f77023db1d
test / integration-docker (pull_request) Successful in 11s
test / unit (pull_request) Successful in 43s
lint / lint (push) Successful in 56s
test / integration-firecracker (pull_request) Successful in 3m19s
test / coverage (pull_request) Successful in 19s
test / publish-infra (pull_request) Has been skipped
tracker-policy-pr / check-pr (pull_request) Successful in 7s
Separate the gateway (data plane) from the orchestrator (control plane) at the
module level. The gateway runtime files move out of the package root — and the
backend-neutral Gateway lifecycle ABC + GATEWAY_* constants move out of
orchestrator/ — into a new bot_bottle/gateway/ package:
gateway/__init__.py (was orchestrator/gateway.py: Gateway ABC + consts
+ rotate_gateway_ca)
gateway/gateway_init.py (the PID-1 daemon supervisor)
gateway/egress_addon.py, egress_addon_core.py, egress_dlp_config.py,
dlp_detectors.py (the egress mitmproxy daemon)
gateway/git_http_backend.py (the git-http daemon)
gateway/git_gate_render.py (the git-gate pre-receive rendering)
gateway/supervise_server.py (the supervise MCP daemon)
gateway/policy_resolver.py (the data-plane control-plane RPC client)
orchestrator/ now holds only control-plane files. The shared plan/types/auth
layer (egress.py=EgressPlan, git_gate.py=GitGatePlan, supervise.py,
supervise_types.py, control_auth.py) and the launch-time git-gate provisioning
helpers stay at root, so orchestrator/ and backend/ still own them.
Because these daemons are invoked as `python3 -m bot_bottle.<name>`, loaded flat
by mitmproxy, and referenced in Dockerfile.gateway, the move updates more than
Python imports: the `-m` invocations (firecracker/macOS infra scripts), the
Dockerfile.gateway addon shim + ENTRYPOINT, gateway_init's _DAEMONS module
paths, and the git-gate CGI heredocs all now point at bot_bottle.gateway.*.
No behavior change; full unit suite green (2251).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
63 lines
2.3 KiB
Python
63 lines
2.3 KiB
Python
"""Rotate the shared gateway's mitmproxy CA (issue #450).
|
|
|
|
python -m bot_bottle.orchestrator.rotate_ca
|
|
|
|
A deliberate CA rollover has two halves: drop the *persisted* CA so a fresh one
|
|
is minted, and drop the *running* gateway so its mitmproxy (which holds the old
|
|
CA in memory) is replaced. This one-shot command does both:
|
|
|
|
1. Delete the persisted CA under the host gateway-CA dir — the next gateway
|
|
start generates a new one (mitmproxy reuses an existing CA, generates only
|
|
when absent).
|
|
2. Force-remove the infra / standalone-gateway containers so the stale
|
|
in-memory CA is gone; the next bottle launch's idempotent `ensure_running`
|
|
brings the gateway back up and mints the fresh CA.
|
|
|
|
It does NOT re-provision the new CA into already-running bottles — those must be
|
|
re-attached so they install the new trust anchor. Rotation is thus an explicit,
|
|
operator-driven action with a brief egress interruption, not an automatic one.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
from ..docker_cmd import run_docker
|
|
from ..paths import host_gateway_ca_dir
|
|
from ..gateway import GATEWAY_NAME, rotate_gateway_ca
|
|
from .lifecycle import INFRA_NAME
|
|
|
|
# The containers whose mitmproxy would still be serving the old CA from memory:
|
|
# the consolidated infra container and the standalone per-host gateway.
|
|
_GATEWAY_CONTAINERS = (INFRA_NAME, GATEWAY_NAME)
|
|
|
|
|
|
def _out(msg: str) -> None:
|
|
sys.stdout.write(f"rotate-ca: {msg}\n")
|
|
|
|
|
|
def main(argv: list[str] | None = None) -> int:
|
|
del argv # no flags — a single deliberate action
|
|
ca_dir: Path = host_gateway_ca_dir()
|
|
removed = rotate_gateway_ca(ca_dir)
|
|
if removed:
|
|
_out(f"removed {len(removed)} CA file(s) from {ca_dir}")
|
|
else:
|
|
_out(f"no persisted CA under {ca_dir}; a fresh one is minted on next start")
|
|
|
|
# Drop any running gateway so its in-memory (now-stale) CA is replaced on
|
|
# the next launch. `rm --force` on an absent name is a tolerated no-op.
|
|
for name in _GATEWAY_CONTAINERS:
|
|
proc = run_docker(["docker", "rm", "--force", name])
|
|
if proc.returncode == 0 and proc.stdout.strip():
|
|
_out(f"removed running container {name}")
|
|
|
|
_out("done — the next bottle launch remints the CA; re-attach bottles to "
|
|
"install the new trust anchor")
|
|
return 0
|
|
|
|
|
|
if __name__ == "__main__":
|
|
raise SystemExit(main())
|