fedora-cosmic: allow seeding the Kanidm unixd token from a CI secret
build.sh writes KANIDM_UNIXD_TOKEN to /etc/kanidm/unixd_token (0600) when the secret is set, via a generated add-files include. Without the secret the image is built unchanged and the token must be provisioned on the host.
This commit is contained in:
@@ -84,6 +84,8 @@ jobs:
|
|||||||
--password-stdin --authfile ~/.docker/config.json "${registry_host}"
|
--password-stdin --authfile ~/.docker/config.json "${registry_host}"
|
||||||
|
|
||||||
- name: Build image
|
- name: Build image
|
||||||
|
env:
|
||||||
|
KANIDM_UNIXD_TOKEN: ${{ secrets.KANIDM_UNIXD_TOKEN }}
|
||||||
run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}"
|
run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}"
|
||||||
|
|
||||||
- name: Push and sign image
|
- name: Push and sign image
|
||||||
|
|||||||
@@ -3,3 +3,4 @@
|
|||||||
/build/
|
/build/
|
||||||
/cache/
|
/cache/
|
||||||
/*.rpm
|
/*.rpm
|
||||||
|
kanidm-unixd-token
|
||||||
|
|||||||
@@ -128,6 +128,28 @@ generate_exclude_yaml() {
|
|||||||
} > "${out}"
|
} > "${out}"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Seed the Kanidm unixd service account token from the KANIDM_UNIXD_TOKEN
|
||||||
|
# environment variable (a CI secret). The token is added to the image, so treat
|
||||||
|
# the image as sensitive: anyone who can pull it can read the token.
|
||||||
|
seed_kanidm_token() {
|
||||||
|
local dir="$1"
|
||||||
|
local out="${dir}/kanidm-token.yaml"
|
||||||
|
if [[ -n "${KANIDM_UNIXD_TOKEN:-}" ]]; then
|
||||||
|
printf '%s\n' "${KANIDM_UNIXD_TOKEN}" > "${dir}/kanidm-unixd-token"
|
||||||
|
chmod 0600 "${dir}/kanidm-unixd-token"
|
||||||
|
cat > "${out}" <<'EOF'
|
||||||
|
# Generated by build.sh from the KANIDM_UNIXD_TOKEN secret.
|
||||||
|
add-files:
|
||||||
|
- ["kanidm-unixd-token", "/etc/kanidm/unixd_token"]
|
||||||
|
EOF
|
||||||
|
else
|
||||||
|
cat > "${out}" <<'EOF'
|
||||||
|
# Generated by build.sh: no Kanidm token seeded (KANIDM_UNIXD_TOKEN unset).
|
||||||
|
add-files: []
|
||||||
|
EOF
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
case "${BUILD_MODE}" in
|
case "${BUILD_MODE}" in
|
||||||
upstream)
|
upstream)
|
||||||
[[ -n "${UPSTREAM_REPO}" ]] || { echo "UPSTREAM_REPO not set in ${CONF}" >&2; exit 1; }
|
[[ -n "${UPSTREAM_REPO}" ]] || { echo "UPSTREAM_REPO not set in ${CONF}" >&2; exit 1; }
|
||||||
@@ -160,6 +182,8 @@ case "${BUILD_MODE}" in
|
|||||||
"${BUILD_DIR}/upstream/hardware-exclude.yaml"
|
"${BUILD_DIR}/upstream/hardware-exclude.yaml"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
seed_kanidm_token "${BUILD_DIR}/upstream"
|
||||||
|
|
||||||
MANIFEST="${BUILD_DIR}/upstream/manifest.yaml"
|
MANIFEST="${BUILD_DIR}/upstream/manifest.yaml"
|
||||||
;;
|
;;
|
||||||
standalone)
|
standalone)
|
||||||
@@ -188,6 +212,7 @@ ref: ${REF}
|
|||||||
include:
|
include:
|
||||||
- manifest.yaml
|
- manifest.yaml
|
||||||
EOF
|
EOF
|
||||||
|
seed_kanidm_token "${local_dir}"
|
||||||
MANIFEST="${local_dir}/.build-manifest.yaml"
|
MANIFEST="${local_dir}/.build-manifest.yaml"
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
|
|||||||
@@ -93,3 +93,12 @@ postprocess:
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
semanage permissive -a unconfined_service_t || true
|
semanage permissive -a unconfined_service_t || true
|
||||||
|
|
||||||
|
# Lock down the Kanidm service account token if it was seeded at build time.
|
||||||
|
- |
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -xeuo pipefail
|
||||||
|
if [[ -f /etc/kanidm/unixd_token ]]; then
|
||||||
|
chown root:root /etc/kanidm/unixd_token
|
||||||
|
chmod 0600 /etc/kanidm/unixd_token
|
||||||
|
fi
|
||||||
|
|||||||
@@ -30,3 +30,5 @@ include:
|
|||||||
- custom.yaml
|
- custom.yaml
|
||||||
# Generated by build.sh from upstream-exclude.txt (exclude-packages list).
|
# Generated by build.sh from upstream-exclude.txt (exclude-packages list).
|
||||||
- hardware-exclude.yaml
|
- hardware-exclude.yaml
|
||||||
|
# Generated by build.sh; adds the Kanidm unixd token when provided.
|
||||||
|
- kanidm-token.yaml
|
||||||
|
|||||||
Reference in New Issue
Block a user