whole-mesh-full: the CA root a person hands the mesh must be readable by it
The control plane's image is FROM scratch and runs as 65534, and docker cp keeps the mode a file had outside — openssl writes a private key 0600 root-owned, so the copy landed unreadable, secret accept failed with permission denied, and the CA crash-looped on a root it never got. Chowning it inside the container is not available: there is no shell in there to do it with. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -370,6 +370,15 @@ async function deliverCaRoot(): Promise<boolean> {
|
|||||||
"rm -f root.unenc",
|
"rm -f root.unenc",
|
||||||
"openssl req -x509 -new -key root.key -passin file:key-password -sha256 -days 3650" +
|
"openssl req -x509 -new -key root.key -passin file:key-password -sha256 -days 3650" +
|
||||||
` -out root.crt -subj "/CN=Mesh Internal CA/O=Novox Mesh Lab"`,
|
` -out root.crt -subj "/CN=Mesh Internal CA/O=Novox Mesh Lab"`,
|
||||||
|
// Readable by the control plane, which is not root. Its image is FROM scratch and runs as
|
||||||
|
// 65534, and `docker cp` keeps the ownership and mode a file had outside — openssl writes a
|
||||||
|
// private key 0600 root-owned, so the copy landed unreadable and `secret accept` failed with
|
||||||
|
// `open /ca-root-key: permission denied`. The CA then crash-looped on a root it never got.
|
||||||
|
// Chowning it inside the container is not available: there is no shell in there to do it with.
|
||||||
|
//
|
||||||
|
// Safe here and nowhere else: these three exist for the seconds between being written and
|
||||||
|
// being sealed to the machine, on a lab node, for a CA thrown away with the scenario.
|
||||||
|
"chmod 0644 /tmp/ca/root.crt /tmp/ca/root.key /tmp/ca/key-password",
|
||||||
"docker cp /tmp/ca/root.crt mesh-control:/ca-root-cert",
|
"docker cp /tmp/ca/root.crt mesh-control:/ca-root-cert",
|
||||||
"docker cp /tmp/ca/root.key mesh-control:/ca-root-key",
|
"docker cp /tmp/ca/root.key mesh-control:/ca-root-key",
|
||||||
"docker cp /tmp/ca/key-password mesh-control:/ca-root-key-password",
|
"docker cp /tmp/ca/key-password mesh-control:/ca-root-key-password",
|
||||||
|
|||||||
Reference in New Issue
Block a user