Pin attended OpenBao login to the operator tunnel.
Public Ingress is gone, so BAO_ADDR=https://bao.coulomb.social fails before command handoff. The wrapper now uses 127.0.0.1:18200. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
parent
4b34c239bc
commit
75e5c1af65
4 changed files with 37 additions and 4 deletions
|
|
@ -55,7 +55,9 @@ Warden's contained child inherits the caller's cwd, so a relative `scripts/...`
|
||||||
path raises OSError, prints `attended command could not start`, and revokes a
|
path raises OSError, prints `attended command could not start`, and revokes a
|
||||||
successful login without applying the callback. Do not run the owner command
|
successful login without applying the callback. Do not run the owner command
|
||||||
directly with a persistent token. The wrapper also supplies the WSL browser
|
directly with a persistent token. The wrapper also supplies the WSL browser
|
||||||
launcher when native `xdg-open` is absent.
|
launcher when native `xdg-open` is absent, and pins `BAO_ADDR` to
|
||||||
|
`http://127.0.0.1:18200`. After public Ingress retraction, CLI login against
|
||||||
|
`https://bao.coulomb.social` fails before command handoff.
|
||||||
|
|
||||||
## Guarded sequence
|
## Guarded sequence
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -23,14 +23,25 @@ def reviewed_command(args):
|
||||||
return [str(command), *args[1:]]
|
return [str(command), *args[1:]]
|
||||||
|
|
||||||
|
|
||||||
def main():
|
TUNNEL = 'http://127.0.0.1:18200'
|
||||||
args = reviewed_command(sys.argv[1:])
|
|
||||||
|
|
||||||
|
def contained_env():
|
||||||
env = os.environ.copy()
|
env = os.environ.copy()
|
||||||
|
env['BAO_ADDR'] = TUNNEL
|
||||||
|
env['VAULT_ADDR'] = TUNNEL
|
||||||
|
env.pop('BAO_TOKEN', None)
|
||||||
|
env.pop('VAULT_TOKEN', None)
|
||||||
if not any(shutil.which(x) for x in ('xdg-open', 'x-www-browser', 'www-browser')):
|
if not any(shutil.which(x) for x in ('xdg-open', 'x-www-browser', 'www-browser')):
|
||||||
if not Path('/mnt/c/Windows/System32/WindowsPowerShell/v1.0/powershell.exe').is_file():
|
if not Path('/mnt/c/Windows/System32/WindowsPowerShell/v1.0/powershell.exe').is_file():
|
||||||
raise SystemExit('No supported attended browser launcher is available')
|
raise SystemExit('No supported attended browser launcher is available')
|
||||||
env['PATH'] = str(Path(__file__).resolve().parent / 'operator-browser') + os.pathsep + env.get('PATH', '')
|
env['PATH'] = str(Path(__file__).resolve().parent / 'operator-browser') + os.pathsep + env.get('PATH', '')
|
||||||
os.execvpe('warden', ['warden', 'access', 'openbao-platform-admin-login', '--exec', '--', *args], env)
|
return env
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
args = reviewed_command(sys.argv[1:])
|
||||||
|
os.execvpe('warden', ['warden', 'access', 'openbao-platform-admin-login', '--exec', '--', *args], contained_env())
|
||||||
|
|
||||||
|
|
||||||
if __name__ == '__main__':
|
if __name__ == '__main__':
|
||||||
|
|
|
||||||
|
|
@ -87,6 +87,21 @@ def test_receipt_records_apply_and_failure(tmp_path, monkeypatch):
|
||||||
assert json.loads(failed.read_text())['status'] == 'bao_write_failed'
|
assert json.loads(failed.read_text())['status'] == 'bao_write_failed'
|
||||||
|
|
||||||
|
|
||||||
|
def test_attended_wrapper_pins_operator_tunnel_address(monkeypatch):
|
||||||
|
spec = importlib.util.spec_from_file_location(
|
||||||
|
'attended', Path(__file__).resolve().parents[1] / 'scripts/openbao-attended-exec.py')
|
||||||
|
wrapper = importlib.util.module_from_spec(spec)
|
||||||
|
spec.loader.exec_module(wrapper)
|
||||||
|
monkeypatch.setenv('BAO_ADDR', 'https://bao.coulomb.social')
|
||||||
|
monkeypatch.setenv('VAULT_ADDR', 'https://bao.coulomb.social')
|
||||||
|
monkeypatch.setenv('BAO_TOKEN', 'must-not-propagate')
|
||||||
|
env = wrapper.contained_env()
|
||||||
|
assert env['BAO_ADDR'] == wrapper.TUNNEL
|
||||||
|
assert env['VAULT_ADDR'] == wrapper.TUNNEL
|
||||||
|
assert 'BAO_TOKEN' not in env
|
||||||
|
assert 'VAULT_TOKEN' not in env
|
||||||
|
|
||||||
|
|
||||||
def test_attended_wrapper_requires_absolute_existing_executable(tmp_path, monkeypatch):
|
def test_attended_wrapper_requires_absolute_existing_executable(tmp_path, monkeypatch):
|
||||||
import os
|
import os
|
||||||
spec = importlib.util.spec_from_file_location(
|
spec = importlib.util.spec_from_file_location(
|
||||||
|
|
|
||||||
|
|
@ -47,3 +47,8 @@ Operator approved CCR-2026-0026/0027 on 2026-09-15. Source registration is in
|
||||||
`key-cape/config/service-clients.example.yaml`. Live apply is the silent helper
|
`key-cape/config/service-clients.example.yaml`. Live apply is the silent helper
|
||||||
`scripts/provision-sitting-requester.sh` through `openbao-attended-exec.py`.
|
`scripts/provision-sitting-requester.sh` through `openbao-attended-exec.py`.
|
||||||
No sitting POST until exchange proof exists. Do not widen CCR-2026-0024/0025.
|
No sitting POST until exchange proof exists. Do not widen CCR-2026-0024/0025.
|
||||||
|
|
||||||
|
2026-09-15 attended attempt failed before command handoff:
|
||||||
|
`revocation could not be confirmed`. Public Ingress is already absent, and the
|
||||||
|
shell still had `BAO_ADDR=https://bao.coulomb.social`. The wrapper now pins the
|
||||||
|
operator tunnel. Retry that same helper; do not treat this attempt as custody.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue