fix: enforce server trust boundaries

This commit is contained in:
2026-08-05 11:42:35 +02:00
parent 96fe5bfa79
commit a94affd6ac
10 changed files with 511 additions and 40 deletions
+4 -2
View File
@@ -15,7 +15,7 @@ first startup. Keep storage separated:
/srv/thothii/data/ # settings, session data, Pi state as applicable
/srv/thothii/workspace-registry/ # repo/, snapshots/, state/, locks/
/srv/thothii/secrets/ # Git and connector secret files, setgid mode 2750
/srv/thothii/operator/ # untracked Compose/.env, setgid mode 2750
/srv/thothii/operator/ # untracked operator files, setgid mode 2770
```
Permit outbound TCP only to approved Git/Gitea, DWH, vector, embedding, and bastion endpoints.
@@ -86,7 +86,8 @@ Variable names derive from the immutable ID: `north-star-research` becomes `NORT
Copy [the bindings env example](examples/workspace-bindings.env.example) to the protected operator
directory. Every path-valued `*_FILE` entry needs an absolute host-only `*_SOURCE` path. Generate
the untracked connector override from those files during bootstrap; do not copy or maintain a
workspace-specific Compose override.
workspace-specific Compose override. Operator-managed path-only files use owner UID 10001, group
`thothii-ops`, and mode `0660`; secret files remain `0640` and non-group-writable.
## Direct PostgreSQL, REST, and SSH tunnel bindings
@@ -163,6 +164,7 @@ Generate the connector override, then use the installation-aware operator CLI. B
`thothctl` requires only Docker and no Go knowledge. From a trusted maintenance shell:
```sh
umask 0007
THT_SOURCE_ROOT=/srv/thothii/source/ThothII
THT_OPERATOR_ENV=/srv/thothii/operator/server.env
THT_WORKSPACE_BINDINGS_ENV_FILE=/srv/thothii/operator/workspace-bindings.env
+15 -7
View File
@@ -64,7 +64,7 @@ files only. Backups are separate from live data.
```sh
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii/source
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii/operator
sudo install -d -o 10001 -g thothii-ops -m 2770 /srv/thothii/operator
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii/secrets
sudo install -d -o 10001 -g 10001 -m 0750 /srv/thothii/data
sudo install -d -o 10001 -g 10001 -m 0750 /srv/thothii/pi-state
@@ -72,9 +72,9 @@ sudo install -d -o 10001 -g 10001 -m 0750 /srv/thothii/workspace-registry
sudo install -d -o root -g root -m 0700 /srv/thothii-backups
```
Do not make `/srv/thothii` a shared application directory. The source checkout may be read by the
operator, while secret contents and writable data remain limited to reviewed administrators and
UID 10001.
The human operator can write only `operator`; setgid keeps generated files in `thothii-ops`.
`source`, `secrets`, and all runtime bind trees remain non-group-writable. Do not make
`/srv/thothii` a shared application directory.
## Firewall and network boundaries
@@ -190,10 +190,12 @@ sudo -u thothii cp docs/install/examples/thothii-installation.server.yaml \
/srv/thothii/operator/thothii-installation.yaml
sudo chown 10001:thothii-ops /srv/thothii/operator/server.env \
/srv/thothii/operator/thothii-installation.yaml
sudo chmod 0640 /srv/thothii/operator/server.env \
sudo chmod 0660 /srv/thothii/operator/server.env \
/srv/thothii/operator/thothii-installation.yaml
```
The named human operator can now edit both placeholder files without `sudo`; use an editor that
preserves the group, or create replacements under `umask 0007` in the setgid operator directory.
Replace every placeholder with an absolute path. Use exactly one Git transport override. For
HTTPS, replace `deploy/compose.git-ssh.yaml` with `deploy/compose.git-https.yaml`. Keep the required
session-server overlay and generated connector-secret override. Optional host-gateway or pinned
@@ -260,11 +262,17 @@ Build the operator binaries with Docker. No Go installation or Go knowledge is r
```sh
cd /srv/thothii/source/ThothII
bash scripts/build-thothctl.sh
sudo install -o root -g thothii-ops -m 0750 dist/thothctl/thothctl-linux-amd64 \
THT_THOTHCTL_OUTPUT_DIRECTORY=/srv/thothii/operator/build-output \
bash scripts/build-thothctl.sh
sudo install -o root -g thothii-ops -m 0750 \
/srv/thothii/operator/build-output/thothctl-linux-amd64 \
/srv/thothii/operator/thothctl
```
The source checkout stays read-only to the human. The explicit output directory is the only build
write boundary; the build script rejects relative or non-canonical output paths. After installation,
remove or retain `build-output` according to the site's reviewed artifact policy.
Use `thothctl-linux-arm64` on an ARM64 server. Set these variables in the maintenance shell; do
not source `server.env` as shell code: