#!/usr/bin/env bash set -euo pipefail repo_root=$(cd "$(dirname "$0")/.." && pwd -P) cd "$repo_root" die() { echo "dwh-auth build/deployment contract: $*" >&2 exit 1 } builder_digest='golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651' dockerfile=docker/dwh-auth.Dockerfile build_script=scripts/build-dwh-auth.sh service=deploy/dwh-auth/dwh-auth.service tmpfiles=deploy/dwh-auth/dwh-auth.tmpfiles.conf http=deploy/dwh-auth/nginx-http.conf.example location=deploy/dwh-auth/nginx-dwh-location.conf.example [[ -f "$dockerfile" ]] || die "missing $dockerfile" [[ -f "$build_script" ]] || die "missing $build_script" [[ -f "$service" ]] || die "missing $service" [[ -f "$tmpfiles" ]] || die "missing $tmpfiles" [[ -f "$http" ]] || die "missing $http" [[ -f "$location" ]] || die "missing $location" grep -Fq "FROM $builder_digest AS build" "$dockerfile" || die "builder image is not pinned" grep -Fq 'CGO_ENABLED=0' "$dockerfile" || die "CGO is not disabled" grep -Fq -- '-trimpath' "$dockerfile" || die "trimpath is missing" grep -Fq -- '-s -w' "$dockerfile" || die "strip flags are missing" if grep -Eq '^[[:space:]]*require([[:space:]]|\()' tools/dwh-auth/go.mod; then die "dwh-auth module declares dependencies" fi for directive in \ 'User=dwh-auth' \ 'Group=www-data' \ 'SupplementaryGroups=dwh-auth' \ 'NoNewPrivileges=true' \ 'ProtectSystem=strict' \ 'ProtectHome=true' \ 'RestrictAddressFamilies=AF_UNIX' \ 'CapabilityBoundingSet=' \ 'UMask=0007'; do grep -Fq "$directive" "$service" || die "missing systemd directive: $directive" done grep -Fq 'RuntimeDirectory=dwh-auth' "$service" || die "runtime directory is missing" grep -Fq 'RuntimeDirectoryMode=0750' "$service" || die "runtime mode is missing" grep -Fq 'ReadOnlyPaths=/var/lib/dwh-auth' "$service" || die "registry is not read-only" grep -Fq 'ExecStart=/usr/local/sbin/dwh-auth serve --registry-root /var/lib/dwh-auth --socket /run/dwh-auth/verify.sock' "$service" \ || die "unexpected service command" grep -Eq '^d[[:space:]]+/var/lib/dwh-auth[[:space:]]+2750[[:space:]]+root[[:space:]]+dwh-auth([[:space:]]|$)' "$tmpfiles" \ || die "tmpfiles root directory contract is missing" for child in active revoked; do grep -Eq "^d[[:space:]]+/var/lib/dwh-auth/$child[[:space:]]+2750[[:space:]]+root[[:space:]]+dwh-auth([[:space:]]|$)" "$tmpfiles" \ || die "tmpfiles $child directory contract is missing" done grep -Eq '^f[[:space:]]+/var/lib/dwh-auth/\.writer\.lock[[:space:]]+0640[[:space:]]+root[[:space:]]+dwh-auth([[:space:]]|$)' "$tmpfiles" \ || die "tmpfiles writer lock contract is missing" grep -Fq 'auth_request /_check_dwh_key;' "$location" || die "DWH auth subrequest is missing" grep -Fq 'proxy_method GET;' "$location" || die "auth method is not GET" grep -Fq 'proxy_pass_request_body off;' "$location" || die "auth body is not disabled" grep -Fq 'proxy_pass_request_headers off;' "$location" || die "auth request headers are not restricted" grep -Fq 'proxy_set_header Content-Length "";' "$location" || die "auth body length is not cleared" grep -Fq 'proxy_set_header X-API-Key $http_x_api_key;' "$location" || die "key is not forwarded to auth" grep -Fq 'proxy_set_header X-API-Key "";' "$location" || die "key is not cleared upstream" grep -Fq 'proxy_set_header X-DWH-Key-ID "";' "$location" || die "public key ID is not cleared" [[ $(grep -Fc 'proxy_set_header X-DWH-Key-ID "";' "$location") -eq 1 ]] || die "public key ID must be cleared exactly once" grep -Fq 'proxy_pass http://unix:/run/dwh-auth/verify.sock:/verify;' "$location" || die "Unix auth socket is missing" grep -Fq 'location /dwh/ {' "$location" || die "DWH prefix location is missing" grep -Fq 'proxy_pass http://127.0.0.1:3001;' "$location" || die "DWH prefix is not preserved" grep -Fq 'limit_req zone=dwh_auth burst=100 nodelay;' "$location" || die "DWH rate limit is missing" grep -Fq 'error_page 500 =503 @dwh_auth_unavailable;' "$location" || die "auth infrastructure failure is not 503" grep -Fq 'map $http_x_api_key $dwh_public_key_class' "$http" || die "public rate-key map is missing" if rg -n 'limit_req_zone.*\$http_x_api_key|limit_req_zone.*\$dwh_key_secret|limit_req_zone.*\$request' "$http" "$location"; then die "rate key includes a secret or full request" fi if command -v docker >/dev/null 2>&1; then out=$(mktemp -d) trap 'rm -rf "$out"' EXIT scripts/build-dwh-auth.sh --output "$out" for arch in amd64 arm64; do artifact="$out/dwh-auth-linux-$arch" [[ -s "$artifact" ]] || die "missing non-empty $artifact" file "$artifact" | grep -Eq 'ELF .*executable' || die "$artifact is not an ELF executable" readelf -h "$artifact" | grep -Eq 'OS/ABI:[[:space:]]+UNIX - (System V|GNU)' || die "$artifact is not a Linux ELF" if [[ "$arch" == amd64 ]]; then readelf -h "$artifact" | grep -Eq 'Machine:.*(X86-64|AMD64)' || die "$artifact has the wrong architecture" else readelf -h "$artifact" | grep -Eq 'Machine:.*AArch64' || die "$artifact has the wrong architecture" fi done fi echo 'dwh-auth build and deployment contract passed'