diff --git a/test/integration/whole-mesh-full.test.ts b/test/integration/whole-mesh-full.test.ts index f5233a5..90f5f05 100644 --- a/test/integration/whole-mesh-full.test.ts +++ b/test/integration/whole-mesh-full.test.ts @@ -370,6 +370,15 @@ async function deliverCaRoot(): Promise { "rm -f root.unenc", "openssl req -x509 -new -key root.key -passin file:key-password -sha256 -days 3650" + ` -out root.crt -subj "/CN=Mesh Internal CA/O=Novox Mesh Lab"`, + // Readable by the control plane, which is not root. Its image is FROM scratch and runs as + // 65534, and `docker cp` keeps the ownership and mode a file had outside — openssl writes a + // private key 0600 root-owned, so the copy landed unreadable and `secret accept` failed with + // `open /ca-root-key: permission denied`. The CA then crash-looped on a root it never got. + // Chowning it inside the container is not available: there is no shell in there to do it with. + // + // Safe here and nowhere else: these three exist for the seconds between being written and + // being sealed to the machine, on a lab node, for a CA thrown away with the scenario. + "chmod 0644 /tmp/ca/root.crt /tmp/ca/root.key /tmp/ca/key-password", "docker cp /tmp/ca/root.crt mesh-control:/ca-root-cert", "docker cp /tmp/ca/root.key mesh-control:/ca-root-key", "docker cp /tmp/ca/key-password mesh-control:/ca-root-key-password",