security: remove node credentials from tracked files (open-source Phase 1)
Demo images / Build & push demo images (push) Failing after 2m28s
Demo images / Build & push demo images (push) Failing after 2m28s
Scrubs the fleet SSH/UI password from every tracked file (22 occurrences) and removes inline credentials from the code paths that used them. Docs and trackers keep the surrounding context — these are published under docs/history/ per the open-source plan — with the literals replaced by <FLEET_PW> / <FLEET_PW_ALT> so the "two variants exist" detail survives without the values. Three of the eight files were in .planning/ and were NOT in the plan's enumerated list; the reworked audit-secrets.sh found them. Code changes: - neode-ui/test-openwrt.mjs: node URL and password come from ARCHY_NODE_URL / ARCHY_NODE_PW; the SSH target derives from the URL instead of a hardcoded tailnet IP; exits 2 when unset. - scripts/run-post-install-tests.sh: drops the built-in "testpass123!" default and adds --password-stdin; refuses to run unauthenticated instead of silently trying a known password. --phase1-only still needs no password. - .gitea/workflows/post-install-tests.yml: sshpass with an inline literal replaced by key auth (NODE_SSH_KEY secret); password comes from the NODE_UI_PASSWORD secret and is piped over stdin rather than argv, so it stays out of the node's process list and the job log. Default target IP removed. scripts/audit-secrets.sh now reports 5/5 pass, 0 fail. Note: rotation of the exposed credentials is deliberately deferred to the pre-publish gate and is NOT done by this commit — these values are still live. See Phase 0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
e3b98ed18f
commit
19082a44f0
@@ -4,13 +4,11 @@ on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
target:
|
||||
description: 'Target node IP (e.g. 192.168.1.198)'
|
||||
description: 'Target node IP or hostname'
|
||||
required: true
|
||||
default: '192.168.1.198'
|
||||
password:
|
||||
description: 'Node password (or "auto" for fresh install)'
|
||||
description: 'Node UI password (leave blank to use the NODE_UI_PASSWORD secret)'
|
||||
required: false
|
||||
default: 'auto'
|
||||
|
||||
jobs:
|
||||
post-install-tests:
|
||||
@@ -22,33 +20,46 @@ jobs:
|
||||
with:
|
||||
fetch-depth: 1
|
||||
|
||||
- name: Run post-install tests on target
|
||||
- name: Install SSH key
|
||||
env:
|
||||
SSH_KEY: ${{ secrets.NODE_SSH_KEY }}
|
||||
run: |
|
||||
TARGET="${{ github.event.inputs.target }}"
|
||||
PASSWORD="${{ github.event.inputs.password }}"
|
||||
if [ "$PASSWORD" = "auto" ]; then
|
||||
PASSWORD="testpass123!"
|
||||
if [ -z "$SSH_KEY" ]; then
|
||||
echo "ERROR: repository secret NODE_SSH_KEY is not configured."
|
||||
echo "Post-install tests authenticate by key; password auth is not supported."
|
||||
exit 1
|
||||
fi
|
||||
mkdir -p ~/.ssh && chmod 700 ~/.ssh
|
||||
printf '%s\n' "$SSH_KEY" > ~/.ssh/id_ed25519
|
||||
chmod 600 ~/.ssh/id_ed25519
|
||||
|
||||
- name: Run post-install tests on target
|
||||
env:
|
||||
TARGET: ${{ github.event.inputs.target }}
|
||||
NODE_PASSWORD: ${{ github.event.inputs.password }}
|
||||
NODE_UI_PASSWORD: ${{ secrets.NODE_UI_PASSWORD }}
|
||||
SSH_USER: ${{ vars.NODE_SSH_USER }}
|
||||
run: |
|
||||
PASSWORD="${NODE_PASSWORD:-$NODE_UI_PASSWORD}"
|
||||
if [ -z "$PASSWORD" ]; then
|
||||
echo "ERROR: no node password supplied (input or NODE_UI_PASSWORD secret)."
|
||||
exit 1
|
||||
fi
|
||||
USER_NAME="${SSH_USER:-archipelago}"
|
||||
|
||||
echo "══════════════════════════════════════════"
|
||||
echo "Running post-install tests on $TARGET"
|
||||
echo "══════════════════════════════════════════"
|
||||
|
||||
# Copy test script to target and run
|
||||
sshpass -p 'archipelago' scp -o StrictHostKeyChecking=no \
|
||||
scp -o StrictHostKeyChecking=accept-new \
|
||||
scripts/run-post-install-tests.sh \
|
||||
archipelago@${TARGET}:/tmp/run-post-install-tests.sh 2>/dev/null || \
|
||||
scp -o StrictHostKeyChecking=no \
|
||||
scripts/run-post-install-tests.sh \
|
||||
archipelago@${TARGET}:/tmp/run-post-install-tests.sh
|
||||
"${USER_NAME}@${TARGET}:/tmp/run-post-install-tests.sh"
|
||||
|
||||
# Run tests (with sudo for service checks)
|
||||
sshpass -p 'archipelago' ssh -o StrictHostKeyChecking=no \
|
||||
archipelago@${TARGET} \
|
||||
"sudo bash /tmp/run-post-install-tests.sh '$PASSWORD'" 2>/dev/null || \
|
||||
ssh -o StrictHostKeyChecking=no \
|
||||
archipelago@${TARGET} \
|
||||
"sudo bash /tmp/run-post-install-tests.sh '$PASSWORD'"
|
||||
# Password is passed over stdin, never as an argv the node's process
|
||||
# list (or this job's log) would expose.
|
||||
printf '%s' "$PASSWORD" | ssh -o StrictHostKeyChecking=accept-new \
|
||||
"${USER_NAME}@${TARGET}" \
|
||||
"sudo bash /tmp/run-post-install-tests.sh --password-stdin"
|
||||
|
||||
frontend-tests:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
Reference in New Issue
Block a user