fix(gateway): persist mitmproxy CA on the host, not a named volume (#450)
The shared gateway self-generates a mitmproxy CA that every bottle installs to trust its TLS interception. It was persisted on a Docker named volume, which survives `docker rm` but is silently wiped by `docker volume prune` / `docker system prune --volumes` during routine host maintenance. When that happens the gateway mints a fresh CA on restart, and every already-running bottle fails the TLS handshake even after it re-resolves and reconnects to the moved gateway — a re-attachment blocker distinct from #443/#445. Move CA persistence to a host bind-mount under the app-data root (`bot_bottle_root()/gateway-ca`, via `host_gateway_ca_dir()`), mirroring how the shared DB and control-plane token already live on the host. Docker never prunes a path under the root, and it stays inspectable + rotatable from the host. mitmproxy already adopts an existing CA and generates one only on first run, so the bind-mount gives adopt-existing/generate-on-first-run for free. Add an explicit rollover path: `rotate_gateway_ca()` clears the persisted CA so the next start remints it, and `python -m bot_bottle.orchestrator.rotate_ca` wires that together with dropping the running gateway container (whose mitmproxy still holds the old CA in memory). Rotation stays an operator action — it doesn't auto-re-provision running bottles, which re-attach to pick up the new anchor. Scope: the Docker infra/gateway path (the "infra container" in the report). The macOS (`container`-only volume) and Firecracker (VM-attached ext4) backends persist the CA differently and are unaffected. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -33,6 +33,13 @@ HOST_DB_FILENAME = "bot-bottle.db"
|
||||
CONTROL_PLANE_TOKEN_FILENAME = "control-plane-token"
|
||||
CONTROL_PLANE_TOKEN_ENV = "BOT_BOTTLE_CONTROL_PLANE_TOKEN"
|
||||
|
||||
# The host directory holding the gateway's persistent mitmproxy CA. Bind-mounted
|
||||
# into the infra/gateway container at mitmproxy's confdir so the self-generated
|
||||
# CA survives container recreation — every agent installs this one CA to trust
|
||||
# the shared gateway's TLS interception, so it must not rotate on restart. See
|
||||
# host_gateway_ca_dir() for why this is a host bind-mount, not a named volume.
|
||||
GATEWAY_CA_DIRNAME = "gateway-ca"
|
||||
|
||||
|
||||
def bot_bottle_root() -> Path:
|
||||
"""The app data root — `$BOT_BOTTLE_ROOT` if set, else `~/.bot-bottle`."""
|
||||
@@ -59,6 +66,23 @@ def host_db_dir() -> Path:
|
||||
return db_dir
|
||||
|
||||
|
||||
def host_gateway_ca_dir() -> Path:
|
||||
"""The directory holding the gateway's persistent mitmproxy CA, created if
|
||||
missing. Backends bind-mount this into the infra/gateway container at
|
||||
mitmproxy's confdir so the CA persists across container recreation.
|
||||
|
||||
A host bind-mount under the app-data root — deliberately NOT a Docker
|
||||
named volume. A named volume survives `docker rm` but is silently wiped by
|
||||
`docker volume prune` / `docker system prune --volumes` during routine host
|
||||
maintenance; the gateway then mints a fresh CA that every already-running
|
||||
bottle distrusts, failing the TLS handshake even after it reconnects to the
|
||||
moved gateway (issue #450). A path under the root docker never prunes it,
|
||||
and it stays directly inspectable + rotatable from the host."""
|
||||
ca_dir = bot_bottle_root() / GATEWAY_CA_DIRNAME
|
||||
ca_dir.mkdir(parents=True, exist_ok=True)
|
||||
return ca_dir
|
||||
|
||||
|
||||
def host_control_plane_token() -> str:
|
||||
"""The per-host control-plane secret, minted (256-bit, url-safe) and
|
||||
persisted 0600 on first use, then reused.
|
||||
@@ -94,8 +118,10 @@ __all__ = [
|
||||
"HOST_DB_FILENAME",
|
||||
"CONTROL_PLANE_TOKEN_FILENAME",
|
||||
"CONTROL_PLANE_TOKEN_ENV",
|
||||
"GATEWAY_CA_DIRNAME",
|
||||
"bot_bottle_root",
|
||||
"host_db_path",
|
||||
"host_db_dir",
|
||||
"host_gateway_ca_dir",
|
||||
"host_control_plane_token",
|
||||
]
|
||||
|
||||
Reference in New Issue
Block a user