From 7693e22b08dde242f32500c8df4a9c370fd1abae Mon Sep 17 00:00:00 2001 From: Wesley van Tilburg Date: Mon, 21 Sep 2026 19:24:15 +0200 Subject: [PATCH] fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the secret is set, via a generated add-files include. Without the secret the image is built unchanged and the token must be provisioned on the host. --- .gitea/workflows/build.yaml | 2 ++ .gitignore | 1 + build.sh | 25 +++++++++++++++++++++++++ images/fedora-cosmic/custom.yaml | 9 +++++++++ images/fedora-cosmic/manifest.yaml | 2 ++ 5 files changed, 39 insertions(+) diff --git a/.gitea/workflows/build.yaml b/.gitea/workflows/build.yaml index fb2d944..d6d93aa 100644 --- a/.gitea/workflows/build.yaml +++ b/.gitea/workflows/build.yaml @@ -84,6 +84,8 @@ jobs: --password-stdin --authfile ~/.docker/config.json "${registry_host}" - name: Build image + env: + KANIDM_UNIXD_TOKEN: ${{ secrets.KANIDM_UNIXD_TOKEN }} run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}" - name: Push and sign image diff --git a/.gitignore b/.gitignore index f10ca3d..9644ea8 100644 --- a/.gitignore +++ b/.gitignore @@ -3,3 +3,4 @@ /build/ /cache/ /*.rpm +kanidm-unixd-token diff --git a/build.sh b/build.sh index 22d2097..de6e042 100755 --- a/build.sh +++ b/build.sh @@ -128,6 +128,28 @@ generate_exclude_yaml() { } > "${out}" } +# Seed the Kanidm unixd service account token from the KANIDM_UNIXD_TOKEN +# environment variable (a CI secret). The token is added to the image, so treat +# the image as sensitive: anyone who can pull it can read the token. +seed_kanidm_token() { + local dir="$1" + local out="${dir}/kanidm-token.yaml" + if [[ -n "${KANIDM_UNIXD_TOKEN:-}" ]]; then + printf '%s\n' "${KANIDM_UNIXD_TOKEN}" > "${dir}/kanidm-unixd-token" + chmod 0600 "${dir}/kanidm-unixd-token" + cat > "${out}" <<'EOF' +# Generated by build.sh from the KANIDM_UNIXD_TOKEN secret. +add-files: + - ["kanidm-unixd-token", "/etc/kanidm/unixd_token"] +EOF + else + cat > "${out}" <<'EOF' +# Generated by build.sh: no Kanidm token seeded (KANIDM_UNIXD_TOKEN unset). +add-files: [] +EOF + fi +} + case "${BUILD_MODE}" in upstream) [[ -n "${UPSTREAM_REPO}" ]] || { echo "UPSTREAM_REPO not set in ${CONF}" >&2; exit 1; } @@ -160,6 +182,8 @@ case "${BUILD_MODE}" in "${BUILD_DIR}/upstream/hardware-exclude.yaml" fi + seed_kanidm_token "${BUILD_DIR}/upstream" + MANIFEST="${BUILD_DIR}/upstream/manifest.yaml" ;; standalone) @@ -188,6 +212,7 @@ ref: ${REF} include: - manifest.yaml EOF + seed_kanidm_token "${local_dir}" MANIFEST="${local_dir}/.build-manifest.yaml" ;; *) diff --git a/images/fedora-cosmic/custom.yaml b/images/fedora-cosmic/custom.yaml index 21c2825..26accc2 100644 --- a/images/fedora-cosmic/custom.yaml +++ b/images/fedora-cosmic/custom.yaml @@ -93,3 +93,12 @@ postprocess: #!/usr/bin/env bash set -xeuo pipefail semanage permissive -a unconfined_service_t || true + + # Lock down the Kanidm service account token if it was seeded at build time. + - | + #!/usr/bin/env bash + set -xeuo pipefail + if [[ -f /etc/kanidm/unixd_token ]]; then + chown root:root /etc/kanidm/unixd_token + chmod 0600 /etc/kanidm/unixd_token + fi diff --git a/images/fedora-cosmic/manifest.yaml b/images/fedora-cosmic/manifest.yaml index c2d8b60..6d28e93 100644 --- a/images/fedora-cosmic/manifest.yaml +++ b/images/fedora-cosmic/manifest.yaml @@ -30,3 +30,5 @@ include: - custom.yaml # Generated by build.sh from upstream-exclude.txt (exclude-packages list). - hardware-exclude.yaml + # Generated by build.sh; adds the Kanidm unixd token when provided. + - kanidm-token.yaml