feat(auth): add local and OIDC management to tht

This commit is contained in:
2026-08-16 19:23:30 +02:00
parent d17ad0e95b
commit 9646ae09a0
15 changed files with 992 additions and 13 deletions
+8
View File
@@ -50,6 +50,9 @@ type generatedDescriptor struct {
Branch string `yaml:"branch"`
Access string `yaml:"access"`
} `yaml:"workspaceRepository"`
Authentication struct {
ConfigDirectory string `yaml:"configDirectory"`
} `yaml:"authentication"`
Overrides []string `yaml:"overrides"`
}
@@ -74,6 +77,9 @@ func EnsureFiles(request Request, input io.Reader, output io.Writer) (FilesResul
}
descriptorPath := filepath.Join(directory, descriptorName)
environmentPath := filepath.Join(directory, environmentName)
if err := safeio.EnsurePrivateDirectory(filepath.Join(directory, "auth")); err != nil {
return FilesResult{}, errors.New("authentication directory is unavailable or unsafe")
}
result := FilesResult{DescriptorPath: descriptorPath, EnvironmentPath: environmentPath}
descriptor, environment, err := render(root, descriptorPath, values)
@@ -298,6 +304,7 @@ func installationDirectory(root, id string) (string, error) {
func render(root, descriptorPath string, value answers) ([]byte, []byte, error) {
descriptor := generatedDescriptor{Profile: value.profile, ProjectDirectory: root, EnvFile: filepath.Join(filepath.Dir(descriptorPath), environmentName)}
descriptor.Workspace.Remote, descriptor.Workspace.Branch, descriptor.Workspace.Access = value.workspaceRemote, value.workspaceBranch, value.workspaceAccess
descriptor.Authentication.ConfigDirectory = filepath.Join(filepath.Dir(descriptorPath), "auth")
descriptor.Overrides = []string{filepath.Join(root, "deploy", "compose.git-"+value.workspaceAccess+".yaml")}
descriptorBytes, err := yaml.Marshal(descriptor)
if err != nil {
@@ -308,6 +315,7 @@ func render(root, descriptorPath string, value answers) ([]byte, []byte, error)
"THT_WORKSPACE_GIT_REMOTE=" + dotenvValue(value.workspaceRemote),
"THT_WORKSPACE_GIT_BRANCH=" + dotenvValue(value.workspaceBranch),
"THT_WORKSPACE_INSTALLATION_ID=" + dotenvValue(value.installationID),
"THT_AUTH_CONFIG_ROOT=" + dotenvValue(descriptor.Authentication.ConfigDirectory),
"THT_SECRETS_FILE=" + dotenvValue(value.secretsFile),
"PI_AUTH_FILE=" + dotenvValue(value.piAuthFile),
"THOTH_HTTP_PORT=8080", "THOTH_CORE_HTTP_PORT=8787", "MAX_PI_PROCESSES=4",