From ac8556c5904ac4c5842e30f6ffcdca964aed4247 Mon Sep 17 00:00:00 2001 From: jochens Date: Wed, 30 Sep 2026 12:16:04 +0200 Subject: [PATCH] baserow: placed directories, the database password from a file, and the build ace runs The module named /var/lib/baserow and /services/baserow/data, a layout no definition may carry (ADR 0112). State and data are now placed directories; bindings and the grant's secret live in the placed state. The all-in-one image's entrypoint honours DATABASE_PASSWORD_FILE (file_env in /baserow.sh), so the grant's password is mounted rather than put in an env-file, and "secrets-in-environment" is gone (ADR 0086). SECRET_KEY is no longer minted: the image keeps it, and its JWT signing key, in the data directory (.secret, .jwt_signing_key) and imports them on start, so a moved data directory carries the keys its sessions and tokens were made with. DISABLE_EMBEDDED_PSQL makes a missing grant fail loudly instead of starting an empty embedded database. BASEROW_PUBLIC_URL was http://localhost. Baserow answers only the host of that URL - any other Host is looked up as a published builder site and gets 404, /api/_health/ included - so it is now https://${bound:route:name} (depends on mesh-controller #149). The runtime's tools could never have worked: its config was "{}", and the client's Host override was silently dropped by Node's fetch, so calls by container name would 404 even with credentials. The client now uses node:http (which sends the Host it is given, with a Content-Length - Baserow reads a chunked body as empty) and re-authenticates once when a cached JWT is refused (access tokens last minutes, the runtime weeks). The password is the accepted `admin` secret; the email is an assignment setting merged into the same file, the host is the route's name. Image pinned to the develop-latest build ace runs today (Baserow 2.3.4, built 2026-09-18). The old pin (built 2026-09-04) is older than ace's data. Verified: catalogue tests with MESH_CATALOGUE set; tsc -p tsconfig.json in the mesh-tools build image. In throwaway containers of the pinned image: a fresh embedded-PG instance with a user, workspace and 5-row table; stopped, copied, dumped from the copy (start-only-db); restored with --no-owner --role into a grant-shaped database on the pgvector image the postgres module pins (PG17); started with this shape (root 0600 password file, embedded PSQL disabled, copied data dir without postgres/): health 200, the user logs in, the 5 rows are there, SECRET_KEY and the JWT key are imported from the data dir. The patched client lists applications and rows through the container name with the public Host, and recovers from a refused token. Test containers and data removed. --- modules/baserow/client.ts | 79 ++++++++++++++++++++++++++----------- modules/baserow/module.json | 31 +++++++-------- 2 files changed, 70 insertions(+), 40 deletions(-) diff --git a/modules/baserow/client.ts b/modules/baserow/client.ts index 59921aa..5fd0ee1 100644 --- a/modules/baserow/client.ts +++ b/modules/baserow/client.ts @@ -2,12 +2,15 @@ // module's tools and anything else baserow-specific import it; nothing outside baserow does. // // Baserow authenticates a person with email + password, exchanged for a JWT at /api/user/token-auth/. -// Those credentials are the mesh's own: a person signs up in Baserow (the standard image creates no -// admin from env), and the credential is placed in the runtime config file the mesh mounts. Until -// that happens fromEnv throws and the module simply exposes no tools — the same dormant-until- -// configured shape gitea uses for its token. +// The standard image creates no admin from env, so the account is one a person made in Baserow: its +// password is the module's `admin` secret, accepted from the operator, and its email and the public +// host Baserow answers to reach the runtime config file the mesh mounts (the email from the +// assignment's settings). Until both are there fromEnv throws and the module exposes no tools — the +// same dormant-until-configured shape gitea uses for its token. import { readFileSync } from "node:fs"; +import { request as httpRequest } from "node:http"; +import { request as httpsRequest } from "node:https"; export interface BaserowApplication { id: number; @@ -68,35 +71,63 @@ export class BaserowClient { return h; } - /** Exchange email + password for a JWT, caching it for the client's lifetime. Handles both the + /** + * One HTTP exchange. Not `fetch`: Node's fetch drops a caller's Host header and sends the URL's + * own, and Baserow answers only the host of its BASEROW_PUBLIC_URL — any other Host is looked up + * as a published builder site and gets 404, `/api/_health/` included. A co-located caller reaching + * it by container name must present the public host, so the request is made with node:http, which + * sends the Host it is given. + */ + private send(path: string, method: string, headers: Record, body?: string): Promise<{ status: number; text: string }> { + const url = new URL(`${this.baseUrl}${path}`); + const request = url.protocol === "https:" ? httpsRequest : httpRequest; + // A length, never chunked: Baserow's server reads a chunked body as empty. + const sent = body === undefined ? headers : { ...headers, "Content-Length": String(Buffer.byteLength(body)) }; + return new Promise((resolve, reject) => { + const req = request(url, { method, headers: sent }, (res) => { + let text = ""; + res.setEncoding("utf8"); + res.on("data", (chunk: string) => (text += chunk)); + res.on("end", () => resolve({ status: res.statusCode ?? 0, text })); + res.on("error", reject); + }); + req.on("error", reject); + if (body !== undefined) req.write(body); + req.end(); + }); + } + + /** Exchange email + password for a JWT, caching it until Baserow refuses it. Handles both the * older `{ token }` and the newer `{ access_token }` response shapes. */ async authenticate(): Promise { if (this.token) return this.token; - const res = await fetch(`${this.baseUrl}/api/user/token-auth/`, { - method: "POST", - headers: this.headers(), - body: JSON.stringify({ email: this.email, password: this.password }), - }); - if (!res.ok) throw new Error(`baserow auth failed: ${res.status} ${await res.text()}`); - const data = (await res.json()) as { token?: string; access_token?: string }; + const res = await this.send( + "/api/user/token-auth/", + "POST", + this.headers(), + JSON.stringify({ email: this.email, password: this.password }), + ); + if (res.status < 200 || res.status >= 300) throw new Error(`baserow auth failed: ${res.status} ${res.text}`); + const data = JSON.parse(res.text) as { token?: string; access_token?: string }; const token = data.access_token ?? data.token; if (!token) throw new Error("baserow auth returned no token"); this.token = token; return token; } - private async authed(path: string, options: RequestInit = {}): Promise { - const token = await this.authenticate(); - const res = await fetch(`${this.baseUrl}${path}`, { - ...options, - headers: this.headers({ - Authorization: `JWT ${token}`, - ...(options.headers as Record | undefined), - }), - }); - if (!res.ok) throw new Error(`baserow ${path}: ${res.status} ${await res.text()}`); - const text = await res.text(); - return (text ? JSON.parse(text) : null) as T; + /** An authenticated GET. A refused token is dropped and the call made once more with a fresh one: + * Baserow's access tokens expire after minutes, and the runtime lives for weeks. */ + private async authed(path: string): Promise { + for (let attempt = 0; ; attempt++) { + const token = await this.authenticate(); + const res = await this.send(path, "GET", this.headers({ Authorization: `JWT ${token}` })); + if (res.status === 401 && attempt === 0) { + this.token = null; + continue; + } + if (res.status < 200 || res.status >= 300) throw new Error(`baserow ${path}: ${res.status} ${res.text}`); + return (res.text ? JSON.parse(res.text) : null) as T; + } } /** The applications (databases) the account can see, across all its workspaces. */ diff --git a/modules/baserow/module.json b/modules/baserow/module.json index d9c2777..9dfd6f3 100644 --- a/modules/baserow/module.json +++ b/modules/baserow/module.json @@ -18,14 +18,14 @@ } }, "binds": { - "postgres-database": "/var/lib/baserow/database.json", - "route": "/var/lib/baserow/route.json" + "postgres-database": "${dir:state}/database.json", + "route": "${dir:state}/route.json" }, "secrets": { - "postgres-database": "/var/lib/baserow/database.secret" + "postgres-database": "${dir:state}/database.secret" }, "own-secrets": { - "secret-key": "/var/lib/baserow/secret-key.secret", + "admin": "${dir:state}/admin.secret", "broker": "/var/lib/mesh/baserow/broker" }, "listens": [ @@ -34,7 +34,7 @@ "port": 80, "protocol": "tcp", "from": "mesh", - "why": "the Baserow web UI and REST API; a public name is a route grant later" + "why": "the Baserow web UI and REST API, served by the image's own Caddy; a public name is the route's" } ], "resources": [ @@ -47,22 +47,21 @@ { "id": "state", "type": "directory", - "path": "/var/lib/baserow", - "mode": "0700" + "mode": "0700", + "place": "." }, { "id": "data", "type": "directory", - "path": "/services/baserow/data", "mode": "0755", "owner": "9999:9999" }, { "id": "server-env", "type": "file", - "path": "/var/lib/baserow/server.env", + "path": "${dir:state}/server.env", "mode": "0600", - "content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD=${secret:postgres-database}\nSECRET_KEY=${secret:secret-key}\nBASEROW_PUBLIC_URL=http://localhost\n" + "content": "DATABASE_HOST=${bound:postgres-database:at}\nDATABASE_PORT=${bound:postgres-database:port}\nDATABASE_NAME=${bound:postgres-database:as}\nDATABASE_USER=${bound:postgres-database:as}\nDATABASE_PASSWORD_FILE=/run/secrets/database\nDISABLE_EMBEDDED_PSQL=true\nBASEROW_PUBLIC_URL=https://${bound:route:name}\n" }, { "id": "net", @@ -73,25 +72,25 @@ "id": "server", "type": "container", "name": "baserow", - "image": "baserow/baserow@sha256:834424a10413798567f76428f255dc259445b7f8dcec56598c05b4073bb2a124", + "image": "baserow/baserow@sha256:263ea6c4b72c9eccabcd975ffe9fdebf23913a293a514bec6a3897a5e0a5a080", "network": "baserow", "env-file": [ - "/var/lib/baserow/server.env" + "${dir:state}/server.env" ], "ports": [ "80" ], "volumes": [ - "/services/baserow/data:/baserow/data" - ], - "secrets-in-environment": "baserow reads DATABASE_PASSWORD and SECRET_KEY with os.getenv and has no _FILE twin (settings/base.py); not convertible" + "${dir:data}:/baserow/data", + "${dir:state}/database.secret:/run/secrets/database:ro" + ] }, { "id": "runtime-config", "type": "file", "path": "/var/lib/mesh/baserow/config.json", "mode": "0600", - "content": "{}\n", + "content": "{\n \"password\": \"${secret:admin}\",\n \"host\": \"${bound:route:name}\"\n}\n", "merge": "json" }, {