feat: add fail-closed Hub access profile foundation
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
parent
df39fd5f43
commit
3e386147fd
35 changed files with 2009 additions and 195 deletions
|
|
@ -38,9 +38,21 @@ class RuntimeSettings:
|
|||
legacy_health: bool = False
|
||||
statehub_inbox_reads: bool = False
|
||||
statehub_inbox_agent: str = "state-hub"
|
||||
access_mode: str = "auto"
|
||||
|
||||
@property
|
||||
def enforce_access(self) -> bool:
|
||||
return self.access_mode == "enforce" or (
|
||||
self.access_mode == "auto" and self.environment not in {"development", "test"}
|
||||
)
|
||||
|
||||
def __post_init__(self) -> None:
|
||||
if self.statehub_inbox_reads and (self.backend != "postgresql" or not self.api_token):
|
||||
if self.access_mode not in {"auto", "enforce", "development"}:
|
||||
raise ValueError("unsupported access mode")
|
||||
if self.access_mode == "development" and self.environment not in {"development", "test"}:
|
||||
raise ValueError("development access is forbidden outside development/test")
|
||||
if self.statehub_inbox_reads and (self.backend != "postgresql" or
|
||||
(not self.enforce_access and not self.api_token)):
|
||||
raise ValueError("State Hub inbox reads require PostgreSQL and operator token")
|
||||
if self.repo_manager_timeout_seconds <= 0:
|
||||
raise ValueError("Repo Manager timeout must be positive")
|
||||
|
|
@ -87,6 +99,7 @@ class RuntimeSettings:
|
|||
legacy_health=_env_bool("HUB_CORE_LEGACY_HEALTH", False),
|
||||
statehub_inbox_reads=_env_bool("HUB_CORE_STATEHUB_INBOX_READS", False),
|
||||
statehub_inbox_agent=os.getenv("HUB_CORE_STATEHUB_INBOX_AGENT", "state-hub"),
|
||||
access_mode=os.getenv("HUB_CORE_ACCESS_MODE", "auto"),
|
||||
)
|
||||
|
||||
def readiness_checks(self, store_backend: str) -> dict[str, str]:
|
||||
|
|
@ -99,7 +112,8 @@ class RuntimeSettings:
|
|||
"operator",
|
||||
}
|
||||
authorization_ready = (
|
||||
not protected_groups
|
||||
self.enforce_access
|
||||
or not protected_groups
|
||||
or bool(self.api_token)
|
||||
or store_backend == "postgresql"
|
||||
)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue