Files
ThothII/.superpowers/sdd/task-3-report.md
T

60 lines
2.8 KiB
Markdown

# Task 3 report — one secret bundle for local services
## Status
Complete. Local pgvector bootstrap, reconciliation, migration, and preprocess services now
mount only `/run/secrets/thothii.secrets`. `deploy/vector/secret-policy.sh` validates the
whole bundle (allowlist, duplicate/empty/unknown keys, comments/blank lines, mode and symlink
policy) and returns only the requested value. The core entrypoint exposes DWH/vector/CA values
to the harness and materializes short-lived 0600 password files for workspace resolution.
## TDD evidence
- RED: `./scripts/test-preprocess-compose-config.sh` failed on the pre-existing
`vector_reader_password` Compose secret declaration.
- GREEN: the same command passes after the bundle conversion and verifies local-vector
workspace interpolation and shared secret mounts.
- `./scripts/test-vector-secret-policy.sh` covers comments/blank lines and rejects an
unrelated duplicate key.
## Verification
- `./scripts/test-vector-secret-policy.sh` — passed.
- `./scripts/test-preprocess-compose-config.sh` — passed.
- `./scripts/test-vector-backup-restore-safety.sh` — passed.
- `./scripts/test-default-compose.sh` — passed.
- `./scripts/test-container-deployment.sh` — passed.
- `./scripts/local-vector-smoke.sh` — passed with real Docker (bootstrap rotation, role
reconciliation, migration, persistence and restart).
- `./scripts/preprocess-smoke.sh` — passed with real Docker (unchanged rerun, mutation, DWH
job, ACTIVE publication and cleanup).
- `./scripts/preprocess-smoke.sh --cleanup-failure` — passed.
- `git diff --check` and `sh -n` gates — passed.
## Critical review fix
`buildPiChildEnv` now removes `THT_DWH_API_KEY`, `THT_VEC_API_KEY`, `THT_VEC_WRITE_API_KEY`,
`THT_SSL_CA`, `THT_CA`, and their file metadata before spawning Pi. A regression test proves
that neither secret values nor bundle/file metadata are inherited by the Pi child.
## Commits
- `70a19f2 feat(compose): use one secret bundle for local services`
- `d500563 fix(security): scrub deployment secrets from Pi child`
- `8518a73 fix(security): scrub raw deployment secret values`
## Concern
The rotation helper retains its old/new scratch-file CLI contract; smoke tests keep those files
outside Compose and mount only the bundle.
## Whole-branch review fixes
- `core-entrypoint.sh` validates `THT_SECRETS_FILE` fail-closed before optional lookups; malformed,
duplicate, unknown, oversized, or overlong bundles stop startup with sanitized diagnostics.
- Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather
than being orphaned by `exec`.
- The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.
- Optional key lookup distinguishes an absent key from an invalid value; present malformed
credentials now stop entrypoint startup instead of being silently ignored.