fix: enforce server trust boundaries
This commit is contained in:
@@ -15,7 +15,7 @@ first startup. Keep storage separated:
|
||||
/srv/thothii/data/ # settings, session data, Pi state as applicable
|
||||
/srv/thothii/workspace-registry/ # repo/, snapshots/, state/, locks/
|
||||
/srv/thothii/secrets/ # Git and connector secret files, setgid mode 2750
|
||||
/srv/thothii/operator/ # untracked Compose/.env, setgid mode 2750
|
||||
/srv/thothii/operator/ # untracked operator files, setgid mode 2770
|
||||
```
|
||||
|
||||
Permit outbound TCP only to approved Git/Gitea, DWH, vector, embedding, and bastion endpoints.
|
||||
@@ -86,7 +86,8 @@ Variable names derive from the immutable ID: `north-star-research` becomes `NORT
|
||||
Copy [the bindings env example](examples/workspace-bindings.env.example) to the protected operator
|
||||
directory. Every path-valued `*_FILE` entry needs an absolute host-only `*_SOURCE` path. Generate
|
||||
the untracked connector override from those files during bootstrap; do not copy or maintain a
|
||||
workspace-specific Compose override.
|
||||
workspace-specific Compose override. Operator-managed path-only files use owner UID 10001, group
|
||||
`thothii-ops`, and mode `0660`; secret files remain `0640` and non-group-writable.
|
||||
|
||||
## Direct PostgreSQL, REST, and SSH tunnel bindings
|
||||
|
||||
@@ -163,6 +164,7 @@ Generate the connector override, then use the installation-aware operator CLI. B
|
||||
`thothctl` requires only Docker and no Go knowledge. From a trusted maintenance shell:
|
||||
|
||||
```sh
|
||||
umask 0007
|
||||
THT_SOURCE_ROOT=/srv/thothii/source/ThothII
|
||||
THT_OPERATOR_ENV=/srv/thothii/operator/server.env
|
||||
THT_WORKSPACE_BINDINGS_ENV_FILE=/srv/thothii/operator/workspace-bindings.env
|
||||
|
||||
+15
-7
@@ -64,7 +64,7 @@ files only. Backups are separate from live data.
|
||||
|
||||
```sh
|
||||
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii/source
|
||||
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii/operator
|
||||
sudo install -d -o 10001 -g thothii-ops -m 2770 /srv/thothii/operator
|
||||
sudo install -d -o 10001 -g thothii-ops -m 2750 /srv/thothii/secrets
|
||||
sudo install -d -o 10001 -g 10001 -m 0750 /srv/thothii/data
|
||||
sudo install -d -o 10001 -g 10001 -m 0750 /srv/thothii/pi-state
|
||||
@@ -72,9 +72,9 @@ sudo install -d -o 10001 -g 10001 -m 0750 /srv/thothii/workspace-registry
|
||||
sudo install -d -o root -g root -m 0700 /srv/thothii-backups
|
||||
```
|
||||
|
||||
Do not make `/srv/thothii` a shared application directory. The source checkout may be read by the
|
||||
operator, while secret contents and writable data remain limited to reviewed administrators and
|
||||
UID 10001.
|
||||
The human operator can write only `operator`; setgid keeps generated files in `thothii-ops`.
|
||||
`source`, `secrets`, and all runtime bind trees remain non-group-writable. Do not make
|
||||
`/srv/thothii` a shared application directory.
|
||||
|
||||
## Firewall and network boundaries
|
||||
|
||||
@@ -190,10 +190,12 @@ sudo -u thothii cp docs/install/examples/thothii-installation.server.yaml \
|
||||
/srv/thothii/operator/thothii-installation.yaml
|
||||
sudo chown 10001:thothii-ops /srv/thothii/operator/server.env \
|
||||
/srv/thothii/operator/thothii-installation.yaml
|
||||
sudo chmod 0640 /srv/thothii/operator/server.env \
|
||||
sudo chmod 0660 /srv/thothii/operator/server.env \
|
||||
/srv/thothii/operator/thothii-installation.yaml
|
||||
```
|
||||
|
||||
The named human operator can now edit both placeholder files without `sudo`; use an editor that
|
||||
preserves the group, or create replacements under `umask 0007` in the setgid operator directory.
|
||||
Replace every placeholder with an absolute path. Use exactly one Git transport override. For
|
||||
HTTPS, replace `deploy/compose.git-ssh.yaml` with `deploy/compose.git-https.yaml`. Keep the required
|
||||
session-server overlay and generated connector-secret override. Optional host-gateway or pinned
|
||||
@@ -260,11 +262,17 @@ Build the operator binaries with Docker. No Go installation or Go knowledge is r
|
||||
|
||||
```sh
|
||||
cd /srv/thothii/source/ThothII
|
||||
bash scripts/build-thothctl.sh
|
||||
sudo install -o root -g thothii-ops -m 0750 dist/thothctl/thothctl-linux-amd64 \
|
||||
THT_THOTHCTL_OUTPUT_DIRECTORY=/srv/thothii/operator/build-output \
|
||||
bash scripts/build-thothctl.sh
|
||||
sudo install -o root -g thothii-ops -m 0750 \
|
||||
/srv/thothii/operator/build-output/thothctl-linux-amd64 \
|
||||
/srv/thothii/operator/thothctl
|
||||
```
|
||||
|
||||
The source checkout stays read-only to the human. The explicit output directory is the only build
|
||||
write boundary; the build script rejects relative or non-canonical output paths. After installation,
|
||||
remove or retain `build-output` according to the site's reviewed artifact policy.
|
||||
|
||||
Use `thothctl-linux-arm64` on an ARM64 server. Set these variables in the maintenance shell; do
|
||||
not source `server.env` as shell code:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user