feat(orchestrator): durable launch-broker secret via TrustDomain (#468)
prd-number-check / require-numbered-prds (pull_request) Failing after 12s
tracker-policy-pr / check-pr (pull_request) Successful in 13s
test / integration-docker (pull_request) Successful in 20s
lint / lint (push) Failing after 56s
test / unit (pull_request) Failing after 4m4s
test / coverage (pull_request) Has been skipped
prd-number-check / require-numbered-prds (pull_request) Failing after 12s
tracker-policy-pr / check-pr (pull_request) Successful in 13s
test / integration-docker (pull_request) Successful in 20s
lint / lint (push) Failing after 56s
test / unit (pull_request) Failing after 4m4s
test / coverage (pull_request) Has been skipped
Chunk 2 of the host-control-server stack: close the PRD's **durable secret** gap and replace chunk 1's BOT_BOTTLE_BROKER_SECRET stopgap. - trust_domain.py: two new domains. LAUNCH_BROKER holds the durable HS256 key both the orchestrator (signer) and the host control server (verifier) share for the broker's launch JWT — a host-canonical key file minted 0600 on first use, so a restarted orchestrator re-verifies against the same key (re-adoption). HOST_CONTROLLER is the separate domain for the controller's own lifecycle endpoints, keyed by a key the orchestrator never holds (its lifecycle role is `host`, deliberately outside the control-plane ROLES). LaunchBrokerProvisioning is the fail-closed seam, mirroring ControlPlaneProvisioning. - orchestrator_auth.py: ROLE_HOST, outside ROLES so the orchestrator's control-plane key can neither mint nor accept it. - paths.py: key-file + env-var constants for both domains. - host_server.py / __main__.py: broker_secret() now resolves the durable LAUNCH_BROKER key — env-injected for a containerized launcher, else the host key file for a host-side dev-harness process — so `--broker http` and the host controller "just work" on one host without exporting a secret, and stay fail-closed when the root is unwritable. Tested: domain boundary (host role unmintable by the control plane, cross-domain tokens don't verify), distinct keys/env vars per domain, provisioning fail-closed, and broker_secret env/file resolution + durability. Full unit suite green; pyright clean; pylint 9.90. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -8,9 +8,12 @@ the full sign -> POST -> verify -> act seam over HTTP.
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import os
|
||||
import secrets
|
||||
import tempfile
|
||||
import threading
|
||||
import unittest
|
||||
from unittest.mock import patch
|
||||
|
||||
from bot_bottle.orchestrator.broker import (
|
||||
BrokerAuthError,
|
||||
@@ -21,10 +24,11 @@ from bot_bottle.orchestrator.broker import (
|
||||
)
|
||||
from bot_bottle.orchestrator.broker_client import BrokerClient
|
||||
from bot_bottle.orchestrator.host_server import (
|
||||
broker_secret_from_env,
|
||||
broker_secret,
|
||||
dispatch,
|
||||
make_host_server,
|
||||
)
|
||||
from bot_bottle.paths import LAUNCH_BROKER_KEY_ENV
|
||||
|
||||
|
||||
def _body(obj: object) -> bytes:
|
||||
@@ -106,16 +110,24 @@ class TestDispatch(unittest.TestCase):
|
||||
self.assertEqual(200, status)
|
||||
|
||||
|
||||
class TestBrokerSecretFromEnv(unittest.TestCase):
|
||||
def test_reads_hex_secret(self) -> None:
|
||||
s = secrets.token_bytes(16)
|
||||
self.assertEqual(s, broker_secret_from_env({"BOT_BOTTLE_BROKER_SECRET": s.hex()}))
|
||||
class TestBrokerSecret(unittest.TestCase):
|
||||
"""The durable launch-broker key (#468/#476): prefer the env-injected key,
|
||||
else the durable host key file, so signer and verifier resolve the same one."""
|
||||
|
||||
def test_unset_is_none(self) -> None:
|
||||
self.assertIsNone(broker_secret_from_env({}))
|
||||
def test_reads_injected_key_from_env(self) -> None:
|
||||
self.assertEqual(
|
||||
b"injected-key", broker_secret({LAUNCH_BROKER_KEY_ENV: "injected-key"}))
|
||||
|
||||
def test_invalid_hex_is_none(self) -> None:
|
||||
self.assertIsNone(broker_secret_from_env({"BOT_BOTTLE_BROKER_SECRET": "not-hex"}))
|
||||
def test_falls_back_to_the_durable_host_key_file(self) -> None:
|
||||
with tempfile.TemporaryDirectory() as root:
|
||||
with patch.dict("os.environ", {"BOT_BOTTLE_ROOT": root}, clear=False):
|
||||
os.environ.pop(LAUNCH_BROKER_KEY_ENV, None)
|
||||
first = broker_secret()
|
||||
second = broker_secret()
|
||||
self.assertTrue(first)
|
||||
# Durable: minted once, the same key on every subsequent call — a
|
||||
# restarted orchestrator re-verifies against it.
|
||||
self.assertEqual(first, second)
|
||||
|
||||
|
||||
class TestSeamRoundTrip(unittest.TestCase):
|
||||
|
||||
Reference in New Issue
Block a user