build: package standalone DWH authentication service
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
[Unit]
|
||||
Description=Standalone DWH API-key verifier
|
||||
After=local-fs.target
|
||||
Wants=local-fs.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=dwh-auth
|
||||
Group=www-data
|
||||
SupplementaryGroups=dwh-auth
|
||||
ExecStart=/usr/local/sbin/dwh-auth serve --registry-root /var/lib/dwh-auth --socket /run/dwh-auth/verify.sock
|
||||
Restart=on-failure
|
||||
RestartSec=2s
|
||||
RuntimeDirectory=dwh-auth
|
||||
RuntimeDirectoryMode=0750
|
||||
UMask=0007
|
||||
NoNewPrivileges=true
|
||||
PrivateTmp=true
|
||||
PrivateDevices=true
|
||||
ProtectSystem=strict
|
||||
ProtectHome=true
|
||||
ProtectClock=true
|
||||
ProtectControlGroups=true
|
||||
ProtectHostname=true
|
||||
ProtectKernelLogs=true
|
||||
ProtectKernelModules=true
|
||||
ProtectKernelTunables=true
|
||||
ProtectProc=invisible
|
||||
ReadOnlyPaths=/var/lib/dwh-auth
|
||||
ReadWritePaths=/run/dwh-auth
|
||||
RestrictAddressFamilies=AF_UNIX
|
||||
RestrictNamespaces=true
|
||||
RestrictRealtime=true
|
||||
RestrictSUIDSGID=true
|
||||
LockPersonality=true
|
||||
MemoryDenyWriteExecute=true
|
||||
SystemCallArchitectures=native
|
||||
CapabilityBoundingSet=
|
||||
AmbientCapabilities=
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,7 @@
|
||||
# The registry is provisioned before dwh-auth starts. The SGID directories
|
||||
# preserve the dwh-auth group for records written by the operator CLI.
|
||||
d /var/lib/dwh-auth 2750 root dwh-auth - -
|
||||
d /var/lib/dwh-auth/active 2750 root dwh-auth - -
|
||||
d /var/lib/dwh-auth/revoked 2750 root dwh-auth - -
|
||||
# OpenReadOnly requires a pre-existing read-only shared-lock file.
|
||||
f /var/lib/dwh-auth/.writer.lock 0640 root dwh-auth - -
|
||||
@@ -0,0 +1,28 @@
|
||||
# Include these locations inside the HTTPS server that publishes /dwh/.
|
||||
# The verifier is deliberately reachable only through an internal subrequest.
|
||||
location = /_check_dwh_key {
|
||||
internal;
|
||||
proxy_method GET;
|
||||
proxy_pass http://unix:/run/dwh-auth/verify.sock:/verify;
|
||||
proxy_pass_request_body off;
|
||||
proxy_set_header Content-Length "";
|
||||
proxy_set_header X-API-Key $http_x_api_key;
|
||||
}
|
||||
|
||||
location @dwh_auth_unavailable {
|
||||
return 503;
|
||||
}
|
||||
|
||||
location /dwh/ {
|
||||
limit_req zone=dwh_auth burst=100 nodelay;
|
||||
auth_request /_check_dwh_key;
|
||||
auth_request_set $dwh_key_id $upstream_http_x_dwh_key_id;
|
||||
error_page 500 =503 @dwh_auth_unavailable;
|
||||
|
||||
# Never forward the credential. Only the verifier's public identity may
|
||||
# reach the upstream for audit/rate attribution.
|
||||
proxy_set_header X-API-Key "";
|
||||
proxy_set_header X-DWH-Key-ID "";
|
||||
proxy_set_header Host $host;
|
||||
proxy_pass http://127.0.0.1:3001;
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
# Include this file from the nginx http {} context. The map emits only a
|
||||
# public key ID for canonical v1 keys; all other input is one opaque class.
|
||||
map $http_x_api_key $dwh_public_key_class {
|
||||
default opaque;
|
||||
"~^thtdwh_v1\.([A-Za-z0-9_-]{16})\.[A-Za-z0-9_-]{43}$" v1:$1;
|
||||
}
|
||||
|
||||
# The secret is never part of this key. This limits each remote address and
|
||||
# public credential identity/class to 20 requests per second.
|
||||
map "$remote_addr:$dwh_public_key_class" $dwh_auth_rate_key {
|
||||
default "$remote_addr:$dwh_public_key_class";
|
||||
}
|
||||
limit_req_zone $dwh_auth_rate_key zone=dwh_auth:10m rate=20r/s;
|
||||
Reference in New Issue
Block a user