fix(ci): project local auth for core runtime

This commit is contained in:
2026-08-25 17:35:29 +02:00
parent 8980c35198
commit f0e78b1ce3
2 changed files with 51 additions and 2 deletions
@@ -40,7 +40,7 @@ const reviewedExpandableBlocks = new Map([
]], ]],
["scripts/unified-deployment-smoke.sh", [ ["scripts/unified-deployment-smoke.sh", [
{ sha256: "ca0c17d9ff8dc0fbe018fc1c5510eb33bc667a936fbe44a9be2d311390576825", rationale: "Generates reviewed Task 13 runtime configuration." }, { sha256: "ca0c17d9ff8dc0fbe018fc1c5510eb33bc667a936fbe44a9be2d311390576825", rationale: "Generates reviewed Task 13 runtime configuration." },
{ sha256: "edf4d9c35b0328ec1549e5a529eceb1044434850b85786091ae8a0c6620b39d7", rationale: "Generates the reviewed local Task 13 Compose override." }, { sha256: "714d44082040affc28114a6a462164e3165c5c9fb2eefcd27f764c8dac7e161e", rationale: "Generates the reviewed local Task 13 Compose override." },
{ sha256: "c556f7d910d0788e219b042957e6b307cb9925b43920c680535d0d3a6dcbdb25", rationale: "Generates the reviewed local Task 13 installation descriptor." }, { sha256: "c556f7d910d0788e219b042957e6b307cb9925b43920c680535d0d3a6dcbdb25", rationale: "Generates the reviewed local Task 13 installation descriptor." },
{ sha256: "c0078c68bd42a8668fbcb849888531e5e56109579df1ff96140a9e91b1efea56", rationale: "Generates the reviewed server Task 13 Compose override." }, { sha256: "c0078c68bd42a8668fbcb849888531e5e56109579df1ff96140a9e91b1efea56", rationale: "Generates the reviewed server Task 13 Compose override." },
{ sha256: "b34a2b4ffaa72e01efb64a7a28b13513527538d837b2f35b6ca5fb3dbdb2d5dc", rationale: "Generates the reviewed server Task 13 installation descriptor." }, { sha256: "b34a2b4ffaa72e01efb64a7a28b13513527538d837b2f35b6ca5fb3dbdb2d5dc", rationale: "Generates the reviewed server Task 13 installation descriptor." },
+50 -1
View File
@@ -502,7 +502,7 @@ services:
- workspace-registry:/data/workspace-registry - workspace-registry:/data/workspace-registry
- workspace-secrets:/data/workspace-secrets - workspace-secrets:/data/workspace-secrets
- sessions:/data/sessions - sessions:/data/sessions
- $TASK13_AUTH_ROOT:/run/thothii-auth:ro - auth-runtime:/run/thothii-auth:ro
- auth-state:/data/auth - auth-state:/data/auth
- $TASK13_SESSION_RUNTIME_PASSWORD:/run/secrets/task13-runtime-password:ro - $TASK13_SESSION_RUNTIME_PASSWORD:/run/secrets/task13-runtime-password:ro
- $TASK13_REMOTE:/fixtures/remote.git:ro - $TASK13_REMOTE:/fixtures/remote.git:ro
@@ -547,6 +547,9 @@ volumes:
auth-state: auth-state:
labels: labels:
io.thothii.task13.run: "$TASK13_RUN_ID" io.thothii.task13.run: "$TASK13_RUN_ID"
auth-runtime:
labels:
io.thothii.task13.run: "$TASK13_RUN_ID"
qdrant-data: qdrant-data:
labels: labels:
io.thothii.task13.run: "$TASK13_RUN_ID" io.thothii.task13.run: "$TASK13_RUN_ID"
@@ -913,10 +916,39 @@ task13_configure_server_oidc_authentication() {
--authentik-base-url "https://task13-fake-oidc:9443" --user-group task13-users --admin-group task13-admins --authentik-base-url "https://task13-fake-oidc:9443" --user-group task13-users --admin-group task13-admins
} }
task13_prepare_local_auth_runtime() {
local owner_label
owner_label="$(docker volume inspect --format '{{ index .Labels "io.thothii.task13.run" }}' \
"$TASK13_AUTH_RUNTIME_VOLUME")"
[[ "$owner_label" == "$TASK13_RUN_ID" ]] \
|| task13_fail "local authentication runtime volume lacks the Task 13 run label"
task13_run_logged "project local authentication for the core runtime" docker run --rm \
--name "$TASK13_AUTH_PROJECTION_CONTAINER" \
--label "io.thothii.task13.run=$TASK13_RUN_ID" \
--user 0:0 \
--entrypoint sh \
--volume "$TASK13_AUTH_ROOT:/source:ro" \
--volume "$TASK13_AUTH_RUNTIME_VOLUME:/target" \
"$TASK13_CORE_IMAGE" -ceu '
test -f /source/auth.yaml && test ! -L /source/auth.yaml
test -f /source/users.yaml && test ! -L /source/users.yaml
test -z "$(find /target -mindepth 1 -maxdepth 1 -print -quit)"
cp /source/auth.yaml /source/users.yaml /target/
chown 10001:10001 /target /target/auth.yaml /target/users.yaml
chmod 0700 /target
chmod 0600 /target/auth.yaml /target/users.yaml
test "$(stat -c "%u:%g:%a" /target)" = 10001:10001:700
test "$(stat -c "%u:%g:%a" /target/auth.yaml)" = 10001:10001:600
test "$(stat -c "%u:%g:%a" /target/users.yaml)" = 10001:10001:600
'
}
task13_start_stack() { task13_start_stack() {
printf '== Build and start isolated local Compose distribution ==\n' printf '== Build and start isolated local Compose distribution ==\n'
task13_assert_rendered_contract task13_assert_rendered_contract
task13_compose_logged "build local Compose images" build --pull task13_compose_logged "build local Compose images" build --pull
task13_compose_logged "create local core authentication runtime" create --no-deps core
task13_prepare_local_auth_runtime
task13_compose_start_logged "start local Compose distribution" up --detach --wait --wait-timeout 120 task13_compose_start_logged "start local Compose distribution" up --detach --wait --wait-timeout 120
TASK13_NETWORK="$(docker network ls \ TASK13_NETWORK="$(docker network ls \
--filter "label=com.docker.compose.project=$TASK13_PROJECT" \ --filter "label=com.docker.compose.project=$TASK13_PROJECT" \
@@ -1762,6 +1794,7 @@ task13_cleanup() {
tail -n 200 "$TASK13_LOG" | task13_sanitize >&2 tail -n 200 "$TASK13_LOG" | task13_sanitize >&2
fi fi
task13_remove_labeled_container "${TASK13_BAD_CANDIDATE_CONTAINER:-}" || cleanup_rc=1 task13_remove_labeled_container "${TASK13_BAD_CANDIDATE_CONTAINER:-}" || cleanup_rc=1
task13_remove_labeled_container "${TASK13_AUTH_PROJECTION_CONTAINER:-}" || cleanup_rc=1
task13_remove_labeled_container "${TASK13_LLM_CONTAINER:-}" || cleanup_rc=1 task13_remove_labeled_container "${TASK13_LLM_CONTAINER:-}" || cleanup_rc=1
task13_remove_labeled_container "${TASK13_OIDC_CONTAINER:-}" || cleanup_rc=1 task13_remove_labeled_container "${TASK13_OIDC_CONTAINER:-}" || cleanup_rc=1
if [[ -n "${TASK13_PROJECT:-}" && -n "${TASK13_ROOT:-}" && -f "${TASK13_OVERRIDE:-}" ]]; then if [[ -n "${TASK13_PROJECT:-}" && -n "${TASK13_ROOT:-}" && -f "${TASK13_OVERRIDE:-}" ]]; then
@@ -2323,11 +2356,16 @@ task13_self_test_registry_fingerprint() {
task13_self_test_source_contract() { task13_self_test_source_contract() {
local root host_network push_command registry_function workflow uses_count pinned_uses_count local root host_network push_command registry_function workflow uses_count pinned_uses_count
local auth_runtime_mount auth_root_mount auth_projection auth_runtime_owner
root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)" root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
workflow="$root/.github/workflows/deployment.yml" workflow="$root/.github/workflows/deployment.yml"
host_network='--network'' host' host_network='--network'' host'
push_command='docker image ''push' push_command='docker image ''push'
registry_function='task13_start_''registry' registry_function='task13_start_''registry'
auth_runtime_mount='auth-runtime:/run/thothii-''auth:ro'
auth_root_mount='$TASK13_AUTH_''ROOT:/run/thothii-auth:ro'
auth_projection='task13_prepare_local_auth_''runtime'
auth_runtime_owner='chown 10001:''10001 /target'
if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \ if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \
"$root/scripts/unified-deployment-smoke.sh" \ "$root/scripts/unified-deployment-smoke.sh" \
"$root/scripts/tht-update-smoke.sh" \ "$root/scripts/tht-update-smoke.sh" \
@@ -2340,6 +2378,15 @@ task13_self_test_source_contract() {
|| grep -Fq -- "$registry_function" "$root/scripts/unified-deployment-smoke.sh"; then || grep -Fq -- "$registry_function" "$root/scripts/unified-deployment-smoke.sh"; then
task13_fail "the rollback fixture must not depend on a daemon-to-host local image registry" task13_fail "the rollback fixture must not depend on a daemon-to-host local image registry"
fi fi
grep -Fq -- "$auth_runtime_mount" "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "the local smoke must mount a Compose-owned authentication runtime volume"
! grep -Fq -- "$auth_root_mount" "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "the local smoke must not bind host-owned authentication into the core"
[[ "$(grep -Ec "^${auth_projection}\\(\\)|^[[:space:]]+${auth_projection}$" \
"$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \
|| task13_fail "the local authentication runtime projection must be defined and invoked once"
grep -Fq -- "$auth_runtime_owner" "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "the local authentication runtime projection must enforce the core UID"
grep -Eq '^TASK13_BAD_CANDIDATE_IMAGE="[^"[:space:]]+@sha256:[0-9a-f]{64}"$' \ grep -Eq '^TASK13_BAD_CANDIDATE_IMAGE="[^"[:space:]]+@sha256:[0-9a-f]{64}"$' \
"$root/scripts/unified-deployment-smoke.sh" \ "$root/scripts/unified-deployment-smoke.sh" \
|| task13_fail "the bad rollback candidate must be an immutable digest reference" || task13_fail "the bad rollback candidate must be an immutable digest reference"
@@ -2491,6 +2538,8 @@ task13_initialize() {
TASK13_SECRETS="$TASK13_TMP/thothii.secrets" TASK13_SECRETS="$TASK13_TMP/thothii.secrets"
TASK13_AUTH_ROOT="$TASK13_TMP/auth" TASK13_AUTH_ROOT="$TASK13_TMP/auth"
TASK13_AUTH_PASSWORD_FILE="$TASK13_TMP/local-auth-password" TASK13_AUTH_PASSWORD_FILE="$TASK13_TMP/local-auth-password"
TASK13_AUTH_RUNTIME_VOLUME="${TASK13_PROJECT}_auth-runtime"
TASK13_AUTH_PROJECTION_CONTAINER="$TASK13_PROJECT-auth-projection"
TASK13_AUTH_ADMIN=task13-admin TASK13_AUTH_ADMIN=task13-admin
TASK13_AUTH_PASSWORD="task13-auth-$TASK13_RUN_ID" TASK13_AUTH_PASSWORD="task13-auth-$TASK13_RUN_ID"
TASK13_OIDC_CLIENT_SECRET="task13-oidc-client-$TASK13_RUN_ID" TASK13_OIDC_CLIENT_SECRET="task13-oidc-client-$TASK13_RUN_ID"