fix: enforce server trust boundaries

This commit is contained in:
2026-08-05 11:42:35 +02:00
parent 96fe5bfa79
commit a94affd6ac
10 changed files with 511 additions and 40 deletions
+81
View File
@@ -0,0 +1,81 @@
#!/usr/bin/env bash
# Execute the documented server ownership model with distinct runtime and human operator IDs.
set -euo pipefail
root="$(cd "$(dirname "$0")/.." && pwd -P)"
image='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651'
docker run --rm --volume "$root:/repository:ro" "$image" /bin/bash -ceu '
groupadd --gid 10001 thothii
useradd --uid 10001 --gid 10001 --no-create-home --shell /usr/sbin/nologin thothii
groupadd --gid 20001 operator-primary
groupadd --gid 20002 thothii-ops
groupadd --gid 20003 docker
useradd --uid 20001 --gid 20001 --groups 20002,20003 --create-home --shell /bin/bash operator
install -d -o 10001 -g 20002 -m 2750 /srv/thothii/source
install -d -o 10001 -g 20002 -m 2770 /srv/thothii/operator
install -d -o 10001 -g 20002 -m 2750 /srv/thothii/secrets
install -d -o 10001 -g 10001 -m 0750 /srv/thothii/data /srv/thothii/pi-state /srv/thothii/workspace-registry
install -d -o 10001 -g 20002 -m 2750 /srv/thothii/source/ThothII /srv/thothii/source/ThothII/scripts
install -o 10001 -g 20002 -m 0750 /repository/scripts/build-thothctl.sh /srv/thothii/source/ThothII/scripts/build-thothctl.sh
install -o 10001 -g 20002 -m 0750 /repository/scripts/generate-connector-secrets-override.sh /srv/thothii/source/ThothII/scripts/generate-connector-secrets-override.sh
printf "%s\n" "PLACEHOLDER=replace-me" "THT_WS_TEST_DWH_PASSWORD_SOURCE=/srv/thothii/secrets/dwh-password" > /srv/thothii/operator/server.env
printf "%s\n" "projectDirectory: replace-me" > /srv/thothii/operator/thothii-installation.yaml
printf "%s\n" "THT_WS_TEST_DWH_PASSWORD_FILE=/run/secrets/test-dwh-password" > /srv/thothii/operator/workspace-bindings.env
printf "%s\n" "operator-readable-secret" > /srv/thothii/secrets/dwh-password
chown 10001:20002 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml /srv/thothii/operator/workspace-bindings.env /srv/thothii/secrets/dwh-password
chmod 0660 /srv/thothii/operator/server.env /srv/thothii/operator/thothii-installation.yaml /srv/thothii/operator/workspace-bindings.env
chmod 0640 /srv/thothii/secrets/dwh-password
printf "%s\n" \
"#!/bin/bash" \
"set -euo pipefail" \
"if [[ \"\${1:-}\" == build ]]; then" \
" destination=; for argument in \"\$@\"; do case \"\$argument\" in type=local,dest=*) destination=\"\${argument#type=local,dest=}\" ;; esac; done" \
" test -n \"\$destination\"; mkdir -p \"\$destination\"" \
" printf \"%s\\n\" \"#!/bin/bash\" \"set -euo pipefail\" \"test -r \\\"\\\$2\\\"\" \"test -r /srv/thothii/secrets/dwh-password\" \"docker compose up --detach\" > \"\$destination/thothctl-linux-amd64\"" \
" chmod 0750 \"\$destination/thothctl-linux-amd64\"; exit 0" \
"fi" \
"test \"\${1:-}\" = compose; : > /srv/thothii/operator/start.marker" \
> /usr/local/bin/docker
chmod 0755 /usr/local/bin/docker
runuser --user operator -- /bin/bash -ceu '\''
umask 0007
sed -i "s/replace-me/ready/" /srv/thothii/operator/server.env
sed -i "s#replace-me#/srv/thothii/source/ThothII#" /srv/thothii/operator/thothii-installation.yaml
/srv/thothii/source/ThothII/scripts/generate-connector-secrets-override.sh \
--bindings-env /srv/thothii/operator/workspace-bindings.env \
--operator-env /srv/thothii/operator/server.env \
--output /srv/thothii/operator/connector-secrets.server.yaml
test -r /srv/thothii/secrets/dwh-password
if (printf tamper >> /srv/thothii/secrets/dwh-password) 2>/dev/null; then exit 41; fi
if touch /srv/thothii/source/operator-must-not-write 2>/dev/null; then exit 42; fi
if touch /srv/thothii/data/operator-must-not-write 2>/dev/null; then exit 43; fi
THT_THOTHCTL_OUTPUT_DIRECTORY=/srv/thothii/operator/build-output \
/srv/thothii/source/ThothII/scripts/build-thothctl.sh
if THT_THOTHCTL_OUTPUT_DIRECTORY=relative-output \
/srv/thothii/source/ThothII/scripts/build-thothctl.sh 2>/dev/null; then exit 44; fi
root_output_error=/srv/thothii/operator/root-output.error
if THT_THOTHCTL_OUTPUT_DIRECTORY=/ \
/srv/thothii/source/ThothII/scripts/build-thothctl.sh 2>"$root_output_error"; then exit 45; fi
grep -Fq "THT_THOTHCTL_OUTPUT_DIRECTORY must be an absolute canonical path" \
"$root_output_error" || exit 46
rm -f "$root_output_error"
/srv/thothii/operator/build-output/thothctl-linux-amd64 \
--installation /srv/thothii/operator/thothii-installation.yaml start
'\''
test "$(stat -c %u:%g /srv/thothii/operator/connector-secrets.server.yaml)" = 20001:20002
test "$(stat -c %a /srv/thothii/operator/connector-secrets.server.yaml)" = 660
test "$(stat -c %u:%g /srv/thothii/operator/build-output/thothctl-linux-amd64)" = 20001:20002
test "$(stat -c %a /srv/thothii/operator/build-output/thothctl-linux-amd64)" = 750
test -f /srv/thothii/operator/start.marker
test ! -e /srv/thothii/source/operator-must-not-write
test ! -e /srv/thothii/data/operator-must-not-write
test "$(cat /srv/thothii/secrets/dwh-password)" = operator-readable-secret
'
echo "distinct server operator UID/GID fixture passed"