From 0a0c57b610f067160297dcc2df56f7ee226b686a Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 10 Sep 2026 22:35:49 +0200 Subject: [PATCH] whole-mesh-full: the CA root a person hands the mesh must be readable by it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The control plane's image is FROM scratch and runs as 65534, and docker cp keeps the mode a file had outside — openssl writes a private key 0600 root-owned, so the copy landed unreadable, secret accept failed with permission denied, and the CA crash-looped on a root it never got. Chowning it inside the container is not available: there is no shell in there to do it with. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- test/integration/whole-mesh-full.test.ts | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/test/integration/whole-mesh-full.test.ts b/test/integration/whole-mesh-full.test.ts index f5233a5..90f5f05 100644 --- a/test/integration/whole-mesh-full.test.ts +++ b/test/integration/whole-mesh-full.test.ts @@ -370,6 +370,15 @@ async function deliverCaRoot(): Promise { "rm -f root.unenc", "openssl req -x509 -new -key root.key -passin file:key-password -sha256 -days 3650" + ` -out root.crt -subj "/CN=Mesh Internal CA/O=Novox Mesh Lab"`, + // Readable by the control plane, which is not root. Its image is FROM scratch and runs as + // 65534, and `docker cp` keeps the ownership and mode a file had outside — openssl writes a + // private key 0600 root-owned, so the copy landed unreadable and `secret accept` failed with + // `open /ca-root-key: permission denied`. The CA then crash-looped on a root it never got. + // Chowning it inside the container is not available: there is no shell in there to do it with. + // + // Safe here and nowhere else: these three exist for the seconds between being written and + // being sealed to the machine, on a lab node, for a CA thrown away with the scenario. + "chmod 0644 /tmp/ca/root.crt /tmp/ca/root.key /tmp/ca/key-password", "docker cp /tmp/ca/root.crt mesh-control:/ca-root-cert", "docker cp /tmp/ca/root.key mesh-control:/ca-root-key", "docker cp /tmp/ca/key-password mesh-control:/ca-root-key-password",