fix(ci): project server auth in deployment smoke
This commit is contained in:
@@ -32,6 +32,7 @@ TASK13_INSTALLATION="$fixture/thothii-installation.yaml"
|
|||||||
TASK13_PI_AUTH="$fixture/pi-auth.json"
|
TASK13_PI_AUTH="$fixture/pi-auth.json"
|
||||||
TASK13_SECRETS="$fixture/thothii.secrets"
|
TASK13_SECRETS="$fixture/thothii.secrets"
|
||||||
TASK13_AUTH_ROOT="$fixture/auth"
|
TASK13_AUTH_ROOT="$fixture/auth"
|
||||||
|
TASK13_AUTH_RUNTIME_ROOT="$fixture/auth-runtime"
|
||||||
TASK13_AUTH_PASSWORD_FILE="$fixture/local-auth-password"
|
TASK13_AUTH_PASSWORD_FILE="$fixture/local-auth-password"
|
||||||
TASK13_AUTH_ADMIN=task13-admin
|
TASK13_AUTH_ADMIN=task13-admin
|
||||||
TASK13_AUTH_PASSWORD="fixture-auth-password-$profile"
|
TASK13_AUTH_PASSWORD="fixture-auth-password-$profile"
|
||||||
@@ -84,6 +85,7 @@ else
|
|||||||
-f "$root/deploy/compose.server.yaml"
|
-f "$root/deploy/compose.server.yaml"
|
||||||
-f "$root/deploy/compose.session-server.yaml.example"
|
-f "$root/deploy/compose.session-server.yaml.example"
|
||||||
-f "$TASK13_OVERRIDE"
|
-f "$TASK13_OVERRIDE"
|
||||||
|
-f "$root/deploy/compose.auth-runtime-projection.yaml"
|
||||||
)
|
)
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -308,6 +308,7 @@ task13_compose_files() {
|
|||||||
-f "$TASK13_ROOT/deploy/compose.server.yaml"
|
-f "$TASK13_ROOT/deploy/compose.server.yaml"
|
||||||
-f "$TASK13_ROOT/deploy/compose.session-server.yaml.example"
|
-f "$TASK13_ROOT/deploy/compose.session-server.yaml.example"
|
||||||
-f "$TASK13_OVERRIDE"
|
-f "$TASK13_OVERRIDE"
|
||||||
|
-f "$TASK13_ROOT/deploy/compose.auth-runtime-projection.yaml"
|
||||||
)
|
)
|
||||||
else
|
else
|
||||||
TASK13_COMPOSE+=(
|
TASK13_COMPOSE+=(
|
||||||
@@ -684,12 +685,10 @@ EOF
|
|||||||
chmod 0600 "$TASK13_SERVER_WORKSPACE_CONFIG"
|
chmod 0600 "$TASK13_SERVER_WORKSPACE_CONFIG"
|
||||||
|
|
||||||
mkdir -p "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" "$TASK13_SERVER_REGISTRY"
|
mkdir -p "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" "$TASK13_SERVER_REGISTRY"
|
||||||
mkdir -p "$TASK13_AUTH_ROOT"
|
|
||||||
"$TASK13_ROOT/scripts/prepare-server-pi-state.sh" \
|
"$TASK13_ROOT/scripts/prepare-server-pi-state.sh" \
|
||||||
"$TASK13_SERVER_PI_STATE" "$(id -u)" "$(id -g)" >>"$TASK13_LOG"
|
"$TASK13_SERVER_PI_STATE" "$(id -u)" "$(id -g)" >>"$TASK13_LOG"
|
||||||
chmod 0777 "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" \
|
chmod 0777 "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" \
|
||||||
"$TASK13_SERVER_PI_STATE/agent" "$TASK13_SERVER_REGISTRY"
|
"$TASK13_SERVER_PI_STATE/agent" "$TASK13_SERVER_REGISTRY"
|
||||||
chmod 0700 "$TASK13_AUTH_ROOT"
|
|
||||||
data_root="$TASK13_SERVER_DATA"
|
data_root="$TASK13_SERVER_DATA"
|
||||||
pi_root="$TASK13_SERVER_PI_STATE"
|
pi_root="$TASK13_SERVER_PI_STATE"
|
||||||
registry_root="$TASK13_SERVER_REGISTRY"
|
registry_root="$TASK13_SERVER_REGISTRY"
|
||||||
@@ -760,6 +759,7 @@ EOF
|
|||||||
printf 'PI_AUTH_FILE=%s\n' "$TASK13_PI_AUTH"
|
printf 'PI_AUTH_FILE=%s\n' "$TASK13_PI_AUTH"
|
||||||
printf 'THT_SECRETS_FILE=%s\n' "$TASK13_SECRETS"
|
printf 'THT_SECRETS_FILE=%s\n' "$TASK13_SECRETS"
|
||||||
printf 'THT_AUTH_CONFIG_ROOT=%s\n' "$TASK13_AUTH_ROOT"
|
printf 'THT_AUTH_CONFIG_ROOT=%s\n' "$TASK13_AUTH_ROOT"
|
||||||
|
printf 'THT_AUTH_RUNTIME_ROOT=%s\n' "$TASK13_AUTH_RUNTIME_ROOT"
|
||||||
printf 'THT_WORKSPACE_GIT_REMOTE=/fixtures/remote.git\n'
|
printf 'THT_WORKSPACE_GIT_REMOTE=/fixtures/remote.git\n'
|
||||||
printf 'THT_WORKSPACE_GIT_BRANCH=%s\n' "$TASK13_BRANCH"
|
printf 'THT_WORKSPACE_GIT_BRANCH=%s\n' "$TASK13_BRANCH"
|
||||||
printf 'THT_DATA_ROOT=%s\n' "$data_root"
|
printf 'THT_DATA_ROOT=%s\n' "$data_root"
|
||||||
@@ -785,6 +785,10 @@ projectDirectory: "$TASK13_ROOT"
|
|||||||
envFile: "$TASK13_ENV_FILE"
|
envFile: "$TASK13_ENV_FILE"
|
||||||
authentication:
|
authentication:
|
||||||
configDirectory: "$TASK13_AUTH_ROOT"
|
configDirectory: "$TASK13_AUTH_ROOT"
|
||||||
|
runtimeProjection:
|
||||||
|
directory: "$TASK13_AUTH_RUNTIME_ROOT"
|
||||||
|
uid: 10001
|
||||||
|
gid: 10001
|
||||||
overrides:
|
overrides:
|
||||||
- "$TASK13_ROOT/deploy/compose.session-server.yaml.example"
|
- "$TASK13_ROOT/deploy/compose.session-server.yaml.example"
|
||||||
- "$TASK13_OVERRIDE"
|
- "$TASK13_OVERRIDE"
|
||||||
@@ -934,7 +938,7 @@ task13_configure_local_authentication() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
task13_configure_server_oidc_authentication() {
|
task13_configure_server_oidc_authentication() {
|
||||||
task13_run_logged "configure fake server OIDC authentication" "$TASK13_THT" --installation "$TASK13_INSTALLATION" auth configure \
|
task13_run_logged "configure fake server OIDC authentication" sudo -n -- "$TASK13_THT" --installation "$TASK13_INSTALLATION" auth configure \
|
||||||
--mode oidc --public-url "https://task13.example.invalid" \
|
--mode oidc --public-url "https://task13.example.invalid" \
|
||||||
--issuer "https://task13-fake-oidc:9443/application/o/task13/" --client-id task13-smoke-client \
|
--issuer "https://task13-fake-oidc:9443/application/o/task13/" --client-id task13-smoke-client \
|
||||||
--authentik-base-url "https://task13-fake-oidc:9443" --user-group task13-users --admin-group task13-admins
|
--authentik-base-url "https://task13-fake-oidc:9443" --user-group task13-users --admin-group task13-admins
|
||||||
@@ -1890,6 +1894,19 @@ task13_assert_built_image_ownership() {
|
|||||||
done
|
done
|
||||||
}
|
}
|
||||||
|
|
||||||
|
task13_reclaim_server_fixture_ownership() {
|
||||||
|
local host_uid host_gid
|
||||||
|
[[ "${TASK13_PROFILE:-local}" == server ]] || return 0
|
||||||
|
[[ -n "${TASK13_TMP:-}" && -d "$TASK13_TMP" ]] || return 0
|
||||||
|
[[ "${TASK13_TMP%/*}" == "${TASK13_TMP_PARENT:-}" \
|
||||||
|
&& "${TASK13_TMP##*/}" == thothii-task13.* ]] \
|
||||||
|
|| task13_fail "refusing to reclaim an unexpected server fixture path"
|
||||||
|
host_uid="$(id -u)"
|
||||||
|
host_gid="$(id -g)"
|
||||||
|
task13_bounded "$TASK13_CLEANUP_TIMEOUT" "reclaim server fixture ownership" \
|
||||||
|
sudo -n -- chown -hR "$host_uid:$host_gid" "$TASK13_TMP"
|
||||||
|
}
|
||||||
|
|
||||||
task13_cleanup() {
|
task13_cleanup() {
|
||||||
local original_rc="$1" cleanup_rc=0 transaction="" leftovers="" image_id=""
|
local original_rc="$1" cleanup_rc=0 transaction="" leftovers="" image_id=""
|
||||||
set +e
|
set +e
|
||||||
@@ -1913,9 +1930,17 @@ task13_cleanup() {
|
|||||||
if [[ -n "${TASK13_PROJECT:-}" && -n "${TASK13_ROOT:-}" && -f "${TASK13_OVERRIDE:-}" ]]; then
|
if [[ -n "${TASK13_PROJECT:-}" && -n "${TASK13_ROOT:-}" && -f "${TASK13_OVERRIDE:-}" ]]; then
|
||||||
if task13_assert_project_ownership >>"${TASK13_LOG:-/dev/null}" 2>&1; then
|
if task13_assert_project_ownership >>"${TASK13_LOG:-/dev/null}" 2>&1; then
|
||||||
task13_compose_files
|
task13_compose_files
|
||||||
task13_bounded "$TASK13_CLEANUP_TIMEOUT" "stop owned Compose project" \
|
if task13_bounded "$TASK13_CLEANUP_TIMEOUT" "stop owned Compose project" \
|
||||||
"${TASK13_COMPOSE[@]}" down --volumes --remove-orphans --timeout 10 \
|
"${TASK13_COMPOSE[@]}" down --volumes --remove-orphans --timeout 10 \
|
||||||
>>"${TASK13_LOG:-/dev/null}" 2>&1 || cleanup_rc=1
|
>>"${TASK13_LOG:-/dev/null}" 2>&1; then
|
||||||
|
if ! {
|
||||||
|
task13_reclaim_server_fixture_ownership
|
||||||
|
} >>"${TASK13_LOG:-/dev/null}" 2>&1; then
|
||||||
|
cleanup_rc=1
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
cleanup_rc=1
|
||||||
|
fi
|
||||||
else
|
else
|
||||||
cleanup_rc=1
|
cleanup_rc=1
|
||||||
fi
|
fi
|
||||||
@@ -2475,6 +2500,9 @@ task13_self_test_source_contract() {
|
|||||||
local application_secret_bind application_secret_mount application_secret_projection
|
local application_secret_bind application_secret_mount application_secret_projection
|
||||||
local application_secret_parent_owner application_secret_file_owner
|
local application_secret_parent_owner application_secret_file_owner
|
||||||
local image_evidence_environment image_evidence_initialization
|
local image_evidence_environment image_evidence_initialization
|
||||||
|
local server_auth_projection_override server_auth_projection_descriptor
|
||||||
|
local server_auth_projection_environment server_auth_privileged_configure
|
||||||
|
local server_fixture_reclamation
|
||||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||||
workflow="$root/.github/workflows/deployment.yml"
|
workflow="$root/.github/workflows/deployment.yml"
|
||||||
runner_preparation="$root/scripts/prepare-linux-docker-runner.sh"
|
runner_preparation="$root/scripts/prepare-linux-docker-runner.sh"
|
||||||
@@ -2497,6 +2525,11 @@ task13_self_test_source_contract() {
|
|||||||
application_secret_file_owner='chown 10001:''10001 /target/thothii.secrets /target/task13-runtime-password'
|
application_secret_file_owner='chown 10001:''10001 /target/thothii.secrets /target/task13-runtime-password'
|
||||||
image_evidence_environment='TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}''/task13-images.json'
|
image_evidence_environment='TASK13_IMAGE_EVIDENCE_OUTPUT: ${{ runner.temp }}''/task13-images.json'
|
||||||
image_evidence_initialization='TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/''.artifacts/task-15/unified-docker-images.json}"'
|
image_evidence_initialization='TASK13_IMAGE_EVIDENCE_OUTPUT="${TASK13_IMAGE_EVIDENCE_OUTPUT:-$TASK13_ROOT/''.artifacts/task-15/unified-docker-images.json}"'
|
||||||
|
server_auth_projection_override='deploy/compose.auth-runtime-''projection.yaml'
|
||||||
|
server_auth_projection_descriptor='runtime''Projection:'
|
||||||
|
server_auth_projection_environment='THT_AUTH_RUNTIME_''ROOT=%s'
|
||||||
|
server_auth_privileged_configure='sudo -n -- "$TASK13_''THT"'
|
||||||
|
server_fixture_reclamation='task13_reclaim_server_fixture_''ownership'
|
||||||
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
|
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
|
||||||
"$root/scripts/unified-deployment-smoke.sh" \
|
"$root/scripts/unified-deployment-smoke.sh" \
|
||||||
"$root/scripts/tht-update-smoke.sh" \
|
"$root/scripts/tht-update-smoke.sh" \
|
||||||
@@ -2554,6 +2587,17 @@ task13_self_test_source_contract() {
|
|||||||
|| task13_fail "CI must write generated Docker image evidence outside the trusted checkout"
|
|| task13_fail "CI must write generated Docker image evidence outside the trusted checkout"
|
||||||
grep -Fq -- "$image_evidence_initialization" "$root/scripts/unified-deployment-smoke.sh" \
|
grep -Fq -- "$image_evidence_initialization" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|| task13_fail "the Docker image evidence output must honor an explicit CI path"
|
|| task13_fail "the Docker image evidence output must honor an explicit CI path"
|
||||||
|
grep -Fq -- "$server_auth_projection_override" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server smoke must mount the UID 10001 authentication projection"
|
||||||
|
grep -Fq -- "$server_auth_projection_descriptor" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server smoke installation must declare its authentication projection"
|
||||||
|
grep -Fq -- "$server_auth_projection_environment" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server smoke must export the authentication projection root"
|
||||||
|
grep -Fq -- "$server_auth_privileged_configure" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server smoke must publish projected authentication as root"
|
||||||
|
[[ "$(grep -Ec "^${server_fixture_reclamation}\\(\\)|^[[:space:]]+${server_fixture_reclamation}$" \
|
||||||
|
"$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \
|
||||||
|
|| task13_fail "the server smoke must reclaim its root- and core-owned fixture exactly once"
|
||||||
[[ -x "$runner_preparation" ]] \
|
[[ -x "$runner_preparation" ]] \
|
||||||
|| task13_fail "the Linux Docker runner preparation must be executable"
|
|| task13_fail "the Linux Docker runner preparation must be executable"
|
||||||
for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do
|
for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do
|
||||||
@@ -2707,6 +2751,7 @@ task13_initialize() {
|
|||||||
TASK13_PI_AUTH="$TASK13_TMP/pi-auth.json"
|
TASK13_PI_AUTH="$TASK13_TMP/pi-auth.json"
|
||||||
TASK13_SECRETS="$TASK13_TMP/thothii.secrets"
|
TASK13_SECRETS="$TASK13_TMP/thothii.secrets"
|
||||||
TASK13_AUTH_ROOT="$TASK13_TMP/auth"
|
TASK13_AUTH_ROOT="$TASK13_TMP/auth"
|
||||||
|
TASK13_AUTH_RUNTIME_ROOT="$TASK13_TMP/auth-runtime"
|
||||||
TASK13_AUTH_PASSWORD_FILE="$TASK13_TMP/local-auth-password"
|
TASK13_AUTH_PASSWORD_FILE="$TASK13_TMP/local-auth-password"
|
||||||
TASK13_AUTH_RUNTIME_VOLUME="${TASK13_PROJECT}_auth-runtime"
|
TASK13_AUTH_RUNTIME_VOLUME="${TASK13_PROJECT}_auth-runtime"
|
||||||
TASK13_AUTH_PROJECTION_CONTAINER="$TASK13_PROJECT-auth-projection"
|
TASK13_AUTH_PROJECTION_CONTAINER="$TASK13_PROJECT-auth-projection"
|
||||||
@@ -2752,6 +2797,11 @@ task13_require_tools() {
|
|||||||
for command in bash git docker curl node openssl python3 sed awk grep rg sort; do
|
for command in bash git docker curl node openssl python3 sed awk grep rg sort; do
|
||||||
command -v "$command" >/dev/null 2>&1 || task13_fail "$command is required"
|
command -v "$command" >/dev/null 2>&1 || task13_fail "$command is required"
|
||||||
done
|
done
|
||||||
|
if [[ "${TASK13_PROFILE:-local}" == server ]]; then
|
||||||
|
command -v sudo >/dev/null 2>&1 || task13_fail "sudo is required for the Linux server smoke"
|
||||||
|
sudo -n -- true >/dev/null 2>&1 \
|
||||||
|
|| task13_fail "passwordless sudo is required for the Linux server smoke"
|
||||||
|
fi
|
||||||
task13_run_logged "Docker daemon readiness" docker info
|
task13_run_logged "Docker daemon readiness" docker info
|
||||||
task13_run_logged "Docker Compose readiness" docker compose version
|
task13_run_logged "Docker Compose readiness" docker compose version
|
||||||
task13_self_test_source_contract
|
task13_self_test_source_contract
|
||||||
|
|||||||
Reference in New Issue
Block a user