feat(auth): integrate authentication with installation lifecycle
This commit is contained in:
@@ -20,7 +20,8 @@ done
|
||||
printf '%s\n' '{}' >"$tmp/pi-auth.json"
|
||||
printf '%s\n' 'THT_MODEL_API_KEY=fixture-model-api-key' >"$tmp/thothii.secrets"
|
||||
chmod 0600 "$tmp/pi-auth.json" "$tmp/thothii.secrets"
|
||||
mkdir -p "$tmp/data" "$tmp/pi-state" "$tmp/workspace-registry"
|
||||
mkdir -p "$tmp/data" "$tmp/pi-state" "$tmp/workspace-registry" "$tmp/auth"
|
||||
chmod 0700 "$tmp/auth"
|
||||
"$root/scripts/prepare-server-pi-state.sh" "$tmp/pi-state" "$(id -u)" "$(id -g)" >/dev/null
|
||||
printf '%s\n' 'fixture-session-password' >"$tmp/session-runtime-password"
|
||||
printf '%s\n' 'fixture-session-migrator-password' >"$tmp/session-migrator-password"
|
||||
@@ -34,7 +35,8 @@ for profile in local server; do
|
||||
printf '%s\n' \
|
||||
'THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git' \
|
||||
"PI_AUTH_FILE=$tmp/pi-auth.json" \
|
||||
"THT_SECRETS_FILE=$tmp/thothii.secrets"
|
||||
"THT_SECRETS_FILE=$tmp/thothii.secrets" \
|
||||
"THT_AUTH_CONFIG_ROOT=$tmp/auth"
|
||||
if [[ "$profile" == server ]]; then
|
||||
printf '%s\n' \
|
||||
"THT_DATA_ROOT=$tmp/data" \
|
||||
@@ -73,6 +75,23 @@ if (!config.services.core.volumes?.some(
|
||||
)) {
|
||||
throw new Error(profile + ": install stack lacks the read-only Pi auth file");
|
||||
}
|
||||
const authConfig = config.services.core.volumes?.filter((mount) => mount.target === "/run/thothii-auth") || [];
|
||||
if (authConfig.length !== 1 || authConfig[0].type !== "bind" || !authConfig[0].read_only) {
|
||||
throw new Error(profile + ": core must receive one read-only authentication config bind");
|
||||
}
|
||||
if (profile === "local") {
|
||||
const authState = config.services.core.volumes?.filter((mount) => mount.target === "/data/auth") || [];
|
||||
if (authState.length !== 1 || authState[0].type !== "volume" || authState[0].source !== "auth-state") {
|
||||
throw new Error("local: core must receive the auth-state volume");
|
||||
}
|
||||
} else if (!config.services.core.volumes?.some((mount) => mount.target === "/data" && mount.type === "bind")) {
|
||||
throw new Error("server: core must preserve the whole /data bind that contains auth state");
|
||||
}
|
||||
if ((config.services["workspace-maintenance"]?.volumes || []).some(
|
||||
(mount) => mount.target === "/run/thothii-auth" || mount.target === "/data/auth",
|
||||
)) {
|
||||
throw new Error(profile + ": workspace-maintenance received authentication data");
|
||||
}
|
||||
if ((config.services.frontend.secrets || []).length !== 0) {
|
||||
throw new Error(profile + ": frontend received runtime secrets");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user