fix(ci): project private application secrets
This commit is contained in:
@@ -501,8 +501,9 @@ services:
|
||||
- sessions:/data/sessions
|
||||
- auth-runtime:/run/thothii-auth:ro
|
||||
- auth-state:/data/auth
|
||||
- $TASK13_SESSION_RUNTIME_PASSWORD:/run/secrets/task13-runtime-password:ro
|
||||
- application-secrets:/run/secrets:ro
|
||||
- registry-remote:/fixtures/remote.git:ro
|
||||
secrets: !reset []
|
||||
frontend:
|
||||
image: $TASK13_FRONTEND_IMAGE
|
||||
build:
|
||||
@@ -547,6 +548,9 @@ volumes:
|
||||
auth-runtime:
|
||||
labels:
|
||||
io.thothii.task13.run: "$TASK13_RUN_ID"
|
||||
application-secrets:
|
||||
labels:
|
||||
io.thothii.task13.run: "$TASK13_RUN_ID"
|
||||
registry-remote:
|
||||
labels:
|
||||
io.thothii.task13.run: "$TASK13_RUN_ID"
|
||||
@@ -978,6 +982,34 @@ task13_prepare_local_pi_runtime() {
|
||||
'
|
||||
}
|
||||
|
||||
task13_prepare_local_application_secrets() {
|
||||
local owner_label
|
||||
owner_label="$(docker volume inspect --format '{{ index .Labels "io.thothii.task13.run" }}' \
|
||||
"$TASK13_APPLICATION_SECRETS_VOLUME")"
|
||||
[[ "$owner_label" == "$TASK13_RUN_ID" ]] \
|
||||
|| task13_fail "application-secret runtime volume lacks the Task 13 run label"
|
||||
task13_run_logged "project local application secrets for the core runtime" docker run --rm \
|
||||
--name "$TASK13_APPLICATION_SECRETS_PROJECTION_CONTAINER" \
|
||||
--label "io.thothii.task13.run=$TASK13_RUN_ID" \
|
||||
--user 0:0 \
|
||||
--entrypoint sh \
|
||||
--volume "$TASK13_SECRETS:/source/thothii.secrets:ro" \
|
||||
--volume "$TASK13_SESSION_RUNTIME_PASSWORD:/source/task13-runtime-password:ro" \
|
||||
--volume "$TASK13_APPLICATION_SECRETS_VOLUME:/target" \
|
||||
"$TASK13_CORE_IMAGE" -ceu '
|
||||
test -f /source/thothii.secrets && test ! -L /source/thothii.secrets
|
||||
test -f /source/task13-runtime-password && test ! -L /source/task13-runtime-password
|
||||
test -z "$(find /target -mindepth 1 -maxdepth 1 -print -quit)"
|
||||
cp /source/thothii.secrets /source/task13-runtime-password /target/
|
||||
chown 10001:10001 /target /target/thothii.secrets /target/task13-runtime-password
|
||||
chmod 0700 /target
|
||||
chmod 0600 /target/thothii.secrets /target/task13-runtime-password
|
||||
test "$(stat -c "%u:%g:%a" /target)" = 10001:10001:700
|
||||
test "$(stat -c "%u:%g:%a" /target/thothii.secrets)" = 10001:10001:600
|
||||
test "$(stat -c "%u:%g:%a" /target/task13-runtime-password)" = 10001:10001:600
|
||||
'
|
||||
}
|
||||
|
||||
task13_prepare_registry_remote() {
|
||||
local owner_label
|
||||
owner_label="$(docker volume inspect --format '{{ index .Labels "io.thothii.task13.run" }}' \
|
||||
@@ -1008,6 +1040,7 @@ task13_start_stack() {
|
||||
task13_compose_logged "create local core authentication runtime" create core
|
||||
task13_prepare_local_auth_runtime
|
||||
task13_prepare_local_pi_runtime
|
||||
task13_prepare_local_application_secrets
|
||||
task13_prepare_registry_remote
|
||||
task13_compose_start_logged "start local Compose distribution" up --detach --wait --wait-timeout 120
|
||||
TASK13_NETWORK="$(docker network ls \
|
||||
@@ -2420,6 +2453,7 @@ task13_self_test_source_contract() {
|
||||
local root host_network push_command registry_function workflow uses_count pinned_uses_count
|
||||
local auth_runtime_mount auth_root_mount auth_projection auth_runtime_owner
|
||||
local pi_auth_bind pi_projection registry_runtime_mount registry_root_mount registry_projection
|
||||
local application_secret_bind application_secret_mount application_secret_projection
|
||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||
workflow="$root/.github/workflows/deployment.yml"
|
||||
host_network='--network'' host'
|
||||
@@ -2434,6 +2468,9 @@ task13_self_test_source_contract() {
|
||||
registry_runtime_mount='registry-remote:/fixtures/remote.git:''ro'
|
||||
registry_root_mount='$TASK13_''REMOTE:/fixtures/remote.git:ro'
|
||||
registry_projection='task13_prepare_registry_''remote'
|
||||
application_secret_bind='$TASK13_''SECRETS:/run/secrets/thothii.secrets:ro'
|
||||
application_secret_mount='application-secrets:/run/''secrets:ro'
|
||||
application_secret_projection='task13_prepare_local_application_''secrets'
|
||||
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
|
||||
"$root/scripts/unified-deployment-smoke.sh" \
|
||||
"$root/scripts/tht-update-smoke.sh" \
|
||||
@@ -2467,6 +2504,13 @@ task13_self_test_source_contract() {
|
||||
[[ "$(grep -Ec "^${registry_projection}\\(\\)|^[[:space:]]+${registry_projection}$" \
|
||||
"$root/scripts/unified-deployment-smoke.sh")" -ge 3 ]] \
|
||||
|| task13_fail "the Git fixture projection must cover bootstrap and subsequent pushes"
|
||||
! grep -Fq -- "$application_secret_bind" "$root/scripts/unified-deployment-smoke.sh" \
|
||||
|| task13_fail "the local smoke must not bind the host-owned application bundle into the core"
|
||||
grep -Fq -- "$application_secret_mount" "$root/scripts/unified-deployment-smoke.sh" \
|
||||
|| task13_fail "the local smoke must mount Compose-owned application secrets"
|
||||
[[ "$(grep -Ec "^${application_secret_projection}\\(\\)|^[[:space:]]+${application_secret_projection}$" \
|
||||
"$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \
|
||||
|| task13_fail "the local application-secret projection must be defined and invoked once"
|
||||
grep -Eq '^TASK13_BAD_CANDIDATE_IMAGE="[^"[:space:]]+@sha256:[0-9a-f]{64}"$' \
|
||||
"$root/scripts/unified-deployment-smoke.sh" \
|
||||
|| task13_fail "the bad rollback candidate must be an immutable digest reference"
|
||||
@@ -2622,6 +2666,8 @@ task13_initialize() {
|
||||
TASK13_AUTH_PROJECTION_CONTAINER="$TASK13_PROJECT-auth-projection"
|
||||
TASK13_PI_RUNTIME_VOLUME="${TASK13_PROJECT}_pi-state"
|
||||
TASK13_PI_PROJECTION_CONTAINER="$TASK13_PROJECT-pi-projection"
|
||||
TASK13_APPLICATION_SECRETS_VOLUME="${TASK13_PROJECT}_application-secrets"
|
||||
TASK13_APPLICATION_SECRETS_PROJECTION_CONTAINER="$TASK13_PROJECT-application-secrets-projection"
|
||||
TASK13_REGISTRY_RUNTIME_VOLUME="${TASK13_PROJECT}_registry-remote"
|
||||
TASK13_REGISTRY_PROJECTION_CONTAINER="$TASK13_PROJECT-registry-projection"
|
||||
TASK13_AUTH_ADMIN=task13-admin
|
||||
|
||||
Reference in New Issue
Block a user