The installer delivers any MESH_…_FILE own secret, not only the store's #15
@@ -334,8 +334,10 @@ func secretsByVariableIn(manifest []byte) (map[string]string, error) {
|
||||
case "container":
|
||||
inside := mountedFrom(r.Volumes)
|
||||
for key, path := range r.Env {
|
||||
if !strings.HasPrefix(key, storeVariablePrefix) ||
|
||||
!strings.HasSuffix(key, storeFileSuffix) {
|
||||
// Any `MESH_…_FILE` naming an own-secret's file, not only the store's: the broker
|
||||
// settings took the same shape once a secret stopped travelling in an env-file
|
||||
// (novox/hq ADR 0086, issue 041).
|
||||
if !strings.HasPrefix(key, "MESH_") || !strings.HasSuffix(key, storeFileSuffix) {
|
||||
continue
|
||||
}
|
||||
on := path
|
||||
|
||||
@@ -273,3 +273,28 @@ func TestThePermanentControlPlaneIsAskedTheSameQuestion(t *testing.T) {
|
||||
t.Errorf("the module was never registered: %v", runtime.commands)
|
||||
}
|
||||
}
|
||||
|
||||
// The broker settings take the file shape too (novox/hq ADR 0086): a `MESH_BROKER_…_FILE` pointing
|
||||
// at a mounted own-secret is delivered as that secret, exactly as a store connection is.
|
||||
func TestABrokerSettingReadFromAFileIsDeliveredToo(t *testing.T) {
|
||||
manifest := `{
|
||||
"module": "mesh-controller", "version": "1",
|
||||
"own-secrets": {"broker": "/var/lib/mesh/mesh-controller/broker", "inventory": "/var/lib/mesh/mesh-controller/inventory"},
|
||||
"resources": [{
|
||||
"id": "server", "type": "container", "name": "mesh-controller", "image": "x@sha256:0",
|
||||
"volumes": ["/var/lib/mesh/mesh-controller/broker:/run/secrets/broker:ro",
|
||||
"/var/lib/mesh/mesh-controller/inventory:/run/secrets/inventory:ro"],
|
||||
"env": {"MESH_BROKER_AMQP_FILE": "/run/secrets/broker", "MESH_STORE_INVENTORY_FILE": "/run/secrets/inventory",
|
||||
"MESH_BROKER_CERTIFICATE": "/broker-tls/tls.crt"}
|
||||
}]}`
|
||||
wanted, err := secretsByVariableIn([]byte(manifest))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if wanted["MESH_BROKER_AMQP"] != "broker" || wanted["MESH_STORE_INVENTORY"] != "inventory" {
|
||||
t.Fatalf("wanted %v", wanted)
|
||||
}
|
||||
if _, has := wanted["MESH_BROKER_CERTIFICATE"]; has {
|
||||
t.Fatal("a plain path variable was taken for a secret")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user