fix(deploy): close container final review
This commit is contained in:
Executable
+42
@@ -0,0 +1,42 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
cd "$(dirname "$0")/.."
|
||||
|
||||
tmp=$(mktemp -d)
|
||||
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
||||
|
||||
docker compose --profile external config >"$tmp/base.yaml"
|
||||
grep -q 'host_ip: 127.0.0.1' "$tmp/base.yaml"
|
||||
grep -q 'AUTH_MODE: none' "$tmp/base.yaml"
|
||||
grep -q 'THOTH_PUBLIC_EXPOSURE: "false"' "$tmp/base.yaml"
|
||||
if grep -q 'env_file:' "$tmp/base.yaml"; then
|
||||
echo "base/production-neutral Compose must not load the local env file" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
docker compose -f compose.yaml -f deploy/compose.local.yaml \
|
||||
--profile external config >"$tmp/local.yaml"
|
||||
grep -q 'env_file:' deploy/compose.local.yaml
|
||||
|
||||
for secret in dwh reader writer ca; do printf '%s\n' "test-$secret" >"$tmp/$secret"; done
|
||||
THT_DWH_API_KEY_SECRET_FILE="$tmp/dwh" \
|
||||
THT_VEC_API_KEY_SECRET_FILE="$tmp/reader" \
|
||||
THT_VEC_WRITE_API_KEY_SECRET_FILE="$tmp/writer" \
|
||||
THT_CA_SECRET_FILE="$tmp/ca" \
|
||||
THT_DB_NAME=test THT_DWH_REST_URL=https://dwh.example.test \
|
||||
THT_VEC_REST_URL=https://vector.example.test THT_OLLAMA_URL=https://embed.example.test \
|
||||
docker compose -f compose.yaml -f deploy/compose.production.yaml \
|
||||
--profile external config >"$tmp/production.yaml"
|
||||
grep -q 'AUTH_MODE: upstream' "$tmp/production.yaml"
|
||||
grep -q 'THOTH_PUBLIC_EXPOSURE: "true"' "$tmp/production.yaml"
|
||||
grep -q 'target: thoth_ca.pem' "$tmp/production.yaml"
|
||||
grep -q 'THT_DWH_API_KEY_FILE: /run/secrets/dwh_api_key' "$tmp/production.yaml"
|
||||
|
||||
if awk '/^FROM / && $2 !~ /@sha256:/ { found=1 } END { exit !found }' \
|
||||
docker/core.Dockerfile docker/frontend.Dockerfile; then
|
||||
echo "every Dockerfile base must include an immutable digest" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "container deployment security contract passed."
|
||||
Reference in New Issue
Block a user