fix(macos): persist gateway CA on host
test / integration-docker (push) Successful in 19s
Update Quality Badges / update-badges (push) Failing after 42s
lint / lint (push) Successful in 52s
test / unit (push) Successful in 1m43s
test / integration-firecracker (push) Successful in 4m56s
test / coverage (push) Successful in 17s
test / publish-infra (push) Successful in 1m49s
test / integration-docker (push) Successful in 19s
Update Quality Badges / update-badges (push) Failing after 42s
lint / lint (push) Successful in 52s
test / unit (push) Successful in 1m43s
test / integration-firecracker (push) Successful in 4m56s
test / coverage (push) Successful in 17s
test / publish-infra (push) Successful in 1m49s
This commit was merged in pull request #454.
This commit is contained in:
@@ -324,15 +324,24 @@ re-attachment blocker distinct from #443/#445).
|
||||
|
||||
The CA lives on the **host filesystem** at `bot_bottle_root()/gateway-ca`
|
||||
(`host_gateway_ca_dir()`), bind-mounted into the container at mitmproxy's
|
||||
confdir. This is deliberately a host bind-mount, **not a Docker named volume**:
|
||||
a named volume survives `docker rm` but is silently wiped by
|
||||
`docker volume prune` / `docker system prune --volumes` during routine host
|
||||
maintenance, which is exactly how the ephemeral-CA symptom shows up in
|
||||
practice. A path under the app-data root is never pruned by docker, and stays
|
||||
directly inspectable and rotatable from the host. mitmproxy reuses an existing
|
||||
CA and generates one only on first run, so the bind-mount alone gives
|
||||
confdir. This is deliberately a host bind-mount, **not a container-runtime
|
||||
named volume**: a named volume survives ordinary container removal but can be
|
||||
silently wiped by Docker's or Apple Container's volume-prune commands during
|
||||
routine host maintenance, which is exactly how the ephemeral-CA symptom shows
|
||||
up in practice. A path under the app-data root is not managed or pruned by the
|
||||
container runtime, and stays directly inspectable and rotatable from the host.
|
||||
mitmproxy reuses an existing CA and generates one only on first run, so the
|
||||
bind-mount alone gives
|
||||
"adopt-existing, generate-on-first-run" for free.
|
||||
|
||||
The macOS backend uses the same host-resident CA directory and bind-mounts it
|
||||
into the consolidated Apple infra container. Its `bot-bottle-mac-db` named
|
||||
volume remains container-only because that prevents incoherent cross-kernel
|
||||
SQLite locking, but the CA is deliberately not stored there: Apple Container
|
||||
also has a `container volume prune` operation, and the named volume is
|
||||
temporarily unreferenced while the infra container is recreated. Keeping the
|
||||
CA on the host makes both ordinary recreation and volume pruning safe.
|
||||
|
||||
**Deliberate rollover** is the explicit inverse: `rotate_gateway_ca()` removes
|
||||
the persisted CA material so the next start remints it, and the
|
||||
`python -m bot_bottle.orchestrator.rotate_ca` one-shot wires that together with
|
||||
|
||||
Reference in New Issue
Block a user