The broker-admin marker ends in a newline, and the transcript never says a credential
The verify reads the marker with the shell's read, which fails at end of file without a line ending; the action ran and its verify said no. And the applier reports each action with its command line, two of which now carry the real store and broker passwords — the installer masks the values it made in everything it says.
This commit is contained in:
@@ -143,6 +143,20 @@ func freshSecret() (string, error) {
|
||||
return base64.RawURLEncoding.EncodeToString(b), nil
|
||||
}
|
||||
|
||||
// Masking makes a reporter that never says the credentials this run made.
|
||||
//
|
||||
// The applier reports each action with its command line, and two of them now carry a real
|
||||
// password — the context schemas' connection strings and the broker's change_password. Those
|
||||
// lines go to a terminal and to whatever keeps the transcript, which for the lab is a file. The
|
||||
// exact values are known here, so they are replaced wherever they appear, in every line said.
|
||||
func Masking(say func(string), c RootCredentials) func(string) {
|
||||
replacer := strings.NewReplacer(c.Store, "…", c.Broker, "…")
|
||||
if c.Store == "" || c.Broker == "" {
|
||||
return say
|
||||
}
|
||||
return func(line string) { say(replacer.Replace(line)) }
|
||||
}
|
||||
|
||||
// RefuseExistingServers stops a run that would put a made credential in front of a server raised
|
||||
// by an earlier installer with the template's.
|
||||
//
|
||||
@@ -219,14 +233,16 @@ func RewriteRoot(r *Rewritten, c RootCredentials) (RootRewrite, error) {
|
||||
// Verified by a marker on the broker's own data volume holding this password's fingerprint —
|
||||
// the image carries nothing that can try a password from inside, and a marker that merely
|
||||
// existed would let a regenerated password go unapplied for ever. What proves the password
|
||||
// works is the control plane answering over it, a few resources later.
|
||||
// works is the control plane answering over it, a few resources later. The marker ends in a
|
||||
// newline because the verify reads it with the shell's `read`, which fails at end of file
|
||||
// without one — an action that ran and a verify that said no, once, in the lab.
|
||||
fp := credentialFingerprint(c.Broker)
|
||||
action := templateBrokerReady + "\n" +
|
||||
" {\n" +
|
||||
" \"id\": \"broker-admin\",\n" +
|
||||
" \"type\": \"action\",\n" +
|
||||
" \"in\": \"mesh-broker\",\n" +
|
||||
" \"command\": [\"sh\", \"-c\", \"lavinmqctl change_password " + BrokerAdminUser + " '" + c.Broker + "' && printf %s " + fp + " > " + brokerAdminMarker + "\"],\n" +
|
||||
" \"command\": [\"sh\", \"-c\", \"lavinmqctl change_password " + BrokerAdminUser + " '" + c.Broker + "' && echo " + fp + " > " + brokerAdminMarker + "\"],\n" +
|
||||
" \"verify\": [\"sh\", \"-c\", \"read m < " + brokerAdminMarker + " && [ \\\"$m\\\" = " + fp + " ]\"]\n" +
|
||||
" },"
|
||||
if bundle, err = replaceOnce(bundle, templateBrokerReady, action, "the broker's readiness check"); err != nil {
|
||||
|
||||
Reference in New Issue
Block a user