feat(auth): integrate authentication with installation lifecycle

This commit is contained in:
2026-08-17 20:21:42 +02:00
parent 0a2c667231
commit 9558eaa508
30 changed files with 756 additions and 120 deletions
+17
View File
@@ -56,6 +56,19 @@ if (core.environment?.THT_SECRETS_FILE !== "/run/secrets/thothii.secrets") {
if (core.environment?.THT_PI_AUTH_FILE !== "/home/thoth/.pi/agent/auth.json") {
throw new Error(`${name}: core does not declare the mounted Pi authentication source`);
}
if (core.environment?.THT_AUTH_CONFIG_FILE !== "/run/thothii-auth/auth.yaml"
|| core.environment?.THT_AUTH_STATE_ROOT !== "/data/auth") {
throw new Error(`${name}: core authentication paths do not use the canonical locations`);
}
const authConfig = (core.volumes || []).filter((mount) => mount.target === "/run/thothii-auth");
if (authConfig.length !== 1 || authConfig[0].type !== "bind" || !authConfig[0].read_only) {
throw new Error(`${name}: core must receive exactly one read-only authentication config bind`);
}
if ((config.services["workspace-maintenance"]?.volumes || []).some(
(mount) => mount.target === "/run/thothii-auth" || mount.target === "/data/auth",
)) {
throw new Error(`${name}: workspace-maintenance received authentication data`);
}
if ((config.services.frontend?.secrets || []).length !== 0) {
throw new Error(`${name}: frontend must not receive runtime secrets`);
}
@@ -113,10 +126,13 @@ write_secret "$fixture_root/https-credentials" 'fixture-https-credentials'
write_secret "$fixture_root/https-ca.pem" 'fixture-https-ca'
write_secret "$fixture_root/dwh-password" 'fixture-dwh-password'
write_secret "$fixture_root/vector-api-key" 'fixture-vector-api-key'
mkdir -p "$fixture_root/auth"
chmod 0700 "$fixture_root/auth"
printf '%s\n' \
'THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git' \
"PI_AUTH_FILE=$fixture_root/pi-auth.json" \
"THT_SECRETS_FILE=$fixture_root/thothii.secrets" \
"THT_AUTH_CONFIG_ROOT=$fixture_root/auth" \
"THT_WORKSPACE_BINDINGS_ENV_FILE=$fixture_root/workspace-bindings.env" \
"THT_WORKSPACE_GIT_SSH_KEY_FILE=$fixture_root/ssh-private-key" \
"THT_WORKSPACE_GIT_KNOWN_HOSTS_FILE=$fixture_root/ssh-known-hosts" \
@@ -188,6 +204,7 @@ printf '%s\n' \
'THT_WORKSPACE_GIT_REMOTE=https://git.example.invalid/platform/thoth-workspaces.git' \
"PI_AUTH_FILE=$fixture_root/pi-auth.json" \
"THT_SECRETS_FILE=$fixture_root/thothii.secrets" \
"THT_AUTH_CONFIG_ROOT=$fixture_root/auth" \
"THT_WS_NORTH_STAR_RESEARCH_DWH_PASSWORD_SOURCE=$fixture_root/dwh-password" \
"THT_WS_NORTH_STAR_RESEARCH_VECTOR_API_KEY_SOURCE=$fixture_root/vector-api-key" \
>"$fixture_root/operator-with-vector.env"