v1.14.0: load secrets from OpenBao at boot via @simpleworkjs/bao-conf
bin/www now runs bao-conf.init({ path: 'jump-host' }) before
require('../models'), so the OIDC clientSecret captured at require time
inside createOidcClient sees the OpenBao-merged config. Authenticates to
OpenBao with a scoped VAULT_TOKEN (policy jump-host), never the root
token; fail-soft to CONF_SECRETS if OpenBao is unreachable.
config/jump-secrets.js becomes an operator-edit seed artifact (OpenBao
authoritative). README gains a Secrets section.
Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
+34
-23
@@ -9,32 +9,43 @@ const http = require('http');
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
const { Server } = require('socket.io');
|
||||
|
||||
require('../models');
|
||||
// @simpleworkjs/conf loads ./config/jump-secrets.js synchronously, then
|
||||
// @simpleworkjs/bao-conf deep-merges secret/jump-host/conf from OpenBao over
|
||||
// it. The OIDC clientSecret is captured at require time inside models (via
|
||||
// createOidcClient), so the fetch MUST resolve before require('../models').
|
||||
// Fail-soft: if OpenBao is unreachable, init() leaves conf as the file-loaded
|
||||
// fallback and boot continues from ./config/jump-secrets.js.
|
||||
require('@simpleworkjs/bao-conf').init({ path: 'jump-host', conf }).then(() => {
|
||||
require('../models');
|
||||
|
||||
const app = require('../app');
|
||||
const middleware = require('../middleware/auth');
|
||||
const sshServer = require('../services/ssh_server');
|
||||
const app = require('../app');
|
||||
const middleware = require('../middleware/auth');
|
||||
const sshServer = require('../services/ssh_server');
|
||||
|
||||
const webPort = (conf.web && conf.web.port) || 3002;
|
||||
const server = http.createServer(app);
|
||||
const webPort = (conf.web && conf.web.port) || 3002;
|
||||
const server = http.createServer(app);
|
||||
|
||||
// Socket.IO — the client framework (app-base.js) opens an authenticated socket.
|
||||
// We don't push anything yet, but serving /socket.io keeps the shared front-end
|
||||
// working exactly as it does in the sibling apps.
|
||||
const io = new Server(server);
|
||||
io.use(middleware.authIO);
|
||||
app.io = io;
|
||||
// Socket.IO — the client framework (app-base.js) opens an authenticated socket.
|
||||
// We don't push anything yet, but serving /socket.io keeps the shared front-end
|
||||
// working exactly as it does in the sibling apps.
|
||||
const io = new Server(server);
|
||||
io.use(middleware.authIO);
|
||||
app.io = io;
|
||||
|
||||
server.listen(webPort, () => {
|
||||
console.log(`[web] jump-host UI/API on :${server.address().port}`);
|
||||
});
|
||||
server.listen(webPort, () => {
|
||||
console.log(`[web] jump-host UI/API on :${server.address().port}`);
|
||||
});
|
||||
|
||||
sshServer.start();
|
||||
sshServer.start();
|
||||
|
||||
function shutdown() {
|
||||
console.log('[jump-host] shutting down');
|
||||
server.close();
|
||||
process.exit(0);
|
||||
}
|
||||
process.on('SIGTERM', shutdown);
|
||||
process.on('SIGINT', shutdown);
|
||||
function shutdown() {
|
||||
console.log('[jump-host] shutting down');
|
||||
server.close();
|
||||
process.exit(0);
|
||||
}
|
||||
process.on('SIGTERM', shutdown);
|
||||
process.on('SIGINT', shutdown);
|
||||
}).catch(err => {
|
||||
console.error('boot failed:', err);
|
||||
process.exit(1);
|
||||
});
|
||||
Generated
+15
-2
@@ -1,16 +1,17 @@
|
||||
{
|
||||
"name": "t42-jump-host",
|
||||
"version": "1.9.0",
|
||||
"version": "1.11.0",
|
||||
"lockfileVersion": 3,
|
||||
"requires": true,
|
||||
"packages": {
|
||||
"": {
|
||||
"name": "t42-jump-host",
|
||||
"version": "1.9.0",
|
||||
"version": "1.11.0",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@fortawesome/fontawesome-free": "^7.3.0",
|
||||
"@simpleworkjs/app-stack": "^1.0.0",
|
||||
"@simpleworkjs/bao-conf": "^1.0.0",
|
||||
"@simpleworkjs/conf": "^1.2.0",
|
||||
"@simpleworkjs/directory-schema": "^1.0.0",
|
||||
"@simpleworkjs/frontend": "^0.2.6",
|
||||
@@ -156,6 +157,18 @@
|
||||
"node": ">=18.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@simpleworkjs/bao-conf": {
|
||||
"version": "1.0.0",
|
||||
"resolved": "https://registry.npmjs.org/@simpleworkjs/bao-conf/-/bao-conf-1.0.0.tgz",
|
||||
"integrity": "sha512-HxB2ohFuDKbwTfNh5dXCot0dd6qoP+3Ebz1xKH0eOhKNVNMjHU1p7XZv2VTe+VnHn+DV22Eh8lAgWxnX/pkXUw==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"extend": "^3.0.2"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=18.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@simpleworkjs/conf": {
|
||||
"version": "1.2.0",
|
||||
"resolved": "https://registry.npmjs.org/@simpleworkjs/conf/-/conf-1.2.0.tgz",
|
||||
|
||||
+2
-1
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "t42-jump-host",
|
||||
"version": "1.11.0",
|
||||
"version": "1.14.0",
|
||||
"description": "SSH jump host for the theta42 stack — LDAP-authenticated, directory-driven host bridging with audit and metrics",
|
||||
"author": [
|
||||
{
|
||||
@@ -21,6 +21,7 @@
|
||||
"dependencies": {
|
||||
"@fortawesome/fontawesome-free": "^7.3.0",
|
||||
"@simpleworkjs/app-stack": "^1.0.0",
|
||||
"@simpleworkjs/bao-conf": "^1.0.0",
|
||||
"@simpleworkjs/conf": "^1.2.0",
|
||||
"@simpleworkjs/directory-schema": "^1.0.0",
|
||||
"@simpleworkjs/frontend": "^0.2.6",
|
||||
|
||||
Reference in New Issue
Block a user