Files
ayurishchevandClaude Sonnet 5.5 debf2afed2 Add authentication: admin/agent bearer tokens for the API, login for the dashboard
control-api: every route now carries a mandatory access level (admin / agent /
open) in a route table. All /api/v1/admin/* require the admin token; the
write calls of validator-agent and prober (self-check, events, results,
complete) require a separate static agent token; register, heartbeat and
fetching the assignment stay open. Tokens come from env vars, are compared in
constant time and never logged. An empty token leaves that level open with a
startup warning (backward compatible).

validator-agent / prober: apiclient sends the agent token only to control-api.

admin-dashboard: login/password (from env) with a stateless HMAC session
cookie, Origin-based CSRF check, per-IP brute-force throttle, HX-Redirect for
htmx polls, logout in the sidebar; the dashboard calls control-api with the
admin token. Login page layout fixed after review.

Also: env plumbing in docker-compose/rxprod-compose/systemd/config examples,
e2e script with token assertions, tests, docs (API, SETUP, USAGE, DASHBOARD,
README), plan and review under docs/changes/, bin/ rebuilt with new
SHA256SUMS.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-01 11:35:24 +03:00

58 lines
2.3 KiB
Bash

# Copy to .env.prod per host and fill in only what that host needs.
#
# docker compose -f docker-compose.yml -f docker-compose.prod.yml --env-file .env.prod up -d --build
#
# COMPOSE_PROFILES controls which services THIS host runs — pick one:
# control-plane host: control-plane,dashboard
# external prober site: prober
# OpenStack validator VM: validator
# single all-in-one host: control-plane,dashboard,prober,validator
COMPOSE_PROFILES=control-plane,dashboard
# --- control-api (only needed when this host runs the control-plane profile) ---
# Real config with validators/sites/targets/ip_addresses — see
# configs/control-api.example.yaml and docs/SETUP.md. Required.
CONTROL_API_CONFIG_PATH=/etc/cloud-ip-validator/control-api.yaml
# OpenStack creds — only read when the mounted control-api.yaml has
# openstack.mode: real. Leave blank in mock mode.
OS_AUTH_URL=
OS_PROJECT_ID=
OS_REGION_NAME=
OS_INTERFACE=
OS_TOKEN=
# auth_method: password instead of token:
# OS_USERNAME=
# OS_USER_DOMAIN_NAME=
# OS_PASSWORD=
# --- prober (only needed on a prober-profile host) ---
PROBER_SITE_ID=
# Real, network-reachable control-api URL — NOT http://control-api:8080
# unless this host also runs the control-plane profile in the same
# compose invocation.
PROBER_CONTROL_API_URL=https://control-api.internal.example.com
# --- validator-agent (only needed on a validator-profile host) ---
VALIDATOR_AGENT_VALIDATOR_ID=
VALIDATOR_AGENT_CONTROL_API_URL=https://control-api.internal.example.com
# --- admin-dashboard (only needed on a dashboard-profile host) ---
ADMIN_DASHBOARD_CONTROL_API_URL=http://control-api:8080
# --- authentication (fill in only what this host needs; empty = open + warning) ---
# Generate each secret with: openssl rand -hex 32
# Rollout order without downtime: update all binaries first, then give the
# tokens to prober / validator-agent / dashboard, and set the control-api
# tokens (and restart it) last.
#
# control-plane host: tokens that control-api enforces
CONTROL_API_ADMIN_TOKEN=
CONTROL_API_AGENT_TOKEN=
# dashboard host: control-api's admin token, the login, and the cookie-signing key
ADMIN_DASHBOARD_CONTROL_API_TOKEN=
ADMIN_DASHBOARD_USERNAME=
ADMIN_DASHBOARD_PASSWORD=
ADMIN_DASHBOARD_SESSION_SECRET=
# prober / validator hosts use CONTROL_API_AGENT_TOKEN (same value as above)