60 lines
2.8 KiB
Markdown
60 lines
2.8 KiB
Markdown
# Task 3 report — one secret bundle for local services
|
|
|
|
## Status
|
|
|
|
Complete. Local pgvector bootstrap, reconciliation, migration, and preprocess services now
|
|
mount only `/run/secrets/thothii.secrets`. `deploy/vector/secret-policy.sh` validates the
|
|
whole bundle (allowlist, duplicate/empty/unknown keys, comments/blank lines, mode and symlink
|
|
policy) and returns only the requested value. The core entrypoint exposes DWH/vector/CA values
|
|
to the harness and materializes short-lived 0600 password files for workspace resolution.
|
|
|
|
## TDD evidence
|
|
|
|
- RED: `./scripts/test-preprocess-compose-config.sh` failed on the pre-existing
|
|
`vector_reader_password` Compose secret declaration.
|
|
- GREEN: the same command passes after the bundle conversion and verifies local-vector
|
|
workspace interpolation and shared secret mounts.
|
|
- `./scripts/test-vector-secret-policy.sh` covers comments/blank lines and rejects an
|
|
unrelated duplicate key.
|
|
|
|
## Verification
|
|
|
|
- `./scripts/test-vector-secret-policy.sh` — passed.
|
|
- `./scripts/test-preprocess-compose-config.sh` — passed.
|
|
- `./scripts/test-vector-backup-restore-safety.sh` — passed.
|
|
- `./scripts/test-default-compose.sh` — passed.
|
|
- `./scripts/test-container-deployment.sh` — passed.
|
|
- `./scripts/local-vector-smoke.sh` — passed with real Docker (bootstrap rotation, role
|
|
reconciliation, migration, persistence and restart).
|
|
- `./scripts/preprocess-smoke.sh` — passed with real Docker (unchanged rerun, mutation, DWH
|
|
job, ACTIVE publication and cleanup).
|
|
- `./scripts/preprocess-smoke.sh --cleanup-failure` — passed.
|
|
- `git diff --check` and `sh -n` gates — passed.
|
|
|
|
## Critical review fix
|
|
|
|
`buildPiChildEnv` now removes `THT_DWH_API_KEY`, `THT_VEC_API_KEY`, `THT_VEC_WRITE_API_KEY`,
|
|
`THT_SSL_CA`, `THT_CA`, and their file metadata before spawning Pi. A regression test proves
|
|
that neither secret values nor bundle/file metadata are inherited by the Pi child.
|
|
|
|
## Commits
|
|
|
|
- `70a19f2 feat(compose): use one secret bundle for local services`
|
|
- `d500563 fix(security): scrub deployment secrets from Pi child`
|
|
- `8518a73 fix(security): scrub raw deployment secret values`
|
|
|
|
## Concern
|
|
|
|
The rotation helper retains its old/new scratch-file CLI contract; smoke tests keep those files
|
|
outside Compose and mount only the bundle.
|
|
|
|
## Whole-branch review fixes
|
|
|
|
- `core-entrypoint.sh` validates `THT_SECRETS_FILE` fail-closed before optional lookups; malformed,
|
|
duplicate, unknown, oversized, or overlong bundles stop startup with sanitized diagnostics.
|
|
- Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather
|
|
than being orphaned by `exec`.
|
|
- The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.
|
|
- Optional key lookup distinguishes an absent key from an invalid value; present malformed
|
|
credentials now stop entrypoint startup instead of being silently ignored.
|