A build machine is told what to check the broker against
The credential was a URL and nothing else, so the builder verified the broker the ordinary way — against public roots. A mesh's broker presents a certificate of the mesh's own, which is in no trust store anywhere, so the connection could only ever succeed against a broker somebody else vouches for. It failed at TLS with an error about an unknown authority rather than about a missing pin, and the container sat there running: up, credential on disk, connected to nothing. So the sealed credential now carries the URL and the broker's fingerprint — the same two facts a node's token carries, for the same reason, delivered out of band relative to the thing being trusted. The builder pins it: the standard chain check is replaced rather than removed, and what replaces it is stricter, accepting one certificate instead of every certificate a public authority would sign. A file holding only a URL still works, for a builder somebody runs by hand against a broker with an ordinary certificate.
This commit is contained in:
@@ -90,8 +90,34 @@ func TestTheCredentialComesFromAFileTheMeshSealed(t *testing.T) {
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got != "amqps://a-builder:secret@broker.internal:5671/" {
|
||||
t.Fatalf("got %q", got)
|
||||
if got.URL != "amqps://a-builder:secret@broker.internal:5671/" {
|
||||
t.Fatalf("got %q", got.URL)
|
||||
}
|
||||
}
|
||||
|
||||
// The credential the mesh seals carries what to check the broker's certificate against, because a
|
||||
// mesh's broker presents a certificate of the mesh's own and no public trust store has it. A URL
|
||||
// alone can only reach a broker somebody else vouches for.
|
||||
func TestTheSealedCredentialCarriesWhatVerifiesTheBroker(t *testing.T) {
|
||||
path := filepath.Join(t.TempDir(), "broker")
|
||||
if err := os.WriteFile(path, []byte(
|
||||
`{"url":"amqps://a-builder:secret@broker.internal:5671/","fingerprint":"abc123"}`),
|
||||
0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv("MESH_BROKER_FILE", path)
|
||||
t.Setenv("MESH_BROKER_AMQP", "")
|
||||
|
||||
got, err := brokerFrom()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got.URL != "amqps://a-builder:secret@broker.internal:5671/" {
|
||||
t.Fatalf("the url was lost: %q", got.URL)
|
||||
}
|
||||
if got.Fingerprint != "abc123" {
|
||||
t.Fatal("the builder was given nothing to check the broker against, so it can only " +
|
||||
"connect to a broker some public authority vouches for")
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user