fix(ci): preserve secure secret mount ownership
This commit is contained in:
@@ -1018,10 +1018,11 @@ task13_prepare_local_application_secrets() {
|
|||||||
test -f /source/task13-runtime-password && test ! -L /source/task13-runtime-password
|
test -f /source/task13-runtime-password && test ! -L /source/task13-runtime-password
|
||||||
test -z "$(find /target -mindepth 1 -maxdepth 1 -print -quit)"
|
test -z "$(find /target -mindepth 1 -maxdepth 1 -print -quit)"
|
||||||
cp /source/thothii.secrets /source/task13-runtime-password /target/
|
cp /source/thothii.secrets /source/task13-runtime-password /target/
|
||||||
chown 10001:10001 /target /target/thothii.secrets /target/task13-runtime-password
|
chown 0:0 /target
|
||||||
chmod 0700 /target
|
chown 10001:10001 /target/thothii.secrets /target/task13-runtime-password
|
||||||
|
chmod 0755 /target
|
||||||
chmod 0600 /target/thothii.secrets /target/task13-runtime-password
|
chmod 0600 /target/thothii.secrets /target/task13-runtime-password
|
||||||
test "$(stat -c "%u:%g:%a" /target)" = 10001:10001:700
|
test "$(stat -c "%u:%g:%a" /target)" = 0:0:755
|
||||||
test "$(stat -c "%u:%g:%a" /target/thothii.secrets)" = 10001:10001:600
|
test "$(stat -c "%u:%g:%a" /target/thothii.secrets)" = 10001:10001:600
|
||||||
test "$(stat -c "%u:%g:%a" /target/task13-runtime-password)" = 10001:10001:600
|
test "$(stat -c "%u:%g:%a" /target/task13-runtime-password)" = 10001:10001:600
|
||||||
'
|
'
|
||||||
@@ -2471,6 +2472,7 @@ task13_self_test_source_contract() {
|
|||||||
local auth_runtime_mount auth_root_mount auth_projection auth_runtime_owner
|
local auth_runtime_mount auth_root_mount auth_projection auth_runtime_owner
|
||||||
local pi_auth_bind pi_projection registry_runtime_mount registry_root_mount registry_projection
|
local pi_auth_bind pi_projection registry_runtime_mount registry_root_mount registry_projection
|
||||||
local application_secret_bind application_secret_mount application_secret_projection
|
local application_secret_bind application_secret_mount application_secret_projection
|
||||||
|
local application_secret_parent_owner application_secret_file_owner
|
||||||
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||||
workflow="$root/.github/workflows/deployment.yml"
|
workflow="$root/.github/workflows/deployment.yml"
|
||||||
host_network='--network'' host'
|
host_network='--network'' host'
|
||||||
@@ -2488,6 +2490,8 @@ task13_self_test_source_contract() {
|
|||||||
application_secret_bind='$TASK13_''SECRETS:/run/secrets/thothii.secrets:ro'
|
application_secret_bind='$TASK13_''SECRETS:/run/secrets/thothii.secrets:ro'
|
||||||
application_secret_mount='application-secrets:/run/''secrets:ro'
|
application_secret_mount='application-secrets:/run/''secrets:ro'
|
||||||
application_secret_projection='task13_prepare_local_application_''secrets'
|
application_secret_projection='task13_prepare_local_application_''secrets'
|
||||||
|
application_secret_parent_owner='chown 0:''0 /target'
|
||||||
|
application_secret_file_owner='chown 10001:''10001 /target/thothii.secrets /target/task13-runtime-password'
|
||||||
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
|
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
|
||||||
"$root/scripts/unified-deployment-smoke.sh" \
|
"$root/scripts/unified-deployment-smoke.sh" \
|
||||||
"$root/scripts/tht-update-smoke.sh" \
|
"$root/scripts/tht-update-smoke.sh" \
|
||||||
@@ -2528,6 +2532,10 @@ task13_self_test_source_contract() {
|
|||||||
[[ "$(grep -Ec "^${application_secret_projection}\\(\\)|^[[:space:]]+${application_secret_projection}$" \
|
[[ "$(grep -Ec "^${application_secret_projection}\\(\\)|^[[:space:]]+${application_secret_projection}$" \
|
||||||
"$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \
|
"$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \
|
||||||
|| task13_fail "the local application-secret projection must be defined and invoked once"
|
|| task13_fail "the local application-secret projection must be defined and invoked once"
|
||||||
|
grep -Fq -- "$application_secret_parent_owner" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the local application-secret mount root must remain root-owned"
|
||||||
|
grep -Fq -- "$application_secret_file_owner" "$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|
|| task13_fail "the projected application secrets must remain readable only by the core UID"
|
||||||
grep -Eq '^TASK13_BAD_CANDIDATE_IMAGE="[^"[:space:]]+@sha256:[0-9a-f]{64}"$' \
|
grep -Eq '^TASK13_BAD_CANDIDATE_IMAGE="[^"[:space:]]+@sha256:[0-9a-f]{64}"$' \
|
||||||
"$root/scripts/unified-deployment-smoke.sh" \
|
"$root/scripts/unified-deployment-smoke.sh" \
|
||||||
|| task13_fail "the bad rollback candidate must be an immutable digest reference"
|
|| task13_fail "the bad rollback candidate must be an immutable digest reference"
|
||||||
|
|||||||
Reference in New Issue
Block a user