v1.29.0: jump host is core + fix fresh-install setup.sh abort (#125)
Two fresh-install fixes and promote the SSH jump host from opt-in to core. setup.sh: fix silent abort after "Minting per-app OpenBao tokens". env_get's grep|cut pipeline returns non-zero under set -euo pipefail when .env exists (created by the root VAULT_TOKEN env_upsert) but an app-token key is absent (the normal first-run state); the unguarded existing assignment from env_get then tripped set -e and killed the script before minting any token. env_get now always returns 0 (|| true). Reproduced + verified under the exact condition. jump host is no longer optional: - docker-compose.yml: drop profiles jump-host from the jump-host service (always started); rename the opt-in test fixture profile jump-host to ldap-test. - setup.sh: SUBMODULES always includes jump-host; build/start/register/summary no longer guarded by JUMP_ENABLED; drop the COMPOSE_PROFILES export. - bootstrap.js: jump provisioning + directory record run unconditionally. - setup.env.example/docs: drop optional/CFG_JUMP_HOST_ENABLED wording. Co-authored-by: Claude <noreply@anthropic.com>
This commit is contained in:
+7
-9
@@ -170,12 +170,10 @@ services:
|
||||
retries: 3
|
||||
start_period: 30s
|
||||
|
||||
# Optional SSH jump host. Only started when the `jump-host` compose profile
|
||||
# is active — setup.sh exports COMPOSE_PROFILES=jump-host when
|
||||
# CFG_JUMP_HOST_ENABLED=true. Authenticates users against the SSO's OpenLDAP,
|
||||
# resolves reachable hosts from the directory API, and bridges SSH through.
|
||||
# SSH jump host — a core component, always built + started alongside the
|
||||
# SSO and proxy. Authenticates users against the SSO's OpenLDAP, resolves
|
||||
# reachable hosts from the directory API, and bridges SSH through.
|
||||
jump-host:
|
||||
profiles: ["jump-host"]
|
||||
build:
|
||||
context: ./jump-host
|
||||
dockerfile: Dockerfile
|
||||
@@ -220,11 +218,11 @@ services:
|
||||
# a container with a manually-dropped public key in authorized_keys never
|
||||
# exercises the LDAP-key-serving path a real production host does. Built
|
||||
# from the theta42/ldap-client submodule -- see ./config/ldap-test-host.vars
|
||||
# for setup notes. Same jump-host profile, so
|
||||
# `docker compose --profile jump-host up` brings up jump-host and a host it
|
||||
# can actually reach together.
|
||||
# for setup notes. Opt-in test fixture: bring it up explicitly with
|
||||
# `docker compose --profile ldap-test up` (jump-host itself now starts
|
||||
# unconditionally, so this only adds a downstream host for it to reach).
|
||||
ldap-test-host:
|
||||
profiles: ["jump-host"]
|
||||
profiles: ["ldap-test"]
|
||||
build:
|
||||
context: ./ldap-client
|
||||
dockerfile: Dockerfile
|
||||
|
||||
Reference in New Issue
Block a user