security: remove node credentials from tracked files (open-source Phase 1)
Demo images / Build & push demo images (push) Failing after 2m28s
Demo images / Build & push demo images (push) Failing after 2m28s
Scrubs the fleet SSH/UI password from every tracked file (22 occurrences) and removes inline credentials from the code paths that used them. Docs and trackers keep the surrounding context — these are published under docs/history/ per the open-source plan — with the literals replaced by <FLEET_PW> / <FLEET_PW_ALT> so the "two variants exist" detail survives without the values. Three of the eight files were in .planning/ and were NOT in the plan's enumerated list; the reworked audit-secrets.sh found them. Code changes: - neode-ui/test-openwrt.mjs: node URL and password come from ARCHY_NODE_URL / ARCHY_NODE_PW; the SSH target derives from the URL instead of a hardcoded tailnet IP; exits 2 when unset. - scripts/run-post-install-tests.sh: drops the built-in "testpass123!" default and adds --password-stdin; refuses to run unauthenticated instead of silently trying a known password. --phase1-only still needs no password. - .gitea/workflows/post-install-tests.yml: sshpass with an inline literal replaced by key auth (NODE_SSH_KEY secret); password comes from the NODE_UI_PASSWORD secret and is piped over stdin rather than argv, so it stays out of the node's process list and the job log. Default target IP removed. scripts/audit-secrets.sh now reports 5/5 pass, 0 fail. Note: rotation of the exposed credentials is deliberately deferred to the pre-publish gate and is NOT done by this commit — these values are still live. See Phase 0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
e3b98ed18f
commit
19082a44f0
@@ -2,8 +2,9 @@
|
||||
# Post-install + onboarding + container lifecycle E2E tests.
|
||||
# Run on an installed Archipelago node (SSH or local).
|
||||
#
|
||||
# Usage: bash run-post-install-tests.sh [password]
|
||||
# bash run-post-install-tests.sh --phase1-only # Install checks only (no auth)
|
||||
# Usage: bash run-post-install-tests.sh --password-stdin # read password from stdin (preferred)
|
||||
# bash run-post-install-tests.sh [password] # argv form; visible in `ps`, local use only
|
||||
# bash run-post-install-tests.sh --phase1-only # Install checks only (no auth)
|
||||
#
|
||||
# Tests:
|
||||
# Phase 1: Install verification (services, files, logs) — safe, no side effects
|
||||
@@ -12,15 +13,22 @@
|
||||
set -u
|
||||
|
||||
PHASE1_ONLY=false
|
||||
PASSWORD="testpass123!"
|
||||
PASSWORD=""
|
||||
|
||||
for arg in "$@"; do
|
||||
case "$arg" in
|
||||
--phase1-only) PHASE1_ONLY=true ;;
|
||||
--password-stdin) IFS= read -r PASSWORD || true ;;
|
||||
*) PASSWORD="$arg" ;;
|
||||
esac
|
||||
done
|
||||
|
||||
if [ "$PHASE1_ONLY" = false ] && [ -z "$PASSWORD" ]; then
|
||||
echo "ERROR: no password supplied. Use --password-stdin, pass one as an argument," >&2
|
||||
echo " or run --phase1-only for the no-auth install checks." >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
BASE="http://127.0.0.1:5678"
|
||||
JAR="/tmp/e2e-cookies.txt"
|
||||
rm -f "$JAR"
|
||||
|
||||
Reference in New Issue
Block a user