Multiple fixes: five modules keep their secrets from the vault (ADR 0094), the authority makes its own root (076), the builder on the host network, route-proxy declares its bases #34
@@ -64,7 +64,8 @@
|
|||||||
"builder-env",
|
"builder-env",
|
||||||
"package-binding",
|
"package-binding",
|
||||||
"needs-npm-password"
|
"needs-npm-password"
|
||||||
]
|
],
|
||||||
|
"network": "host"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,7 +3,8 @@
|
|||||||
"version": "1",
|
"version": "1",
|
||||||
"requires": [
|
"requires": [
|
||||||
"postgres-database",
|
"postgres-database",
|
||||||
"route"
|
"route",
|
||||||
|
"secret"
|
||||||
],
|
],
|
||||||
"contributes": {
|
"contributes": {
|
||||||
"postgres-database": {
|
"postgres-database": {
|
||||||
@@ -19,7 +20,11 @@
|
|||||||
"route": "/var/lib/gitea/route.json"
|
"route": "/var/lib/gitea/route.json"
|
||||||
},
|
},
|
||||||
"secrets": {
|
"secrets": {
|
||||||
"postgres-database": "/var/lib/gitea/database.secret"
|
"postgres-database": "/var/lib/gitea/database.secret",
|
||||||
|
"secret": {
|
||||||
|
"internal-token": "/var/lib/gitea/internal-token.secret",
|
||||||
|
"admin": "/var/lib/gitea/admin.secret"
|
||||||
|
}
|
||||||
},
|
},
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"container-runtime"
|
"container-runtime"
|
||||||
@@ -57,8 +62,6 @@
|
|||||||
"package-registry": "/var/lib/gitea/grants"
|
"package-registry": "/var/lib/gitea/grants"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"internal-token": "/var/lib/gitea/internal-token.secret",
|
|
||||||
"admin": "/var/lib/gitea/admin.secret",
|
|
||||||
"broker": "/var/lib/mesh/gitea/broker"
|
"broker": "/var/lib/mesh/gitea/broker"
|
||||||
},
|
},
|
||||||
"resources": [
|
"resources": [
|
||||||
|
|||||||
@@ -9,9 +9,6 @@
|
|||||||
"module.icecast.stream.stopped"
|
"module.icecast.stream.stopped"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"source": "/var/lib/icecast-module/source.secret",
|
|
||||||
"admin": "/var/lib/icecast-module/admin.secret",
|
|
||||||
"relay": "/var/lib/icecast-module/relay.secret",
|
|
||||||
"broker": "/var/lib/mesh/icecast/broker"
|
"broker": "/var/lib/mesh/icecast/broker"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
@@ -103,5 +100,15 @@
|
|||||||
"from": "Dockerfile"
|
"from": "Dockerfile"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
},
|
||||||
|
"requires": [
|
||||||
|
"secret"
|
||||||
|
],
|
||||||
|
"secrets": {
|
||||||
|
"secret": {
|
||||||
|
"source": "/var/lib/icecast-module/source.secret",
|
||||||
|
"admin": "/var/lib/icecast-module/admin.secret",
|
||||||
|
"relay": "/var/lib/icecast-module/relay.secret"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,8 +5,6 @@
|
|||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"admin": "/var/lib/influxdb-module/admin.secret",
|
|
||||||
"admin-token": "/var/lib/influxdb-module/admin-token.secret",
|
|
||||||
"broker": "/var/lib/mesh/influxdb/broker"
|
"broker": "/var/lib/mesh/influxdb/broker"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
@@ -118,5 +116,14 @@
|
|||||||
"from": "Dockerfile"
|
"from": "Dockerfile"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
},
|
||||||
|
"requires": [
|
||||||
|
"secret"
|
||||||
|
],
|
||||||
|
"secrets": {
|
||||||
|
"secret": {
|
||||||
|
"admin": "/var/lib/influxdb-module/admin.secret",
|
||||||
|
"admin-token": "/var/lib/influxdb-module/admin-token.secret"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -6,7 +6,8 @@
|
|||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
"postgres-database",
|
"postgres-database",
|
||||||
"route"
|
"route",
|
||||||
|
"secret"
|
||||||
],
|
],
|
||||||
"contributes": {
|
"contributes": {
|
||||||
"postgres-database": {
|
"postgres-database": {
|
||||||
@@ -22,7 +23,12 @@
|
|||||||
"route": "/var/lib/mailu/route.json"
|
"route": "/var/lib/mailu/route.json"
|
||||||
},
|
},
|
||||||
"secrets": {
|
"secrets": {
|
||||||
"postgres-database": "/var/lib/mailu/database.secret"
|
"postgres-database": "/var/lib/mailu/database.secret",
|
||||||
|
"secret": {
|
||||||
|
"secret-key": "/var/lib/mailu/secret-key.secret",
|
||||||
|
"admin": "/var/lib/mailu/admin.secret",
|
||||||
|
"api-token": "/var/lib/mailu/api-token.secret"
|
||||||
|
}
|
||||||
},
|
},
|
||||||
"emits": [
|
"emits": [
|
||||||
"module.mailu.user.created",
|
"module.mailu.user.created",
|
||||||
@@ -67,9 +73,6 @@
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"secret-key": "/var/lib/mailu/secret-key.secret",
|
|
||||||
"admin": "/var/lib/mailu/admin.secret",
|
|
||||||
"api-token": "/var/lib/mailu/api-token.secret",
|
|
||||||
"broker": "/var/lib/mesh/mailu/broker"
|
"broker": "/var/lib/mesh/mailu/broker"
|
||||||
},
|
},
|
||||||
"resources": [
|
"resources": [
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
ARG ALPINE_BASE=alpine:3.20
|
||||||
|
ARG GO_BASE=golang:1.25
|
||||||
# The route-proxy module's runtime image: the reference reverse proxy compiled into a container.
|
# The route-proxy module's runtime image: the reference reverse proxy compiled into a container.
|
||||||
#
|
#
|
||||||
# **The proxy source is not vendored here.** The canonical proxy — the contract written as something
|
# **The proxy source is not vendored here.** The canonical proxy — the contract written as something
|
||||||
@@ -10,7 +12,7 @@
|
|||||||
#
|
#
|
||||||
# The mesh pins the digest of what this produces; the committed module.json carries the placeholder
|
# The mesh pins the digest of what this produces; the committed module.json carries the placeholder
|
||||||
# digest every mesh-built image does, replaced at publish.
|
# digest every mesh-built image does, replaced at publish.
|
||||||
FROM golang:1.25 AS build
|
FROM ${GO_BASE} AS build
|
||||||
WORKDIR /src
|
WORKDIR /src
|
||||||
COPY go.mod go.sum ./
|
COPY go.mod go.sum ./
|
||||||
RUN go mod download
|
RUN go mod download
|
||||||
@@ -19,7 +21,7 @@ RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -o /mesh-route-proxy ./examples/
|
|||||||
|
|
||||||
# A small runtime with the public CA roots the ACME client needs to reach a real authority, and run
|
# A small runtime with the public CA roots the ACME client needs to reach a real authority, and run
|
||||||
# as root so it can bind :80 and :443 — the two privileged ports a public front door listens on.
|
# as root so it can bind :80 and :443 — the two privileged ports a public front door listens on.
|
||||||
FROM alpine:3.20
|
FROM ${ALPINE_BASE}
|
||||||
RUN apk add --no-cache ca-certificates
|
RUN apk add --no-cache ca-certificates
|
||||||
COPY --from=build /mesh-route-proxy /usr/local/bin/mesh-route-proxy
|
COPY --from=build /mesh-route-proxy /usr/local/bin/mesh-route-proxy
|
||||||
ENTRYPOINT ["/usr/local/bin/mesh-route-proxy"]
|
ENTRYPOINT ["/usr/local/bin/mesh-route-proxy"]
|
||||||
|
|||||||
@@ -62,19 +62,31 @@
|
|||||||
"path": "/var/lib/route-proxy/ca",
|
"path": "/var/lib/route-proxy/ca",
|
||||||
"mode": "0755"
|
"mode": "0755"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"id": "ca-bundle",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/route-proxy/ca/root.crt",
|
|
||||||
"mode": "0644",
|
|
||||||
"content": "${bound:acme-ca:root}\n"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "acme-env",
|
"id": "acme-env",
|
||||||
"type": "file",
|
"type": "file",
|
||||||
"path": "/var/lib/route-proxy/acme.env",
|
"path": "/var/lib/route-proxy/acme.env",
|
||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\n"
|
"content": "ACME_DIRECTORY=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:path}\nACME_ROOTS=https://${bound:acme-ca:at}:${bound:acme-ca:port}${bound:acme-ca:roots}\n"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "trust",
|
||||||
|
"type": "container",
|
||||||
|
"name": "route-proxy-trust",
|
||||||
|
"artifact": "trust",
|
||||||
|
"run-once": true,
|
||||||
|
"network": "host",
|
||||||
|
"env-file": [
|
||||||
|
"/var/lib/route-proxy/acme.env"
|
||||||
|
],
|
||||||
|
"volumes": [
|
||||||
|
"/var/lib/route-proxy/ca:/ca"
|
||||||
|
],
|
||||||
|
"args": [
|
||||||
|
"sh",
|
||||||
|
"-c",
|
||||||
|
"for i in $(seq 1 60); do wget -q -T 10 --no-check-certificate -O /ca/root.crt \"$ACME_ROOTS\" && grep -q 'BEGIN CERTIFICATE' /ca/root.crt && exit 0; sleep 2; done; echo \"the authority at $ACME_ROOTS did not serve its roots within two minutes\" >&2; exit 1"
|
||||||
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
@@ -98,5 +110,29 @@
|
|||||||
"ACME_CA_BUNDLE": "/ca/root.crt"
|
"ACME_CA_BUNDLE": "/ca/root.crt"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
]
|
],
|
||||||
|
"build": {
|
||||||
|
"artifacts": [
|
||||||
|
{
|
||||||
|
"name": "server",
|
||||||
|
"kind": "image",
|
||||||
|
"from": "Dockerfile"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "trust",
|
||||||
|
"kind": "upstream",
|
||||||
|
"from": "alpine@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"on": [
|
||||||
|
{
|
||||||
|
"arg": "GO_BASE",
|
||||||
|
"image": "golang@sha256:699337d620559a59b4a2bb298ad59611e535d2ee755a34cf2d2a98f37578dc80"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"arg": "ALPINE_BASE",
|
||||||
|
"image": "alpine@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
"serves": {
|
"serves": {
|
||||||
"acme-ca": {
|
"acme-ca": {
|
||||||
"path": "/acme/acme/directory",
|
"path": "/acme/acme/directory",
|
||||||
"root": ""
|
"roots": "/roots.pem"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
@@ -25,10 +25,7 @@
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"password": "/var/lib/mesh/step-ca/password",
|
"password": "/var/lib/mesh/step-ca/password"
|
||||||
"root-cert": "/var/lib/mesh/step-ca/root-cert",
|
|
||||||
"root-key": "/var/lib/mesh/step-ca/root-key",
|
|
||||||
"root-key-password": "/var/lib/mesh/step-ca/root-key-password"
|
|
||||||
},
|
},
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
{
|
||||||
@@ -59,30 +56,6 @@
|
|||||||
"mode": "0600",
|
"mode": "0600",
|
||||||
"content": "DOCKER_STEPCA_INIT_PASSWORD=${secret:password}\nDOCKER_STEPCA_INIT_DNS_NAMES=${machine:at},${machine:name},localhost,127.0.0.1\n"
|
"content": "DOCKER_STEPCA_INIT_PASSWORD=${secret:password}\nDOCKER_STEPCA_INIT_DNS_NAMES=${machine:at},${machine:name},localhost,127.0.0.1\n"
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"id": "root-cert-file",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/mesh/step-ca/root-cert.pem",
|
|
||||||
"mode": "0600",
|
|
||||||
"owner": "1000:1000",
|
|
||||||
"content": "${secret:root-cert}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "root-key-file",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/mesh/step-ca/root-key.pem",
|
|
||||||
"mode": "0600",
|
|
||||||
"owner": "1000:1000",
|
|
||||||
"content": "${secret:root-key}"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"id": "root-key-password-file",
|
|
||||||
"type": "file",
|
|
||||||
"path": "/var/lib/mesh/step-ca/root-key-password.txt",
|
|
||||||
"mode": "0600",
|
|
||||||
"owner": "1000:1000",
|
|
||||||
"content": "${secret:root-key-password}"
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"id": "server",
|
"id": "server",
|
||||||
"type": "container",
|
"type": "container",
|
||||||
@@ -95,10 +68,7 @@
|
|||||||
"env": {
|
"env": {
|
||||||
"DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA",
|
"DOCKER_STEPCA_INIT_NAME": "Mesh Internal CA",
|
||||||
"DOCKER_STEPCA_INIT_ACME": "true",
|
"DOCKER_STEPCA_INIT_ACME": "true",
|
||||||
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false",
|
"DOCKER_STEPCA_INIT_REMOTE_MANAGEMENT": "false"
|
||||||
"DOCKER_STEPCA_INIT_ROOT_FILE": "/run/mesh/root-cert.pem",
|
|
||||||
"DOCKER_STEPCA_INIT_KEY_FILE": "/run/mesh/root-key.pem",
|
|
||||||
"DOCKER_STEPCA_INIT_KEY_PASSWORD_FILE": "/run/mesh/root-key-password.txt"
|
|
||||||
},
|
},
|
||||||
"volumes": [
|
"volumes": [
|
||||||
"/var/lib/step-ca:/home/step",
|
"/var/lib/step-ca:/home/step",
|
||||||
|
|||||||
@@ -6,7 +6,8 @@
|
|||||||
],
|
],
|
||||||
"requires": [
|
"requires": [
|
||||||
"postgres-database",
|
"postgres-database",
|
||||||
"route"
|
"route",
|
||||||
|
"secret"
|
||||||
],
|
],
|
||||||
"contributes": {
|
"contributes": {
|
||||||
"postgres-database": {
|
"postgres-database": {
|
||||||
@@ -22,7 +23,11 @@
|
|||||||
"route": "/var/lib/umami/route.json"
|
"route": "/var/lib/umami/route.json"
|
||||||
},
|
},
|
||||||
"secrets": {
|
"secrets": {
|
||||||
"postgres-database": "/var/lib/umami/database.secret"
|
"postgres-database": "/var/lib/umami/database.secret",
|
||||||
|
"secret": {
|
||||||
|
"app-secret": "/var/lib/umami/app.secret",
|
||||||
|
"admin": "/var/lib/umami/admin.secret"
|
||||||
|
}
|
||||||
},
|
},
|
||||||
"provides": [
|
"provides": [
|
||||||
{
|
{
|
||||||
@@ -40,8 +45,6 @@
|
|||||||
"analytics": "/var/lib/umami/grants"
|
"analytics": "/var/lib/umami/grants"
|
||||||
},
|
},
|
||||||
"own-secrets": {
|
"own-secrets": {
|
||||||
"app-secret": "/var/lib/umami/app.secret",
|
|
||||||
"admin": "/var/lib/umami/admin.secret",
|
|
||||||
"broker": "/var/lib/mesh/umami/broker"
|
"broker": "/var/lib/mesh/umami/broker"
|
||||||
},
|
},
|
||||||
"listens": [
|
"listens": [
|
||||||
|
|||||||
Reference in New Issue
Block a user