feat(auth): add local and OIDC management to tht
This commit is contained in:
@@ -50,6 +50,9 @@ type generatedDescriptor struct {
|
||||
Branch string `yaml:"branch"`
|
||||
Access string `yaml:"access"`
|
||||
} `yaml:"workspaceRepository"`
|
||||
Authentication struct {
|
||||
ConfigDirectory string `yaml:"configDirectory"`
|
||||
} `yaml:"authentication"`
|
||||
Overrides []string `yaml:"overrides"`
|
||||
}
|
||||
|
||||
@@ -74,6 +77,9 @@ func EnsureFiles(request Request, input io.Reader, output io.Writer) (FilesResul
|
||||
}
|
||||
descriptorPath := filepath.Join(directory, descriptorName)
|
||||
environmentPath := filepath.Join(directory, environmentName)
|
||||
if err := safeio.EnsurePrivateDirectory(filepath.Join(directory, "auth")); err != nil {
|
||||
return FilesResult{}, errors.New("authentication directory is unavailable or unsafe")
|
||||
}
|
||||
result := FilesResult{DescriptorPath: descriptorPath, EnvironmentPath: environmentPath}
|
||||
|
||||
descriptor, environment, err := render(root, descriptorPath, values)
|
||||
@@ -298,6 +304,7 @@ func installationDirectory(root, id string) (string, error) {
|
||||
func render(root, descriptorPath string, value answers) ([]byte, []byte, error) {
|
||||
descriptor := generatedDescriptor{Profile: value.profile, ProjectDirectory: root, EnvFile: filepath.Join(filepath.Dir(descriptorPath), environmentName)}
|
||||
descriptor.Workspace.Remote, descriptor.Workspace.Branch, descriptor.Workspace.Access = value.workspaceRemote, value.workspaceBranch, value.workspaceAccess
|
||||
descriptor.Authentication.ConfigDirectory = filepath.Join(filepath.Dir(descriptorPath), "auth")
|
||||
descriptor.Overrides = []string{filepath.Join(root, "deploy", "compose.git-"+value.workspaceAccess+".yaml")}
|
||||
descriptorBytes, err := yaml.Marshal(descriptor)
|
||||
if err != nil {
|
||||
@@ -308,6 +315,7 @@ func render(root, descriptorPath string, value answers) ([]byte, []byte, error)
|
||||
"THT_WORKSPACE_GIT_REMOTE=" + dotenvValue(value.workspaceRemote),
|
||||
"THT_WORKSPACE_GIT_BRANCH=" + dotenvValue(value.workspaceBranch),
|
||||
"THT_WORKSPACE_INSTALLATION_ID=" + dotenvValue(value.installationID),
|
||||
"THT_AUTH_CONFIG_ROOT=" + dotenvValue(descriptor.Authentication.ConfigDirectory),
|
||||
"THT_SECRETS_FILE=" + dotenvValue(value.secretsFile),
|
||||
"PI_AUTH_FILE=" + dotenvValue(value.piAuthFile),
|
||||
"THOTH_HTTP_PORT=8080", "THOTH_CORE_HTTP_PORT=8787", "MAX_PI_PROCESSES=4",
|
||||
|
||||
Reference in New Issue
Block a user