feat(policy): netkingdom maturity-gated publication-scope policy
Token scope is now bound to package maturity, gated on netkingdom's own maturity: - maturity-build -> gitea-wide, maturity-test -> org-wide, maturity-prod -> repo-scoped (scope narrows as stakes rise; broad tokens only for low-stakes build artifacts) - the graduated table is DORMANT until netkingdom reaches production grade; until then every lane clamps to repo-scope, injected as NPM_AUTH_TOKEN (fail-safe) - token env-var name signals blast radius: NPM_AUTH_TOKEN (repo default), NPM_AUTH_COULOMB_TOKEN (org), NPM_AUTH_GITEA_TOKEN (gitea), NPM_AUTH_WHYNOT_TOKEN (npm scope, defined but unused), NPM_AUTH_WHYNOTDESIGN (explicit repo) netkingdom is at maturity-build today, so whynot-design resolves to repo-scope / NPM_AUTH_TOKEN. Flip netkingdom_maturity to maturity-prod to activate graduation. - policies/netkingdom-publication-scope.yaml: the policy data + gate - publication_policy.py: load + resolve (clamp/active, env naming, override) - exec delivery injects under the resolved env-var name (was fixed SE_NPM_TOKEN) - catalog lane carries delivery_config.npm.maturity - new CLI: `secrets-engine policy publication <lane>` - docs/publication-scope-policy.md; tests for clamp, graduation, naming, override Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
f87f4e5e4d
commit
5b48033bce
11 changed files with 394 additions and 9 deletions
|
|
@ -27,9 +27,29 @@ from typing import Iterator
|
|||
from secrets_engine.catalog import CatalogEntry
|
||||
from secrets_engine.errors import DeliveryError
|
||||
from secrets_engine.openbao import OpenBaoClient
|
||||
from secrets_engine.publication_policy import PublicationPolicy, resolve
|
||||
from secrets_engine.redact import redact_text
|
||||
|
||||
|
||||
def resolve_npm_token_env(entry: CatalogEntry, *, policy_dir=None) -> str:
|
||||
"""Resolve the env-var name to inject for a lane via the publication policy."""
|
||||
if policy_dir is None:
|
||||
from secrets_engine.config import Config
|
||||
|
||||
policy_dir = Config.load().policy_dir
|
||||
npm = entry.npm
|
||||
policy = PublicationPolicy.load(policy_dir)
|
||||
res = resolve(
|
||||
policy,
|
||||
org=entry.org,
|
||||
repo=entry.repo,
|
||||
npm_scope=npm.get("scope", ""),
|
||||
package_maturity=npm.get("maturity", "maturity-build"),
|
||||
token_env_override=npm.get("token_env", ""),
|
||||
)
|
||||
return res.token_env
|
||||
|
||||
|
||||
def _fetch_value(client: OpenBaoClient, entry: CatalogEntry, field: str) -> str:
|
||||
"""Read the field value via an approle-scoped token. Held in memory only."""
|
||||
try:
|
||||
|
|
@ -58,11 +78,13 @@ def _registry_authkey(registry: str) -> str:
|
|||
|
||||
|
||||
@contextmanager
|
||||
def _npm_userconfig(registry: str, scope: str) -> Iterator[Path]:
|
||||
def _npm_userconfig(registry: str, scope: str, token_env: str) -> Iterator[Path]:
|
||||
"""Write a mode-0600 temp .npmrc for the configured registry/scope.
|
||||
|
||||
The token itself is NOT written to the file — npm expands ${SE_NPM_TOKEN}
|
||||
from the child environment, so the value never touches disk.
|
||||
The token itself is NOT written to the file — npm expands ${<token_env>}
|
||||
from the child environment, so the value never touches disk. `token_env` is
|
||||
resolved from the netkingdom publication-scope policy, so its name reflects
|
||||
the lane's effective publication scope.
|
||||
"""
|
||||
fd, name = tempfile.mkstemp(prefix="se-npmrc-", suffix=".ini")
|
||||
path = Path(name)
|
||||
|
|
@ -72,7 +94,7 @@ def _npm_userconfig(registry: str, scope: str) -> Iterator[Path]:
|
|||
with os.fdopen(fd, "w") as fh:
|
||||
# e.g. @whynot:registry=https://gitea.coulomb.social/api/packages/coulomb/npm/
|
||||
fh.write(f"{scope}:registry={registry}\n")
|
||||
fh.write(f"{authkey}:_authToken=${{SE_NPM_TOKEN}}\n")
|
||||
fh.write(f"{authkey}:_authToken=${{{token_env}}}\n")
|
||||
yield path
|
||||
finally:
|
||||
try:
|
||||
|
|
@ -96,6 +118,7 @@ def exec_with_secret(
|
|||
command: list[str],
|
||||
*,
|
||||
mode: str = "auto",
|
||||
policy_dir=None,
|
||||
) -> int:
|
||||
"""Run `command` with the lane's secret injected for the child only.
|
||||
|
||||
|
|
@ -132,9 +155,10 @@ def exec_with_secret(
|
|||
f"lane '{entry.id}' npm-config delivery needs "
|
||||
"delivery_config.npm.registry and .scope"
|
||||
)
|
||||
with _npm_userconfig(registry, scope) as npmrc:
|
||||
token_env = resolve_npm_token_env(entry, policy_dir=policy_dir)
|
||||
with _npm_userconfig(registry, scope, token_env) as npmrc:
|
||||
child_env["NPM_CONFIG_USERCONFIG"] = str(npmrc)
|
||||
child_env["SE_NPM_TOKEN"] = value
|
||||
child_env[token_env] = value
|
||||
rc = _spawn(command, child_env, value)
|
||||
return rc
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue