtime secret");
|
||||
|
||||
const mounts = core.volumes || [];
|
||||
const runtimePasswordMounts = mounts.filter(
|
||||
(mount: any) => mount.target === "/run/secrets/task13-runtime-password",
|
||||
);
|
||||
if (runtimePasswordMounts.length !== 1 || runtimePasswordMounts[0].type !== "bind"
|
||||
if (profile === "local") {
|
||||
const projected = mounts.filter((mount: any) => mount.target === "/run/secrets");
|
||||
if (runtimePasswordMounts.length !== 0 || projected.length !== 1
|
||||
|| projected[0].type !== "volume" || !projected[0].read_only
|
||||
|| (projected[0].source !== "application-secrets"
|
||||
&& !projected[0].source.endsWith("_application-secrets"))) {
|
||||
throw new Error("local secrets are not isolated in the Compose-owned projection volume");
|
||||
}
|
||||
} else if (runtimePasswordMounts.length !== 1 || runtimePasswordMounts[0].type !== "bind"
|
||||
|| !runtimePasswordMounts[0].read_only || !statSync(runtimePasswordMounts[0].source).isFile()) {
|
||||
throw new Error("runtime fixture lacks one readable, read-only password-file bind");
|
||||
throw new Error("server runtime fixture lacks one readable, read-only password-file bind");
|
||||
}
|
||||
accessSync(runtimePasswordMounts[0].source, constants.R_OK);
|
||||
accessSync(runtimePasswordSourceInput, constants.R_OK);
|
||||
const piTargets = [
|
||||
"/home/thoth/.pi/agent/auth.json",
|
||||
"/home/thoth/.pi/agent/models.json",
|
||||
@@ -168,7 +181,7 @@ for (const [target, localVolume] of [
|
||||
}
|
||||
|
||||
const resolverEnvironment = { ...core.environment };
|
||||
const runtimePasswordSource = realpathSync(runtimePasswordMounts[0].source);
|
||||
const runtimePasswordSource = realpathSync(runtimePasswordSourceInput);
|
||||
resolverEnvironment.THT_WS_TASK13_SMOKE_DWH_PASSWORD_FILE = runtimePasswordSource;
|
||||
const bindings = resolveRuntimeBindings(workspace, resolverEnvironment, [dirname(runtimePasswordSource)]);
|
||||
for (const [role, binding] of Object.entries(bindings)) {
|
||||
@@ -200,7 +213,7 @@ if (runtime.resources?.embeddings?.base_url !== "http://embedding:11434"
|
||||
throw new Error("workspace resolver produced the wrong embedding runtime");
|
||||
}
|
||||
const secret = readFileSync(bundleSource, "utf8").trim();
|
||||
const runtimePassword = readFileSync(runtimePasswordMounts[0].source, "utf8");
|
||||
const runtimePassword = readFileSync(runtimePasswordSourceInput, "utf8");
|
||||
if (JSON.stringify(config).includes(secret)) throw new Error("fixture render leaked application bundle content");
|
||||
if (JSON.stringify(runtime).includes(secret)) throw new Error("runtime render leaked application bundle content");
|
||||
if (JSON.stringify(config).includes(runtimePassword)) throw new Error("fixture render leaked runtime password content");
|
||||
|
||||
Reference in New Issue
Block a user