2.8 KiB
Task 3 report — one secret bundle for local services
Status
Complete. Local pgvector bootstrap, reconciliation, migration, and preprocess services now
mount only /run/secrets/thothii.secrets. deploy/vector/secret-policy.sh validates the
whole bundle (allowlist, duplicate/empty/unknown keys, comments/blank lines, mode and symlink
policy) and returns only the requested value. The core entrypoint exposes DWH/vector/CA values
to the harness and materializes short-lived 0600 password files for workspace resolution.
TDD evidence
- RED:
./scripts/test-preprocess-compose-config.shfailed on the pre-existingvector_reader_passwordCompose secret declaration. - GREEN: the same command passes after the bundle conversion and verifies local-vector workspace interpolation and shared secret mounts.
./scripts/test-vector-secret-policy.shcovers comments/blank lines and rejects an unrelated duplicate key.
Verification
./scripts/test-vector-secret-policy.sh— passed../scripts/test-preprocess-compose-config.sh— passed../scripts/test-vector-backup-restore-safety.sh— passed../scripts/test-default-compose.sh— passed../scripts/test-container-deployment.sh— passed../scripts/local-vector-smoke.sh— passed with real Docker (bootstrap rotation, role reconciliation, migration, persistence and restart)../scripts/preprocess-smoke.sh— passed with real Docker (unchanged rerun, mutation, DWH job, ACTIVE publication and cleanup)../scripts/preprocess-smoke.sh --cleanup-failure— passed.git diff --checkandsh -ngates — passed.
Critical review fix
buildPiChildEnv now removes THT_DWH_API_KEY, THT_VEC_API_KEY, THT_VEC_WRITE_API_KEY,
THT_SSL_CA, THT_CA, and their file metadata before spawning Pi. A regression test proves
that neither secret values nor bundle/file metadata are inherited by the Pi child.
Commits
70a19f2 feat(compose): use one secret bundle for local servicesd500563 fix(security): scrub deployment secrets from Pi child8518a73 fix(security): scrub raw deployment secret values
Concern
The rotation helper retains its old/new scratch-file CLI contract; smoke tests keep those files outside Compose and mount only the bundle.
Whole-branch review fixes
core-entrypoint.shvalidatesTHT_SECRETS_FILEfail-closed before optional lookups; malformed, duplicate, unknown, oversized, or overlong bundles stop startup with sanitized diagnostics.- Runtime password files are cleaned after child exit via signal forwarding and
wait, rather than being orphaned byexec. - The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.
- Optional key lookup distinguishes an absent key from an invalid value; present malformed credentials now stop entrypoint startup instead of being silently ignored.