181ca8c9cb
See CHANGELOG.md for the full breakdown. Summary:
- POST /api/v1/ldap/{bind,search}: LDAP-over-HTTPS so a client stops
speaking raw LDAP and instead calls the SSO, which binds/searches its
own OpenLDAP on the caller's behalf (DESIGN.md §3).
- LDAP byte-pump relay (utils/ldap_tunnel.js): forwards raw LDAP bytes
from an agent's local socket into OpenLDAP over the existing agent WSS
channel; the SSO never parses LDAP (DESIGN.md §4).
- POST /api/v1/agent/secrets: node-scoped OpenBao secret fetch for
agents, enforced to each agent's own secret/data/nodes/<id>/* prefix
(DESIGN.md §5).
- iam_apply signed command: push node-scoped IAM config (sudo rules, SSH
keys, access control, revocation) to an agent (DESIGN.md §6).
- Agent capability badges on the Directory Metrics tab, sourced from the
agent's own discovery frame.
- Join key management: GET /api/agent/join-keys/:id/agents (which hosts
enrolled through a key) plus a Manage join keys table in the Install
Agent modal with Revoke/Delete actions, confirmed inline per-row rather
than a blocking native confirm() or the shared app.messages.confirm()
banner (which desyncs across concurrent rows -- see CHANGELOG).
- docs/agents.md: capability matrix updated for the three new
capabilities, a full secrets-engine walkthrough with screenshots
(bash + Node consuming a rendered secret, plus the direct-API
alternative), and the join-key reuse/UI/audit questions answered.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
55 lines
1.8 KiB
Docker
55 lines
1.8 KiB
Docker
# Test-runner image for SSO Manager.
|
|
#
|
|
# Installs all dependencies (including dev) and bundles the app code plus
|
|
# the seed script. The entrypoint waits for LDAP + Redis, seeds the test
|
|
# user, then runs whatever command is given (default: npm test).
|
|
|
|
FROM node:20-alpine
|
|
|
|
# Install OpenLDAP clients (ldapadd, ldapsearch) and bash for the seed script
|
|
RUN apk add --no-cache openldap-clients bash
|
|
|
|
WORKDIR /app
|
|
|
|
# Copy and install dependencies (including devDependencies for jest/supertest)
|
|
COPY nodejs/package*.json ./
|
|
RUN npm ci
|
|
|
|
# Copy the application source
|
|
COPY nodejs/app.js ./
|
|
COPY nodejs/bin ./bin
|
|
COPY nodejs/conf ./conf
|
|
COPY nodejs/controller ./controller
|
|
COPY nodejs/middleware ./middleware
|
|
COPY nodejs/models ./models
|
|
# Without this the discovery/plugin suites cannot even load their subject and
|
|
# fail as "Cannot find module ../plugins/discovery/..." -- plugin code was
|
|
# effectively untested in CI.
|
|
COPY nodejs/plugins ./plugins
|
|
COPY nodejs/routes ./routes
|
|
COPY nodejs/services ./services
|
|
COPY nodejs/utils ./utils
|
|
COPY nodejs/views ./views
|
|
COPY nodejs/public ./public
|
|
COPY nodejs/tests ./tests
|
|
|
|
# SQLite database directory (config/inventory.sqlite for Resource model's ORM)
|
|
RUN mkdir -p /app/config
|
|
|
|
# Files expected at the flattened /app path (see Dockerfile.openldap notes)
|
|
COPY tos.md /tos.md
|
|
COPY README.md /README.md
|
|
COPY CHANGELOG.md /CHANGELOG.md
|
|
COPY API.md /API.md
|
|
COPY directory_spec.md /directory_spec.md
|
|
|
|
# Seed script and utility
|
|
COPY test_seed.js ./test_seed.js
|
|
COPY test/seed-test-user.sh /usr/local/bin/seed-test-user
|
|
RUN chmod +x /usr/local/bin/seed-test-user
|
|
# End-to-end LDAP tunnel test client (docker-compose.e2e.yml)
|
|
COPY test/tunnel_e2e.js ./test/tunnel_e2e.js
|
|
|
|
# Default command: seed the test user, then run the test suite
|
|
CMD ["sh", "-c", "seed-test-user && npm test"]
|