fix(ci): verify projected server auth layout
This commit is contained in:
@@ -1592,7 +1592,18 @@ task13_assert_server_runtime() {
|
|||||||
|| task13_fail "server frontend did not use the smoke-built frontend image"
|
|| task13_fail "server frontend did not use the smoke-built frontend image"
|
||||||
task13_compose_logged "verify server runtime configuration and secret readability" exec -T core sh -ceu '
|
task13_compose_logged "verify server runtime configuration and secret readability" exec -T core sh -ceu '
|
||||||
check_readable() { test -r "$1" || { printf "server precondition failed: unreadable %s\n" "$1" >&2; exit 1; }; }
|
check_readable() { test -r "$1" || { printf "server precondition failed: unreadable %s\n" "$1" >&2; exit 1; }; }
|
||||||
check_readable /run/thothii-auth/auth.yaml
|
check_readable /run/thothii-auth/CURRENT
|
||||||
|
projection_generation="$(node -e '\''
|
||||||
|
const fs = require("node:fs");
|
||||||
|
const selector = JSON.parse(fs.readFileSync("/run/thothii-auth/CURRENT", "utf8"));
|
||||||
|
if (selector.version !== 1 || selector.state !== "ready" ||
|
||||||
|
typeof selector.generation !== "string" || !/^[0-9a-f]{64}$/.test(selector.generation)) {
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(selector.generation);
|
||||||
|
'\'')" || { printf "server precondition failed: invalid authentication projection selector\n" >&2; exit 1; }
|
||||||
|
check_readable "/run/thothii-auth/generations/$projection_generation/auth.yaml"
|
||||||
|
check_readable "/run/thothii-auth/generations/$projection_generation/manifest.json"
|
||||||
test -d /data/auth || { printf "server precondition failed: missing /data/auth\n" >&2; exit 1; }
|
test -d /data/auth || { printf "server precondition failed: missing /data/auth\n" >&2; exit 1; }
|
||||||
test -z "${AUTH_MODE+x}" || { printf "server precondition failed: AUTH_MODE must be unset\n" >&2; exit 1; }
|
test -z "${AUTH_MODE+x}" || { printf "server precondition failed: AUTH_MODE must be unset\n" >&2; exit 1; }
|
||||||
test "$THT_SESSION_STORAGE" = postgres || { printf "server precondition failed: session storage\n" >&2; exit 1; }
|
test "$THT_SESSION_STORAGE" = postgres || { printf "server precondition failed: session storage\n" >&2; exit 1; }
|
||||||
@@ -2557,6 +2568,7 @@ task13_self_test_source_contract() {
|
|||||||
local server_auth_projection_override server_auth_projection_descriptor
|
local server_auth_projection_override server_auth_projection_descriptor
|
||||||
local server_auth_projection_environment server_auth_privileged_configure
|
local server_auth_projection_environment server_auth_privileged_configure
|
||||||
local server_fixture_reclamation server_runtime_config_probe server_workspace_config_permission
|
local server_fixture_reclamation server_runtime_config_probe server_workspace_config_permission
|
||||||
|
local server_runtime_selector_probe server_runtime_generation_probe server_runtime_direct_file_probe
|
||||||
local server_secret_source_owner server_secret_source_preparation server_tht_wrapper
|
local server_secret_source_owner server_secret_source_preparation server_tht_wrapper
|
||||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||||
workflow="$root/.github/workflows/deployment.yml"
|
workflow="$root/.github/workflows/deployment.yml"
|
||||||
@@ -2589,6 +2601,9 @@ task13_self_test_source_contract() {
|
|||||||
server_auth_privileged_configure='sudo -n -- "$TASK13_''THT"'
|
server_auth_privileged_configure='sudo -n -- "$TASK13_''THT"'
|
||||||
server_fixture_reclamation='task13_reclaim_server_fixture_''ownership'
|
server_fixture_reclamation='task13_reclaim_server_fixture_''ownership'
|
||||||
server_runtime_config_probe='task13_compose_''logged "verify server runtime configuration and secret readability"'
|
server_runtime_config_probe='task13_compose_''logged "verify server runtime configuration and secret readability"'
|
||||||
|
server_runtime_selector_probe='check_readable /run/thothii-auth/''CURRENT'
|
||||||
|
server_runtime_generation_probe='check_readable "/run/thothii-auth/generations/$projection_generation/''auth.yaml"'
|
||||||
|
server_runtime_direct_file_probe='check_readable /run/thothii-auth/''auth.yaml'
|
||||||
server_secret_source_preparation='task13_prepare_server_secret_''sources'
|
server_secret_source_preparation='task13_prepare_server_secret_''sources'
|
||||||
server_secret_source_owner='chown 10001:''10001 -- "$TASK13_SECRETS" "$TASK13_PI_AUTH"'
|
server_secret_source_owner='chown 10001:''10001 -- "$TASK13_SECRETS" "$TASK13_PI_AUTH"'
|
||||||
server_tht_wrapper='task13_server_''tht'
|
server_tht_wrapper='task13_server_''tht'
|
||||||
@@ -2670,6 +2685,12 @@ task13_self_test_source_contract() {
|
|||||||
|| task13_fail "the server smoke must reclaim its root- and core-owned fixture exactly once"
|
|| task13_fail "the server smoke must reclaim its root- and core-owned fixture exactly once"
|
||||||
grep -Fq -- "$server_runtime_config_probe" "$root/scripts/unified-deployment-smoke.sh" \
|
grep -Fq -- "$server_runtime_config_probe" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|| task13_fail "the server runtime preconditions must emit a named diagnostic"
|
|| task13_fail "the server runtime preconditions must emit a named diagnostic"
|
||||||
|
grep -Fq -- "$server_runtime_selector_probe" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server runtime preconditions must verify the projection selector"
|
||||||
|
grep -Fq -- "$server_runtime_generation_probe" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server runtime preconditions must verify the selected generation"
|
||||||
|
! grep -Fq -- "$server_runtime_direct_file_probe" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the server runtime preconditions must not require the forbidden direct-file fallback"
|
||||||
grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \
|
grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|| task13_fail "the server workspace fixture must be readable by the container UID"
|
|| task13_fail "the server workspace fixture must be readable by the container UID"
|
||||||
[[ "$(grep -Ec "^${server_secret_source_preparation}\\(\\)|^[[:space:]]+${server_secret_source_preparation}$" \
|
[[ "$(grep -Ec "^${server_secret_source_preparation}\\(\\)|^[[:space:]]+${server_secret_source_preparation}$" \
|
||||||
|
|||||||
Reference in New Issue
Block a user