fix(deploy): validate session migrator TLS mode

This commit is contained in:
User
2026-07-16 19:07:53 +02:00
parent cadc4c6947
commit 7a65fc80a2
6 changed files with 96 additions and 8 deletions
+11
View File
@@ -66,3 +66,14 @@ An operator must still choose the three reviewed legacy IDs, materialize real ru
secrets, deploy Task 4 and Task 5 together in a maintenance window, apply the one-shot migrator,
and run the documented authenticated smoke. The guarded helper has not been invoked with
`--delete`.
## P1 correction — migrator TLS validation
The original migrator Compose command interpolated `THT_SESSION_DB_SSLMODE` into its URL without
checking it. `docker/session-migrate.sh` now rejects every value except `verify-ca` and
`verify-full` before reading the password file or building that URL; the Compose service invokes
this helper. `docker/session-migrate.test.sh` first established RED because the helper did not
exist, then verified that `prefer` is rejected before `tht` can run and that `verify-full` reaches
a fake `tht` binary with the expected TLS URL. The helper and test pass `bash -n`; the focused
backend config/health suite remains green, and the base-plus-overlay Compose configuration renders
with temporary empty secret files.