fix(backend): inject provider credentials from file
This commit is contained in:
@@ -36,11 +36,12 @@ docker compose -f compose.yaml -f deploy/compose.local.yaml \
|
||||
--profile external config >"$tmp/local.yaml"
|
||||
grep -q 'env_file:' deploy/compose.local.yaml
|
||||
|
||||
for secret in dwh reader writer ca; do printf '%s\n' "test-$secret" >"$tmp/$secret"; done
|
||||
for secret in dwh reader writer ca model; do printf '%s\n' "test-$secret" >"$tmp/$secret"; done
|
||||
THT_DWH_API_KEY_SECRET_FILE="$tmp/dwh" \
|
||||
THT_VEC_API_KEY_SECRET_FILE="$tmp/reader" \
|
||||
THT_VEC_WRITE_API_KEY_SECRET_FILE="$tmp/writer" \
|
||||
THT_CA_SECRET_FILE="$tmp/ca" \
|
||||
THT_MODEL_API_KEY_SECRET_FILE="$tmp/model" \
|
||||
THT_DB_NAME=test THT_DWH_REST_URL=https://dwh.example.test \
|
||||
THT_VEC_REST_URL=https://vector.example.test THT_OLLAMA_URL=https://embed.example.test \
|
||||
docker compose -f compose.yaml -f deploy/compose.production.yaml \
|
||||
@@ -49,6 +50,22 @@ grep -q 'AUTH_MODE: upstream' "$tmp/production.yaml"
|
||||
grep -q 'THOTH_PUBLIC_EXPOSURE: "true"' "$tmp/production.yaml"
|
||||
grep -q 'target: thoth_ca.pem' "$tmp/production.yaml"
|
||||
grep -q 'THT_DWH_API_KEY_FILE: /run/secrets/dwh_api_key' "$tmp/production.yaml"
|
||||
grep -q 'THT_MODEL_API_KEY_FILE: /run/secrets/model_api_key' "$tmp/production.yaml"
|
||||
grep -q 'target: model_api_key' "$tmp/production.yaml"
|
||||
if grep -q 'test-model' "$tmp/production.yaml"; then
|
||||
echo "rendered production config leaked the model API key" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if PI_PROVIDER_API_KEY='must-not-leak' ./docker/core-entrypoint.sh doctor 2>"$tmp/legacy-model.err"; then
|
||||
echo "legacy generic model credential was accepted" >&2
|
||||
exit 1
|
||||
fi
|
||||
grep -q 'PI_PROVIDER_API_KEY is unsupported' "$tmp/legacy-model.err"
|
||||
if grep -q 'must-not-leak' "$tmp/legacy-model.err"; then
|
||||
echo "legacy model credential leaked through entrypoint diagnostics" >&2
|
||||
exit 1
|
||||
fi
|
||||
if grep -q 'THT_VECTOR_READER_PASSWORD_FILE\|THT_VECTOR_WRITER_PASSWORD_FILE\|target: vector_reader_password\|target: vector_writer_password' "$tmp/production.yaml"; then
|
||||
echo "production external config contains local direct vector secrets" >&2
|
||||
exit 1
|
||||
|
||||
Reference in New Issue
Block a user