Compare commits
105 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a1ea2d458e | |||
| f7df04c2f0 | |||
| 3277972037 | |||
| 0c7593cc59 | |||
| ec625f7cb0 | |||
| 2a6c7775c9 | |||
| 010ff037ce | |||
| f8f1961b30 | |||
| 49dee5c477 | |||
| 1a832d068e | |||
| 60ae421cb2 | |||
| 90e95bfece | |||
| 144e97d0e1 | |||
| 9dc2de7818 | |||
| a959b331ae | |||
| b64083f008 | |||
| a2fa7a7fc7 | |||
| 6d6aea6011 | |||
| 43e3c79880 | |||
| 8b549c3315 | |||
| f25a684eb2 | |||
| 87d06441c7 | |||
| cf1591cdaa | |||
| d4154cfec6 | |||
| 6e411160a6 | |||
| e25d112787 | |||
| 3b5f3423c8 | |||
| 084c8fdfb3 | |||
| f2e924bf58 | |||
| 7c0fbd959f | |||
| e1cb855529 | |||
| 51e9e5e42f | |||
| e27439e491 | |||
| cf8c5c9a04 | |||
| c7c0aa8cf5 | |||
| 538b939f9e | |||
| d61e661099 | |||
| 81046a186f | |||
| ab9d9301f0 | |||
| ffc8af562a | |||
| a308fc8bbc | |||
| b6c8fe5a89 | |||
| b1cfaa1046 | |||
| 2f0e291b29 | |||
| db2db5095b | |||
| 79f1f62318 | |||
| d8717fd613 | |||
| f8a213a3bf | |||
| f90d319eeb | |||
| 27ab105325 | |||
| 5aaec1b18a | |||
| 8c7648781e | |||
| 46815e681c | |||
| a888624f38 | |||
| 191ef0a55f | |||
| 128083aee6 | |||
| f59f987115 | |||
| 71e8c09e8f | |||
| acc61a4c3d | |||
| 67f62276e7 | |||
| 6ef12408df | |||
| c3d232f7cc | |||
| 285cc4fbef | |||
| 5299556057 | |||
| cc03b3758c | |||
| 2d0496cfda | |||
| 48df638ddd | |||
| d6d2c7144a | |||
| 67374dc914 | |||
| a3b41c6775 | |||
| b25fb56a0d | |||
| a15002b588 | |||
| fe8133b21c | |||
| c83248e40b | |||
| e5a5eef428 | |||
| d098ba7082 | |||
| 1f8f4c70be | |||
| 9671339076 | |||
| aa74ca1b8c | |||
| cf919de1a6 | |||
| 3e85e37b63 | |||
| 75278f3e16 | |||
| faf67d8ffc | |||
| 892069eaea | |||
| 4f61eeb1a7 | |||
| f51b7e2dbe | |||
| 1c96c75118 | |||
| 5c8e5be0c5 | |||
| 4b613c7ca1 | |||
| a118f7ad4e | |||
| 87c8c0fc02 | |||
| 43cdf1dbbb | |||
| 9a737dd178 | |||
| fea1237c46 | |||
| 0b55535aa9 | |||
| 2baf8acd64 | |||
| 3943ed02c5 | |||
| 7f43eee36e | |||
| 19ea7e012a | |||
| 94b357e915 | |||
| f5d8cdd09d | |||
| 96b3aec5eb | |||
| 5aff5349a8 | |||
| 3b0f8f1f9a | |||
| 28016376ad |
+7
-1
@@ -76,4 +76,10 @@ MGMT_BIND=0.0.0.0
|
|||||||
# Defaults to LDAP_DOMAIN. Set to the hostname the proxy connects via
|
# Defaults to LDAP_DOMAIN. Set to the hostname the proxy connects via
|
||||||
# (sso-manager inside the docker net uses the service name, which is in the
|
# (sso-manager inside the docker net uses the service name, which is in the
|
||||||
# cert's SAN, so the default is usually fine).
|
# cert's SAN, so the default is usually fine).
|
||||||
LDAP_CERT_CN=
|
LDAP_CERT_CN=
|
||||||
|
|
||||||
|
# ── Optional: LDAPS hostname shown on the SSO /integrations page ────────────────
|
||||||
|
# Leave blank to derive from the public SSO host (SSO_HOST). Set an internal-only
|
||||||
|
# name like 'ldap.internal.example.com' or 'sso-manager' so direct-LDAP clients
|
||||||
|
# don't need a public 636 port forward. See docs/ldap.md for network layouts.
|
||||||
|
LDAPS_HOST=
|
||||||
@@ -2,7 +2,9 @@ name: Lint
|
|||||||
|
|
||||||
# theta-env has no app code of its own to unit-test (it orchestrates the
|
# theta-env has no app code of its own to unit-test (it orchestrates the
|
||||||
# proxy/sso-manager-node submodules) -- this checks the one thing that can
|
# proxy/sso-manager-node submodules) -- this checks the one thing that can
|
||||||
# actually break silently: setup.sh and bootstrap.js.
|
# actually break silently: setup.sh and bootstrap.js, plus a static
|
||||||
|
# consistency check on the config bootstrap.js generates for jump-host
|
||||||
|
# (test/check_jump_ldap_tls.js).
|
||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
branches:
|
branches:
|
||||||
@@ -39,3 +41,6 @@ jobs:
|
|||||||
|
|
||||||
- name: Syntax check
|
- name: Syntax check
|
||||||
run: node --check bootstrap/bootstrap.js
|
run: node --check bootstrap/bootstrap.js
|
||||||
|
|
||||||
|
- name: Jump-host LDAP config consistency
|
||||||
|
run: node test/check_jump_ldap_tls.js
|
||||||
|
|||||||
+6
-2
@@ -5,8 +5,12 @@
|
|||||||
config/
|
config/
|
||||||
backups/
|
backups/
|
||||||
|
|
||||||
# Legacy .env / proxy.env (no longer used — config is in ./config/). Still
|
# .env: NOT app config (that's ./config/, generated by setup.sh) — this is
|
||||||
# ignored in case a migrated deployment hasn't deleted them yet.
|
# docker compose's own auto-loaded env file, which setup.sh uses only to
|
||||||
|
# persist *_GIT_COMMIT build args so an ad-hoc rebuild of a single service
|
||||||
|
# still bakes the right commit hash. Generated; never commit.
|
||||||
|
# proxy.env: legacy, no longer used — still ignored in case an old
|
||||||
|
# deployment hasn't deleted it yet.
|
||||||
.env
|
.env
|
||||||
proxy.env
|
proxy.env
|
||||||
|
|
||||||
|
|||||||
@@ -4,3 +4,10 @@
|
|||||||
[submodule "proxy"]
|
[submodule "proxy"]
|
||||||
path = proxy
|
path = proxy
|
||||||
url = https://github.com/theta42/proxy.git
|
url = https://github.com/theta42/proxy.git
|
||||||
|
[submodule "jump-host"]
|
||||||
|
path = jump-host
|
||||||
|
url = https://github.com/theta42/jump-host.git
|
||||||
|
branch = master
|
||||||
|
[submodule "ldap-client"]
|
||||||
|
path = ldap-client
|
||||||
|
url = https://github.com/theta42/ldap-client.git
|
||||||
|
|||||||
+910
-1
@@ -8,8 +8,916 @@ orchestration code; see each submodule's own `CHANGELOG.md`
|
|||||||
[sso-manager-node](https://github.com/theta42/sso-manager-node/blob/master/CHANGELOG.md))
|
[sso-manager-node](https://github.com/theta42/sso-manager-node/blob/master/CHANGELOG.md))
|
||||||
for what changed inside the apps it composes.
|
for what changed inside the apps it composes.
|
||||||
|
|
||||||
|
## [v1.28.0] - 2026-08-01
|
||||||
|
|
||||||
|
OpenBao becomes the central secrets store for the whole stack. Every app now
|
||||||
|
loads its secrets from OpenBao at boot via the new
|
||||||
|
[`@simpleworkjs/bao-conf`](https://simpleworkjs.github.io/bao-conf/) package;
|
||||||
|
end users get personal per-user secret storage through the SSO UI; external
|
||||||
|
apps get scoped `secret/apps/<app>/*` access. `setup.sh` mints the policies
|
||||||
|
and scoped tokens, `bootstrap.js` writes generated creds into OpenBao, and a
|
||||||
|
new `docs/secrets.md` documents the architecture.
|
||||||
|
|
||||||
|
### Changed (theta-env orchestration)
|
||||||
|
- **`setup.sh`** — after the KV-v2 enable, a new idempotent block writes four
|
||||||
|
OpenBao policies (`sso-broker`, `sso-admin`, `proxy`, `jump-host`) via
|
||||||
|
heredocs, a `sso-broker` token role (`allowed_policies_glob` `user-*`/`app-*`,
|
||||||
|
24h period), and mints scoped `SSO_VAULT_TOKEN` / `PROXY_VAULT_TOKEN` /
|
||||||
|
`JUMP_VAULT_TOKEN` (orphan, renewable, reused from `setup.env` if still
|
||||||
|
valid). `seed_app_conf` seeds `secret/{sso-manager,proxy,jump-host}/conf`
|
||||||
|
from the operator-edit `/config/*-secrets.js` files on first run. The
|
||||||
|
bootstrap exec now passes the root `VAULT_ADDR`/`VAULT_TOKEN` for seeding.
|
||||||
|
The root token stays in `setup.env` for maintenance only — it is never passed
|
||||||
|
to a service container. `bash -n` + `shellcheck` clean.
|
||||||
|
- **`docker-compose.yml`** — `sso-manager`/`proxy`/`jump-host` get
|
||||||
|
`VAULT_ADDR=http://openbao:8200` and `VAULT_TOKEN=${SSO|PROXY|JUMP}_VAULT_TOKEN:-`;
|
||||||
|
`proxy`/`jump-host` gain `depends_on: openbao: service_started`. compose
|
||||||
|
config valid.
|
||||||
|
- **`bootstrap/bootstrap.js`** — `baoPut()` writes the generated OAuth client
|
||||||
|
creds to `secret/proxy/conf` and `secret/jump-host/conf` (POST replaces; the
|
||||||
|
full file object), so OpenBao — not the on-disk `/config/*-secrets.js` — is
|
||||||
|
authoritative after first boot. Fail-soft. `node --check` clean.
|
||||||
|
- **`docs/secrets.md`** (new) — the full secrets architecture: load path,
|
||||||
|
policy/token table, the `sso-broker` role, seeding, end-user personal
|
||||||
|
secrets, external-app convention (curl + Node `bao-conf` examples), operator
|
||||||
|
rotation, backups. Linked from the README and the docs nav (`_config.yml`).
|
||||||
|
- **README** — Configuration section rewritten (OpenBao authoritative, link to
|
||||||
|
`docs/secrets.md`); Secrets-backup section adds the `openbao-data` volume.
|
||||||
|
|
||||||
|
### Submodule bumps
|
||||||
|
- `sso-manager-node` → **v1.16.0** (was v1.15.2-era).
|
||||||
|
- `proxy` → **v1.13.1** (was v1.12.1; passes through v1.13.0).
|
||||||
|
- `jump-host` → **v1.14.1** (was v1.11.0-era; passes through v1.14.0).
|
||||||
|
- `ldap-client` unchanged (v1.1.1).
|
||||||
|
|
||||||
|
#### sso-manager-node — [v1.16.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.16.0)
|
||||||
|
|
||||||
|
OpenBao becomes the central secrets store for the theta42 stack, and the SSO
|
||||||
|
Manager becomes its broker. This is the SSO's half of the move: it loads its
|
||||||
|
own secrets from OpenBao, mints scoped tokens for users and external apps,
|
||||||
|
and exposes a fixed, role-scoped personal-secrets UI.
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- **Secrets now load from OpenBao at boot** via
|
||||||
|
[@simpleworkjs/bao-conf](https://simpleworkjs.github.io/bao-conf/), which
|
||||||
|
deep-merges `secret/sso-manager/conf` over the file-loaded config
|
||||||
|
(replacing the old `utils/conf_manager.js`, which did a shallow-per-key
|
||||||
|
merge). `bin/www` runs `bao-conf.init()` after `models.initORM()` and
|
||||||
|
before `listen`. Fail-soft: if OpenBao is unreachable, boot continues from
|
||||||
|
`CONF_SECRETS`. The SSO authenticates with a scoped `VAULT_TOKEN` (policy
|
||||||
|
`sso-broker`), never the root token. The admin **Configuration** UI
|
||||||
|
(`/api/conf`) now writes through `bao-conf.set('sso-manager', …)`.
|
||||||
|
- **`/api/vault` proxy reworked** — the old endpoint was an ungated
|
||||||
|
pass-through that never injected an `X-Vault-Token` (so the UI was both
|
||||||
|
ungated *and* broken). It is now `middleware.auth` → `scopeGuard` → a
|
||||||
|
token-injecting proxy. `scopeGuard` resolves a per-user (`user-<uid>`) or
|
||||||
|
per-admin (`sso-admin`) token via the new `utils/vault_broker.js`
|
||||||
|
(Redis-cached, minted through the `sso-broker` token role) and enforces a
|
||||||
|
path prefix as a second layer on top of the OpenBao policy. The client
|
||||||
|
`auth-token` is stripped; only the server-minted token reaches OpenBao.
|
||||||
|
- **Vault UI reworked and renamed** (`views/vaultwarden.ejs` →
|
||||||
|
`views/vault.ejs`; the `/vault` route is now `middleware.auth`-gated).
|
||||||
|
Non-admin users see only their `secret/users/<uid>/` namespace; admins get
|
||||||
|
free-form path entry across `secret/` plus an **Apps** tab to mint scoped
|
||||||
|
tokens for external apps (`secret/apps/<name>/*`, shown once with copy +
|
||||||
|
`curl` convention).
|
||||||
|
- Bumped package version to track the release tag.
|
||||||
|
|
||||||
|
##### Removed
|
||||||
|
- `nodejs/utils/conf_manager.js` (replaced by `@simpleworkjs/bao-conf`).
|
||||||
|
- `nodejs/views/vaultwarden.ejs` (renamed `vault.ejs`).
|
||||||
|
|
||||||
|
##### Security
|
||||||
|
- **Committed-secrets remediation.** `config/sso-secrets.js` (LDAP bind
|
||||||
|
password, SMTP, `oauth.jwtSecret`) and `nodejs/test_plugins.js` (a
|
||||||
|
hardcoded Proxmox root API token and a UniFi password) were tracked on
|
||||||
|
master. They are now untracked + gitignored (`config/*-secrets.js`), and
|
||||||
|
`test_plugins.js` is deleted; `config/proxy-secrets.js.example` added as a
|
||||||
|
placeholder template. **The secrets remain in git history — rotation at
|
||||||
|
the providers is the real remediation and is the operator's to perform.**
|
||||||
|
OpenBao is now the authoritative store; the local files are seed artifacts
|
||||||
|
only.
|
||||||
|
|
||||||
|
> Note: sso releases v1.12.0–v1.15.2 were tagged from merge PRs without
|
||||||
|
> corresponding `CHANGELOG.md` entries or GitHub releases; v1.16.0 resumes
|
||||||
|
> the changelog.
|
||||||
|
|
||||||
|
#### proxy — [v1.13.1](https://github.com/theta42/proxy/releases/tag/v1.13.1) (via [v1.13.0](https://github.com/theta42/proxy/releases/tag/v1.13.0))
|
||||||
|
|
||||||
|
##### v1.13.1 — Fixed
|
||||||
|
- **Bumped `@simpleworkjs/bao-conf` to 1.0.1** so standalone/no-OpenBao boots
|
||||||
|
don't crash. bao-conf 1.0.0's `init()` threw when `VAULT_TOKEN` was unset,
|
||||||
|
which — combined with `bin/www`'s `.catch(() => process.exit(1))` — made the
|
||||||
|
proxy exit at boot in any deployment without an OpenBao sidecar (standalone
|
||||||
|
Docker, bare metal). 1.0.1 makes `init()` fail-soft on a missing token (warn
|
||||||
|
+ continue from `CONF_SECRETS`), matching the documented contract. The
|
||||||
|
theta-env stack is unaffected (it always sets a scoped `VAULT_TOKEN`).
|
||||||
|
|
||||||
|
##### v1.13.0 — Changed
|
||||||
|
- **Secrets now load from OpenBao at boot** via
|
||||||
|
[@simpleworkjs/bao-conf](https://simpleworkjs.github.io/bao-conf/), which
|
||||||
|
deep-merges `secret/proxy/conf` over the file-loaded config. The proxy
|
||||||
|
authenticates to OpenBao with a scoped `VAULT_TOKEN` (policy `proxy` —
|
||||||
|
read-only on its own path), never the root token. Because the OIDC
|
||||||
|
`clientSecret` is captured at require time inside `createOidcClient` (during
|
||||||
|
`require('../models')`, which `require('../app')` triggers transitively),
|
||||||
|
`bin/www` now defers `require('../app')` until after `bao-conf.init()`
|
||||||
|
resolves. Fail-soft: if OpenBao is unreachable, boot continues from
|
||||||
|
`CONF_SECRETS`. The `config/proxy-secrets.js` file is now an operator-edit
|
||||||
|
seed artifact (gitignored); OpenBao is authoritative.
|
||||||
|
- Bumped package version to track the release tag.
|
||||||
|
|
||||||
|
#### jump-host — [v1.14.1](https://github.com/theta42/jump-host/releases/tag/v1.14.1) (via [v1.14.0](https://github.com/theta42/jump-host/releases/tag/v1.14.0))
|
||||||
|
|
||||||
|
##### v1.14.1 — Fixed
|
||||||
|
- **Bumped `@simpleworkjs/bao-conf` to 1.0.1** so standalone/no-OpenBao boots
|
||||||
|
don't crash. bao-conf 1.0.0's `init()` threw when `VAULT_TOKEN` was unset,
|
||||||
|
which — combined with `bin/www`'s `.catch(() => process.exit(1))` — made the
|
||||||
|
jump host exit at boot in any deployment without an OpenBao sidecar
|
||||||
|
(standalone Docker, bare metal). 1.0.1 makes `init()` fail-soft on a missing
|
||||||
|
token (warn + continue from `CONF_SECRETS`), matching the documented
|
||||||
|
contract. The theta-env stack is unaffected (it always sets a scoped
|
||||||
|
`VAULT_TOKEN`).
|
||||||
|
|
||||||
|
##### v1.14.0 — Changed
|
||||||
|
- **Secrets now load from OpenBao at boot** via
|
||||||
|
[@simpleworkjs/bao-conf](https://simpleworkjs.github.io/bao-conf/), which
|
||||||
|
deep-merges `secret/jump-host/conf` over the file-loaded config. The jump
|
||||||
|
host authenticates to OpenBao with a scoped `VAULT_TOKEN` (policy
|
||||||
|
`jump-host` — read-only on its own path), never the root token. Because the
|
||||||
|
OIDC `clientSecret` is captured at require time inside `createOidcClient`
|
||||||
|
(during `require('../models')`), `bin/www` now runs `bao-conf.init()`
|
||||||
|
**before** `require('../models')`. Fail-soft: if OpenBao is unreachable,
|
||||||
|
boot continues from `CONF_SECRETS`. The `config/jump-secrets.js` file is now
|
||||||
|
an operator-edit seed artifact (gitignored); OpenBao is authoritative.
|
||||||
|
- Bumped package version to track the release tag.
|
||||||
|
|
||||||
|
## [v1.27.2] - 2026-08-01
|
||||||
|
|
||||||
|
- Updated `proxy` to v1.12.1 (Dependabot security/maintenance bumps).
|
||||||
|
|
||||||
|
#### proxy — [v1.12.1](https://github.com/theta42/proxy/releases/tag/v1.12.1)
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- Bumped `body-parser` 2.2.2 → 2.3.0 (Dependabot #175).
|
||||||
|
- Bumped `ejs` and `brace-expansion` (Dependabot #179, security maintenance).
|
||||||
|
|
||||||
|
## [v1.27.1] - 2026-08-01
|
||||||
|
|
||||||
|
- Added automated integration tests for the environment (`test-integration.sh`).
|
||||||
|
- Updated `sso-manager-node` to v1.15.2 (Directory UI tab styling fixes and Vault documentation).
|
||||||
|
|
||||||
|
## [v1.27.0] - 2026-08-01
|
||||||
|
|
||||||
|
- Updated `sso-manager-node` to v1.15.0 (UI/UX improvements and structured conf page).
|
||||||
|
|
||||||
|
## [v1.26.0] - 2026-08-01
|
||||||
|
|
||||||
|
- Made OpenBao production-ready by using a persistent file backend, enabling `IPC_LOCK`, and dynamically generating a robust config file.
|
||||||
|
- Automated OpenBao initialization, unsealing, and secrets seeding via `setup.sh`.
|
||||||
|
|
||||||
|
## [v1.25.0] - 2026-08-01
|
||||||
|
|
||||||
|
- Added OpenBao (Vault) container for secrets management and native UI proxying.
|
||||||
|
- Updated `sso-manager-node` to v1.14.0 (Discovery and Vault integration).
|
||||||
|
- Updated `proxy` to v1.12.0.
|
||||||
|
|
||||||
## [Unreleased]
|
## [Unreleased]
|
||||||
|
|
||||||
|
## [1.23.0] - 2026-07-31
|
||||||
|
|
||||||
|
### Submodules bumped
|
||||||
|
- jump-host `v1.12.0` -> [`v1.13.0`](https://github.com/theta42/jump-host/releases/tag/v1.13.0)
|
||||||
|
- proxy `v1.10.0` -> [`v1.11.0`](https://github.com/theta42/proxy/releases/tag/v1.11.0)
|
||||||
|
- sso-manager-node `v1.12.0` -> [`v1.13.0`](https://github.com/theta42/sso-manager-node/releases/tag/v1.13.0)
|
||||||
|
|
||||||
|
#### jump-host — [v1.13.0](https://github.com/theta42/jump-host/releases/tag/v1.13.0)
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- **Title changed to "SSO Manager"** — the jump-host web UI now presents itself as "SSO Manager" in the navbar and page title, matching its role as the unified access portal for both services and hosts.
|
||||||
|
|
||||||
|
#### sso-manager-node — [v1.13.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.13.0)
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- **Directory page cleaned up** — removed the parent badge and slug display from the directory table; resource names now align with the badges above for a cleaner, more compact layout.
|
||||||
|
- **Users list SSH key column fixed** — users with multiple SSH keys no longer show multiple checkmarks; the column now shows a single checkmark indicating "has key" regardless of key count.
|
||||||
|
|
||||||
|
#### proxy — [v1.11.0](https://github.com/theta42/proxy/releases/tag/v1.11.0)
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- **Permissions, Users, and Groups pages converted to table layouts** — card grids replaced with striped tables for better scanability and alignment. Users page adds per-field validation error display alongside the summary message.
|
||||||
|
- **Groups page auto-refreshes** — adding or removing a group now triggers an explicit reload, ensuring the list stays in sync without manual refresh.
|
||||||
|
|
||||||
|
## [1.22.0] - 2026-07-31
|
||||||
|
|
||||||
|
### Submodules bumped
|
||||||
|
- jump-host `v1.11.0` -> [`v1.12.0`](https://github.com/theta42/jump-host/releases/tag/v1.12.0)
|
||||||
|
- proxy `v1.9.0` -> [`v1.10.0`](https://github.com/theta42/proxy/releases/tag/v1.10.0)
|
||||||
|
- sso-manager-node `v1.11.0` -> [`v1.12.0`](https://github.com/theta42/sso-manager-node/releases/tag/v1.12.0)
|
||||||
|
|
||||||
|
#### jump-host — [v1.12.0](https://github.com/theta42/jump-host/releases/tag/v1.12.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- **TUI host picker with colors**: ANSI-colored terminal UI with box-drawing header, cyan/magenta/green title treatment, per-row coloring (cyan hostnames, blue IPs), environment badges (red PROD / dim DEV), green inverse selection highlight with "◄ SELECTED ►" indicator, yellow filter text, and a footer separator with quick-select hint.
|
||||||
|
|
||||||
|
#### sso-manager-node — [v1.12.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.12.0)
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- **Catalog page (`/`) redesigned**: Removed the portal banner; "My Access" section now has tabs separating Services and Hosts; icons support both Font Awesome classes and image URLs (http/https).
|
||||||
|
- **Profile page redesigned as a single card with tabs**: Password reset is now a modal button; "My groups", "My Services", "Security & Usage Stats", and "Members of X's group" are now tabs on the main profile card instead of separate cards; metrics display fixed to properly load and show service usage data.
|
||||||
|
|
||||||
|
#### proxy — [v1.10.0](https://github.com/theta42/proxy/releases/tag/v1.10.0)
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- **Permissions page**: Converted from card grid to table/list layout with columns: Subject, Scope, Domain, Role, Actions.
|
||||||
|
- **Users page**: Converted from card grid to table/list layout; form validation now shows both a summary message AND per-field error messages with visual highlighting.
|
||||||
|
- **Groups page**: Added automatic refresh after adding/deleting groups to ensure new entries appear immediately.
|
||||||
|
|
||||||
|
## [1.21.0] - 2026-07-31
|
||||||
|
|
||||||
|
### Submodules bumped
|
||||||
|
- ldap-client `v1.1.0` -> [`v1.1.1`](https://github.com/theta42/ldap-client/releases/tag/v1.1.1)
|
||||||
|
- sso-manager-node `v1.10.0` -> [`v1.11.0`](https://github.com/theta42/sso-manager-node/releases/tag/v1.11.0)
|
||||||
|
|
||||||
|
> **Operational note — the SSO image now builds slapd from source.** OpenLDAP's
|
||||||
|
> `nestgroup` overlay (nested groups) exists only on master; no 2.6.x release
|
||||||
|
> ships it. `Dockerfile.openldap` therefore compiles OpenLDAP from a **pinned**
|
||||||
|
> commit, which makes the SSO image slower to build and pulls `pw-sha2` from
|
||||||
|
> contrib. Two consequences worth knowing:
|
||||||
|
>
|
||||||
|
> - Master ships **LMDB 1.0.0**, whose on-disk format is mutually unreadable
|
||||||
|
> with the 0.9.x in 2.6.x (`MDB_INVALID: File is not an LMDB file`). Moving an
|
||||||
|
> existing `/var/lib/ldap` onto this image is a `slapcat` -> `slapadd` reload,
|
||||||
|
> not a restart.
|
||||||
|
> - There is a `TODO` to drop the whole from-source stage once `nestgroup` ships
|
||||||
|
> in a release. The entrypoint already probes for `nestgroup.so` and the app
|
||||||
|
> keys off `app_ldap__nestedGroupsServerSide`, so that swap needs no other
|
||||||
|
> changes.
|
||||||
|
|
||||||
|
#### sso-manager-node — [v1.11.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.11.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- **End-user catalog at `/`** — the first ungated nav item; previously every nav entry was admin-only and a normal user had no signposted destination. Search/filter, per-kind icons, and a *how to reach it* block per card: the URL for a service, the SSH invocation for a host (using the jump-host `uid_-_slug@host` grammar when `directory.jumpHost` is set).
|
||||||
|
- **Self-service access requests** — `/api/access-requests` (create, list own, list decidable, approve, deny, withdraw) with approve/deny queues on the catalog. Approving performs the LDAP group add, so LDAP stays the access-control truth. Requests target a resource's `_access` group, never `_admin`. Replaces the "coming soon" stub.
|
||||||
|
- **Admin access visibility** — an Access column on the directory table (member/group counts, flagging links whose LDAP group was deleted) and a "what can this user reach" lookup, the reverse question that previously had no UI at all.
|
||||||
|
- **Nested LDAP groups.** `groupOfNames.member` already accepts a group DN, so nesting needs no schema — what it needs is resolution, which no released OpenLDAP performs. Server-side via the pinned-master `nestgroup` overlay; client-side the app computes the closure itself (cycle-detected, depth-capped) against any other server. `PUT`/`DELETE /api/group/:group/nested/:child`, `GET /api/group/:group/effective`, and a **Nested** tab on each group card.
|
||||||
|
- **`app_super_admin` is now seeded** (it never was) and nested into `app_sso_admin` / `app_sso_invite` / `app_sso_oauth_admin`, so the privilege is real LDAP membership visible to SSSD and sudo rather than a special case in app code. Resource creation nests `app_super_admin` -> `<slug>_admin` and `<slug>_admin` -> `<slug>_access`.
|
||||||
|
- Resource metadata `icon` and `tagline`, collected on the admin form with a live icon preview.
|
||||||
|
|
||||||
|
##### Fixed
|
||||||
|
- **`GET /api/discovery/me` returned only `isPublic` resources for every human caller** — it read `req.user.groups`, which does not exist (`req.user` carries `memberOf`), so the empty list failed open. "My Services" was blank for everyone, and `isDirectoryAdmin()` was false even for real directory admins.
|
||||||
|
- **The portal's "Discover More Services" was dead for every non-admin** — it called the admin-gated endpoint and swallowed the 403 into an empty array.
|
||||||
|
- **Services reported no address** — `/me` had reimplemented `getMyAccess` without its parent-walking resolution, so a service reached at its host's IP resolved to nothing.
|
||||||
|
- `GET /api/user/me` derived `isAdmin` from `memberOf`, which is only transitive with `nestgroup`; against a stock server an admin holding their group via nesting lost the entire admin UI while still passing every server-side check.
|
||||||
|
- `utils/permission.js`'s `byGroup` saw only direct membership.
|
||||||
|
- Adding an existing group member, and removing a group's last member, both returned bare 500s; now 409s that explain themselves.
|
||||||
|
- `DELETE /api/directory-admin/resources/:id` deleted the resource before its edges and group links, orphaning rows on a mid-way failure.
|
||||||
|
- `/api/directory-admin/audit-logs` shelled out to `tail` via `execSync`; replaced with a bounded async read.
|
||||||
|
- Broken `api.html` link in the published docs.
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- `@simpleworkjs/directory-schema` -> `^1.1.0`, declaring ten metadata keys the admin form always wrote but the schema never listed. Undeclared keys are dropped for non-admin callers — which blanked the portal's `OS:` field, hid every service's port, and left machine tokens unable to read the port mapping the firewall consumer exists to render.
|
||||||
|
|
||||||
|
#### ldap-client — [v1.1.1](https://github.com/theta42/ldap-client/releases/tag/v1.1.1)
|
||||||
|
|
||||||
|
##### Fixed
|
||||||
|
- Sets `ldap_group_nesting_level = 5` so SSSD walks nested groups itself when pointed at a server without `nestgroup`. Against the SSO's bundled slapd the existing `memberof=` access filter is already transitive, so SSH login inherits nesting for free. The explicit `app_super_admin` clause is kept, to keep super-admin login working against a directory predating the new nesting.
|
||||||
|
|
||||||
|
|
||||||
|
## [1.20.0] - 2026-07-30
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **`setup.sh` persists `SSO_GIT_COMMIT`/`PROXY_GIT_COMMIT`/`JUMP_GIT_COMMIT` into `./.env`** (new `env_upsert` helper), which `docker compose` auto-loads on every future invocation in this directory. Previously these were only `export`ed for the current shell, so an ad-hoc `docker compose up --build <service>` run later (outside a full `setup.sh` run) would build with an empty `GIT_COMMIT` arg — and since each submodule's checked-out `.git` is a pointer file, not a real repo, the in-container git fallback can't resolve it either, so the image silently baked "unknown" as its commit hash. `.gitignore`'s `.env` comment updated to describe this (it was previously labeled "legacy, no longer used").
|
||||||
|
|
||||||
|
### Submodules bumped
|
||||||
|
- jump-host `v1.10.2` -> [`v1.11.0`](https://github.com/theta42/jump-host/releases/tag/v1.11.0)
|
||||||
|
- ldap-client `v1.0.0` -> [`v1.1.0`](https://github.com/theta42/ldap-client/releases/tag/v1.1.0)
|
||||||
|
- proxy `v1.8.0` -> [`v1.9.0`](https://github.com/theta42/proxy/releases/tag/v1.9.0)
|
||||||
|
- sso-manager-node `v1.9.0` -> [`v1.10.0`](https://github.com/theta42/sso-manager-node/releases/tag/v1.10.0)
|
||||||
|
|
||||||
|
#### sso-manager-node — [v1.10.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.10.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- `app_super_admin` cross-app group: members are full admins here regardless of `app_sso_admin` membership. The same group is now also recognized by proxy and jump-host, and by `ldap-client`'s SSSD access filter (SSH login on every host).
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- Renamed the Executive page to Overview (route, view, `/api/metrics/overview`, nav label, docs). `/executive` kept as a 301 redirect.
|
||||||
|
|
||||||
|
#### proxy — [v1.9.0](https://github.com/theta42/proxy/releases/tag/v1.9.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- `app_super_admin` cross-app group recognized as a global admin (`conf.auth.adminGroups`).
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- Users and Permissions pages: the always-visible sidebar "Add" forms are now an "Add User"/"Add Permission" button that opens an `app.modal` dialog, matching the hosts.ejs convention.
|
||||||
|
- Let's Encrypt ACME account key now defaults to the already-persisted `/data` volume instead of a CWD-relative path (`./le_key.cert` -> `/app/le_key.cert` in the container), which was lost on every image rebuild.
|
||||||
|
|
||||||
|
#### jump-host — [v1.11.0](https://github.com/theta42/jump-host/releases/tag/v1.11.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- `app_super_admin` (cross-app) and `app_jump_admin` groups: super admins are full admins here same as `app_sso_admin`; jump admins get audit page/data access without other admin rights. The Audit page/API is now actually admin-gated server-side (previously the page shell rendered for any logged-in user, only its data was gated).
|
||||||
|
- Host list adds Last connection/Last failed connection columns and highlights rows green (a session is live right now) or yellow (the most recent attempt failed), backed by new per-host last-success/last-fail timestamps.
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- Dashboard's stat boxes and Top hosts/Top users cards moved to the Audit page. "All hosts" renamed to "My hosts".
|
||||||
|
|
||||||
|
#### ldap-client — [v1.1.0](https://github.com/theta42/ldap-client/releases/tag/v1.1.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- `app_super_admin` cross-app group now grants SSH login access to every host (`ldap_access_filter` + `ldap_access_groups`), matching the same group's admin rights in sso-manager-node, proxy, and jump-host. Sudo is not yet extended to super admins (`ldap_sudo_search_filter` remains non-functional on this SSSD version — pre-existing, documented gap).
|
||||||
|
|
||||||
|
## [1.19.0] - 2026-07-30
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **New `ldap-client` submodule + `ldap-test-host` service** (`jump-host` compose profile): a real SSSD + AuthorizedKeysCommand LDAP-joined downstream host for testing jump-host's actual key-injection -> upstream-connect flow end-to-end against this stack's own local LDAP, instead of a container with a manually-dropped public key in `authorized_keys`. Verified live (SSH CLI and WinSCP) through jump-host's `uid_-_target` grammar.
|
||||||
|
|
||||||
|
#### ldap-client — [v1.0.0](https://github.com/theta42/ldap-client/releases/tag/v1.0.0) (first tagged release)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- Docker test fixture (`Dockerfile` + `entrypoint.sh`): Ubuntu 22.04 + sssd + sshd, no systemd required.
|
||||||
|
|
||||||
|
##### Fixed
|
||||||
|
Building that fixture surfaced three real bugs that would break login on any deployment, not just the test fixture:
|
||||||
|
- `sssd.conf.mo` used `ldap_bind_dn`/`ldap_bind_pw`, which aren't real SSSD options — corrected to `ldap_default_bind_dn` / `ldap_default_authtok(_type)`.
|
||||||
|
- `sssd.conf.mo` had no explicit `services =` list, so SSSD started only its backend, never the nss/pam responders — `getent passwd <ldap-user>` silently failed even with the domain reachable.
|
||||||
|
- `ldap-ssh-key.sh`'s `memberof` filter was missing the `cn=` prefix on the group name, so the AuthorizedKeysCommand script always returned zero keys for a correctly-provisioned user — no error, just silently nothing.
|
||||||
|
|
||||||
|
#### sso-manager-node — [v1.9.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.9.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- Directory modal's Associated LDAP Groups tab now supports full membership management: view, add, and remove members/owners of each associated group directly from the tab.
|
||||||
|
- `app.util.revealItem()` (shared `app-base.js`): scrolls a just-added/-edited element into view and flashes its background.
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- Groups page's search/sort bar is now sticky while scrolling.
|
||||||
|
- Directory table: Kind/Name/Env/Host merged into a single "Resource" column.
|
||||||
|
|
||||||
|
#### proxy — [v1.8.0](https://github.com/theta42/proxy/releases/tag/v1.8.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- Users backed by SSO/OIDC login are now marked "External (SSO)" and read-only (password-change hidden client-side, `PUT /password/:username` rejects with 403 server-side). Redis user-backend only.
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- All pages now wrap their content in a standard-width container, matching sso-manager-node instead of rendering full-bleed.
|
||||||
|
- Users and Permissions pages converted from bare `<table>`s to the card-grid convention already used on the Groups page.
|
||||||
|
|
||||||
|
#### jump-host — [v1.10.2](https://github.com/theta42/jump-host/releases/tag/v1.10.2)
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- Dashboard, Sessions, and Audit pages now match sso-manager-node/proxy's page width.
|
||||||
|
- Audit's nav entry is now admin-gated (`groups: ['admin']`).
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.9.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.9.0)
|
||||||
|
- proxy -> [v1.8.0](https://github.com/theta42/proxy/releases/tag/v1.8.0)
|
||||||
|
- jump-host -> [v1.10.2](https://github.com/theta42/jump-host/releases/tag/v1.10.2)
|
||||||
|
- ldap-client -> [v1.0.0](https://github.com/theta42/ldap-client/releases/tag/v1.0.0) (new submodule)
|
||||||
|
|
||||||
|
## [1.18.0] - 2026-07-28
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
Cross-app API-token self-service UI unification: all 3 apps now share the
|
||||||
|
same card-grid list, "+ New Token" modal-based create flow, `app.modal`-based
|
||||||
|
secret reveal, and Edit modal (with real created-by/on audit metadata).
|
||||||
|
|
||||||
|
#### sso-manager-node — [v1.8.2](https://github.com/theta42/sso-manager-node/releases/tag/v1.8.2), [v1.8.3](https://github.com/theta42/sso-manager-node/releases/tag/v1.8.3)
|
||||||
|
|
||||||
|
**v1.8.2**
|
||||||
|
|
||||||
|
##### Fixed
|
||||||
|
- **Creating a new OAuth integration didn't reliably show the "save this client secret now" reveal modal** — `saveResource()` called `app.modal.close()` immediately before conditionally showing the secret via `app.modal.open()`. `app.modal` is a singleton, and `close()` immediately followed by `open()` collides with Bootstrap's hide-transition guard. An intervening `await loadResources()` made this race unlikely to lose in practice, but not guaranteed to — found while fixing the same, guaranteed-to-lose bug in jump-host and proxy's API-token create flows.
|
||||||
|
|
||||||
|
**v1.8.3**
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- **`profile.ejs`'s self-service API-token UI unified onto `app.modal`**, matching the pattern already shipped this round in `directory.ejs`, proxy, and jump-host: the static `#secretModal`/`#editModal` elements are retired in favor of the shared `app.modal` singleton, the always-visible inline create-form card becomes a "+ New Token" button + modal, and badge classes switch from `bg-*` to `text-bg-*`.
|
||||||
|
- Checkmark-flash copy feedback (silently broken by FontAwesome's `<i>`→`<svg>` replacement) replaced with toast-based `copyFieldValue`, matching proxy and jump-host.
|
||||||
|
|
||||||
|
#### proxy — [v1.7.0](https://github.com/theta42/proxy/releases/tag/v1.7.0)
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- **API tokens: "+ New Token" modal button (replacing the always-visible inline create-form card) and a new Edit modal** — continues the cross-app API-token UI unification started in jump-host. The Edit modal's footer shows real created-by/on data; the `PUT /api-token/:id` route already fully supported editing, so no backend change was needed.
|
||||||
|
|
||||||
|
##### Fixed
|
||||||
|
- **Creating an API token didn't show the "save this secret now" reveal modal** — the create flow called `app.modal.close()` immediately before `app.modal.open()` (to show the secret) in the same tick; since `app.modal` is a singleton, that collided with Bootstrap's hide-transition guard and the reveal modal silently never appeared.
|
||||||
|
|
||||||
|
#### jump-host — [v1.10.0](https://github.com/theta42/jump-host/releases/tag/v1.10.0), [v1.10.1](https://github.com/theta42/jump-host/releases/tag/v1.10.1)
|
||||||
|
|
||||||
|
**v1.10.0**
|
||||||
|
|
||||||
|
##### Added
|
||||||
|
- **API-token UI unified with sso-manager-node/proxy**: card grid replacing the bare table, a new Edit modal (footer shows real created-by/on data), and a Description field on both the create and edit flows — the model and API already fully supported all of this, it just wasn't exposed anywhere in the dashboard.
|
||||||
|
|
||||||
|
##### Changed
|
||||||
|
- `@simpleworkjs/frontend` bumped to `^0.2.6` (this app was still on `^0.2.5`).
|
||||||
|
|
||||||
|
**v1.10.1**
|
||||||
|
|
||||||
|
##### Fixed
|
||||||
|
- **The API-token reveal modal silently didn't show after creating a token** — `submitApiToken()` called `app.modal.close()` immediately before `showToken()`'s `app.modal.open()` in the same tick, colliding with Bootstrap's hide-transition guard on the singleton modal. Same root cause as the OAuth-secret-reveal race fixed in sso-manager-node (v1.8.2) and the create-token race fixed in proxy (v1.7.0).
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.8.3](https://github.com/theta42/sso-manager-node/releases/tag/v1.8.3)
|
||||||
|
- proxy -> [v1.7.0](https://github.com/theta42/proxy/releases/tag/v1.7.0)
|
||||||
|
- jump-host -> [v1.10.1](https://github.com/theta42/jump-host/releases/tag/v1.10.1)
|
||||||
|
|
||||||
|
## [1.17.0] - 2026-07-28
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **proxy's host modal now has a footer (created/updated-by/on metadata) and a linkable `/hosts/{host}` URL**, migrated onto the same shared `app.modal` component as sso-manager-node's resource modal — continuing the entity-modal standardization across the stack.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **proxy: the Let's-Encrypt challenge-type/wildcard-matching visibility logic could stop reacting to the hostname field after the first Add/Edit host**, and **the SSO allow-list autocomplete could go empty starting on the second Add/Edit** — both were DOM-rebuild timing bugs in the same class as the resource-modal fixes already shipped.
|
||||||
|
- **sso-manager-node: the resource modal's "Associated LDAP Groups" autocomplete went empty after the first Add/Edit** — same DOM-rebuild timing bug, now fixed.
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.8.1](https://github.com/theta42/sso-manager-node/releases/tag/v1.8.1)
|
||||||
|
- proxy -> [v1.6.0](https://github.com/theta42/proxy/releases/tag/v1.6.0)
|
||||||
|
|
||||||
|
## [1.16.0] - 2026-07-28
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **"Quick Jump" copy-to-clipboard section on the jump-host dashboard** — one-click-copy SSH commands (interactive-picker mode, plus a per-host `uid_-_target` grammar-mode command) instead of having to remember/reconstruct the format by hand.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **jump-host audit records for a failed downstream connection only ever said `upstream-unreachable`**, with no way to tell a network-layer failure from an auth failure — the real error (ECONNREFUSED, ETIMEDOUT, an ssh2 auth-failure message, etc.) is now captured and shown as a tooltip on the audit table's fail badge.
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- jump-host -> [v1.9.0](https://github.com/theta42/jump-host/releases/tag/v1.9.0)
|
||||||
|
|
||||||
|
## [1.15.0] - 2026-07-28
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **sso-manager's Directory data (every site/host/service/oauth-client resource and their relationships/LDAP-group associations) had no persistent volume** — `@simpleworkjs/orm` fell back to `./config/inventory.sqlite` (relative to the app's `/app` cwd) whenever `conf.orm` wasn't set, which sits in the container's ephemeral writable layer, not any mounted volume. Every container recreate (`docker compose up --build`, `down`/`up`, an image rebuild) silently wiped the entire Directory Management page. `setup.sh`'s generated `sso-secrets.js` (and the example template) now set `orm: { dialect: 'sqlite', storage: '/data/inventory.sqlite' }`, co-locating it with the already-persisted `sso-data` volume (where Redis lives). **Existing deployments**: this repo doesn't rewrite an operator's existing `config/sso-secrets.js` (re-running `setup.sh` leaves it untouched by design) — add the `orm` block above manually, and copy the container's current `/app/config/inventory.sqlite` to `/data/inventory.sqlite` *before* recreating the container, or the existing Directory data will be lost on the next recreate instead of migrated.
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.8.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.8.0)
|
||||||
|
|
||||||
|
## [1.14.0] - 2026-07-28
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **jump-host's Redis had zero persistence** (`--save '' --appendonly no`, no data-dir volume) — every container rebuild/recreation (including a `setup.sh` re-run) silently wiped all sessions, in-flight OAuth logins, and any admin-created API token. This is the root cause of the reported "re-running setup.sh breaks OAuth with jump" — the jump-host container gets recreated, and any token or in-flight login vanished with it, while proxy was unaffected because its Redis was already persisted. Now jump-host's Redis persists (AOF + periodic RDB) to `/data`, mounted as a new named volume, `jump-redis-data`. Verified live: minted a PAT, force-recreated the container, confirmed the same PAT still authenticated afterward.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- `docker-compose.yml`: added the `jump-redis-data` volume, mounted at `/data` on the `jump-host` service.
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- jump-host -> [v1.8.1](https://github.com/theta42/jump-host/releases/tag/v1.8.1)
|
||||||
|
|
||||||
|
## [1.13.0] - 2026-07-28
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
Found via feedback on a fresh install:
|
||||||
|
- **jump-host's OAuth client had no parent in the Directory.** `seedDirectory()` only ever linked the proxy's OAuth client; jump-host's own (minted by `provisionJumpHost`) was created but never passed through, so it never got a `ResourceEdge`. Existing deployments self-heal on the next `setup.sh` run.
|
||||||
|
- **TUI-mode SSH connections (bare `ssh user@host`) could drop** with "PTY allocation request failed" / "shell request failed" — a session-listener race in jump-host, same class of bug `runGrammar` already had a fix for.
|
||||||
|
- **Every form submit briefly showed literal HTML** instead of a loading spinner, across all three apps.
|
||||||
|
- **`POST /api/user/` and `PUT /api/user/password` had no success message** — a green notification with nothing in it right after adding a user.
|
||||||
|
- **The login page gave no explanation for why the user landed there** when redirected mid-OAuth-flow.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Directory: tree view is now the only view; clicking a resource's name opens its detail modal.**
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.7.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.7.0)
|
||||||
|
- proxy -> [v1.5.3](https://github.com/theta42/proxy/releases/tag/v1.5.3)
|
||||||
|
- jump-host -> [v1.8.0](https://github.com/theta42/jump-host/releases/tag/v1.8.0)
|
||||||
|
|
||||||
|
No `setup.sh` or compose change. Also confirmed (no fix needed): the Let's Encrypt ACME account key persists correctly across container rebuilds — `lua-resty-auto-ssl`'s Redis storage adapter writes through the bundled Redis, which is started with `--appendonly yes` into `/data`, mapped to the persisted `proxy-data` volume. Only an explicit `docker-compose down -v` / volume removal would lose it (which is also what's required, and expected, on a domain change).
|
||||||
|
|
||||||
|
## [1.12.0] - 2026-07-28
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.6.3](https://github.com/theta42/sso-manager-node/releases/tag/v1.6.3) — fixes the root cause of a real "lost user" report: `routes/group.js` never invalidated the User cache on membership changes, so an account added to the `app_sso_service_account` marker group (which hides accounts from the Users page's People tab) could look like it had vanished for up to 5 minutes — and, separately, could be added to that group with no warning at all. Both fixed; see the linked release for detail.
|
||||||
|
|
||||||
|
No `setup.sh` or compose change.
|
||||||
|
|
||||||
|
## [1.11.0] - 2026-07-28
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **`test/check_jump_ldap_tls.js`**, wired into the `Lint` workflow: a static consistency check on the jump-secrets.js template `bootstrap.js` generates, so the `ldap://` + `tlsOptions` mistake that broke every SSH login in 1.10.0 fails CI before it ever reaches a real deployment again.
|
||||||
|
- **A static "no native `alert()`/`confirm()`/`prompt()`" check** is now part of all three apps' own test suites (they block all further browser events on the page — see 1.9.0/1.10.0's release notes).
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.6.2](https://github.com/theta42/sso-manager-node/releases/tag/v1.6.2) — fixes `DELETE /api/oauth/client/:id` (`client.remove is not a function`, a genuine 500 masked by tests that never checked the response status), plus the regression test above.
|
||||||
|
- proxy -> [v1.5.2](https://github.com/theta42/proxy/releases/tag/v1.5.2) — the regression test above.
|
||||||
|
- jump-host -> [v1.7.1](https://github.com/theta42/jump-host/releases/tag/v1.7.1) — the regression test above.
|
||||||
|
|
||||||
|
No `setup.sh` or compose change.
|
||||||
|
|
||||||
|
## [1.10.0] - 2026-07-27
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **`bootstrap/bootstrap.js`'s jump-secrets.js template now points jump-host at `ldaps://sso-manager:636`**, not `ldap://sso-manager:389`. The plain-port URL combined with jump-host's `tlsOptions` made `ldapts` attempt implicit TLS against a port serving plaintext LDAP — slapd dropped every connection before any LDAP message parsed, so SSH password login failed for every account, with any password, indistinguishable from a wrong credential. Root-caused by standing up a local jump-host, editing its config, and calling `getUser`/`checkPassword` directly inside the container. **Existing deployments must edit `./config/jump-secrets.js` themselves** (this template only affects fresh bootstraps) — see theta42/theta-env#99. Companion defensive fix: [simpleworkjs/ldap v1.0.2](https://github.com/simpleworkjs/ldap/releases/tag/v1.0.2) now rejects this `ldap://` + `tlsOptions` combination outright.
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- jump-host -> [v1.7.0](https://github.com/theta42/jump-host/releases/tag/v1.7.0) — adds self-service API tokens (create/list/rotate/revoke from its dashboard); jump-host previously had none.
|
||||||
|
|
||||||
|
No `setup.sh` or compose change.
|
||||||
|
|
||||||
|
## [1.9.0] - 2026-07-27
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.6.1](https://github.com/theta42/sso-manager-node/releases/tag/v1.6.1)
|
||||||
|
- proxy -> [v1.5.1](https://github.com/theta42/proxy/releases/tag/v1.5.1)
|
||||||
|
|
||||||
|
Both apps had every native `alert()`/`confirm()` call removed, replaced by
|
||||||
|
`@simpleworkjs/frontend`'s `app.messages.action`/`confirm`/`toast` (the
|
||||||
|
same modules adopted in [1.8.0](#180---2026-07-27)). This was found live,
|
||||||
|
mid browser-verification of that release: clicking sso-manager-node
|
||||||
|
directory.ejs's "Rotate Client Secret" triggered a native `confirm()`,
|
||||||
|
which blocks all further browser events on the page — a real hazard for
|
||||||
|
anyone driving the app with browser automation, not just a cosmetic
|
||||||
|
inconsistency. sso-manager-node also dropped `app.user.remove`/
|
||||||
|
`app.oauthClient.remove` from `public/js/app.js` (dead code with a native
|
||||||
|
`confirm()` guard and zero callers).
|
||||||
|
|
||||||
|
No `setup.sh`, compose, or config change.
|
||||||
|
|
||||||
|
## [1.8.0] - 2026-07-27
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.6.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.6.0)
|
||||||
|
- proxy -> [v1.5.0](https://github.com/theta42/proxy/releases/tag/v1.5.0)
|
||||||
|
- jump-host -> [v1.6.0](https://github.com/theta42/jump-host/releases/tag/v1.6.0)
|
||||||
|
|
||||||
|
All three apps adopt the newly published `@simpleworkjs/frontend` package's
|
||||||
|
`app.messages`, `app.modal`, and `app.validate` modules, replacing the
|
||||||
|
vendored `app.util.actionMessage`/`actionConfirm`/`alert` in
|
||||||
|
`public/lib/js/app-base.js` (byte-identical across all three apps) and the
|
||||||
|
vendored `public/lib/js/val.js` (byte-identical in sso-manager-node and
|
||||||
|
jump-host, and the same engine plus proxy-only DNS/hostname rules in proxy).
|
||||||
|
Message content is now HTML-escaped — the ad hoc `app.util.alert()` this
|
||||||
|
replaces had none — and `app.messages.action` falls back to a page-wide
|
||||||
|
toast when there's no inline `.actionMessage` target on the page. proxy's
|
||||||
|
`host`/`target`/`hostname` wildcard-DNS validation rules (mirroring
|
||||||
|
`utils/hostname_validate.js`) move to its own `public/js/app.js`, registered
|
||||||
|
via `$.validateSettings`, since they're proxy-specific and don't belong in
|
||||||
|
the shared package's generic rule set (`eq`/`user`/`password`/`ip`).
|
||||||
|
jump-host doesn't currently use any `[validate]` attributes, so its `val.js`
|
||||||
|
swap is dedup/future-proofing rather than a behavior change.
|
||||||
|
|
||||||
|
`app.api`/`app.auth`/`app.pubsub`/`app.socket` in each app's `app-base.js`
|
||||||
|
are untouched: they're app-specific (a dual-mode callback/promise API with
|
||||||
|
`auth-token` header injection) and not something the frontend package's
|
||||||
|
generic `app.js` provides, so it isn't loaded.
|
||||||
|
|
||||||
|
No `setup.sh`, compose, or config change.
|
||||||
|
|
||||||
|
## [1.7.0] - 2026-07-27
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.5.1](https://github.com/theta42/sso-manager-node/releases/tag/v1.5.1)
|
||||||
|
- jump-host -> [v1.5.0](https://github.com/theta42/jump-host/releases/tag/v1.5.0)
|
||||||
|
|
||||||
|
Two production bugs fixed: `PUT /api/user/:uid` 500'd with an LDAP
|
||||||
|
`ObjectClassViolationError` when setting `sshPublicKey` on any account
|
||||||
|
predating the `ldapPublicKey` objectClass (notably the bootstrap admin) —
|
||||||
|
and the exact same bug, in the shared `@simpleworkjs/ldap` package's
|
||||||
|
`addSshKey`, was silently aborting SSH connections at jump-host's
|
||||||
|
key-injection step for the same class of accounts. Both are fixed by
|
||||||
|
ensuring the objectClass is present before writing the attribute. Also
|
||||||
|
fixed: the Directory's "add resource" modal left the parent-Service
|
||||||
|
dropdown blank when adding an OAuth Integration.
|
||||||
|
|
||||||
|
Jump-host's web dashboard also gained a "Hosts you can reach" list
|
||||||
|
(admins see "All hosts") — previously it only showed usage metrics with
|
||||||
|
no way to see your actual access from the browser.
|
||||||
|
|
||||||
|
No `setup.sh`, compose, or config change.
|
||||||
|
|
||||||
|
## [1.6.0] - 2026-07-26
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- jump-host -> [v1.4.0](https://github.com/theta42/jump-host/releases/tag/v1.4.0)
|
||||||
|
|
||||||
|
Jump-host gains **standalone mode**: it can now run with no LDAP directory and
|
||||||
|
no SSO Manager at all, storing users and hosts itself via
|
||||||
|
`@simpleworkjs/orm` (Sequelize; SQLite by default, any Sequelize-supported
|
||||||
|
dialect). This is an app-internal capability, opt-in via
|
||||||
|
`standalone.enabled` in jump-host's own config — the bundled theta-env stack
|
||||||
|
is unaffected and continues to wire jump-host to the shared LDAP directory
|
||||||
|
and SSO Manager as before. Two bugs were also fixed in jump-host's SSH
|
||||||
|
server: an ephemeral listen port (`0`) was silently overridden back to the
|
||||||
|
default, and session listeners could miss a client's immediate `exec`/`shell`
|
||||||
|
request.
|
||||||
|
|
||||||
|
No `setup.sh`, compose, or config change on the theta-env side.
|
||||||
|
|
||||||
|
## [1.5.0] - 2026-07-26
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.5.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.5.0)
|
||||||
|
- proxy -> [v1.4.0](https://github.com/theta42/proxy/releases/tag/v1.4.0)
|
||||||
|
- jump-host -> [v1.3.0](https://github.com/theta42/jump-host/releases/tag/v1.3.0)
|
||||||
|
|
||||||
|
This release finishes the UI half of the unification that 1.4.0 deferred: the
|
||||||
|
three apps now share one front-end shell. `views/top.ejs`, `views/bottom.ejs`
|
||||||
|
and `public/lib/js/app-base.js` are byte-identical across sso-manager-node,
|
||||||
|
proxy and jump-host, and everything per-app moved into each repo's new
|
||||||
|
`nodejs/utils/ui.js` (nav items and the groups that may see them, footer links,
|
||||||
|
favicon, profile/logout targets, update-banner on/off). Nav gating is one model
|
||||||
|
everywhere — the shell reveals `.group-required-<cn>` from `GET /api/user/me`,
|
||||||
|
normalising sso's LDAP DNs and the OIDC clients' group CNs to the same shape,
|
||||||
|
with the clients' `isAdmin` flag exposed as a synthetic `admin` group. jQuery is
|
||||||
|
4.0.0 and EJS 3.1.10 in all three.
|
||||||
|
|
||||||
|
Five client-side bugs were fixed along the way, including two that broke real
|
||||||
|
flows: `app.api.delete` ignored the callback that `formAJAX` passes (so
|
||||||
|
DELETE-method forms — the proxy's host and DNS delete buttons — never refreshed),
|
||||||
|
and the login page threw on every logged-out visit while revealing its card.
|
||||||
|
|
||||||
|
No `setup.sh`, compose or config change: this is app-internal UI work. Verified
|
||||||
|
by driving a full stack of all three apps in a browser — every page renders
|
||||||
|
console-clean, nav gating is correct per role, and the OIDC login round trip
|
||||||
|
completes on both OIDC clients.
|
||||||
|
|
||||||
|
sso-manager-node 1.5.0:
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Unified the front-end UI shell across the three theta42 apps.** `views/top.ejs`, `views/bottom.ejs` and `public/lib/js/app-base.js` are now byte-identical in sso-manager-node, proxy and jump-host, so the apps look and behave the same and a shell change lands in one edit per repo instead of three divergent ones. Everything that differs between the apps moved into a new `nodejs/utils/ui.js`, exposed to every render as `ui` via `app.locals`: nav items and the groups that may see them, footer repo/license/docs/Terms links, favicon, the profile and post-logout targets, and whether the update banner exists at all.
|
||||||
|
- **One nav-gating model everywhere.** `app-base.js` reveals `.group-required-<cn>` elements for each group the current user is in, read from `GET /api/user/me`. sso-manager-node reports LDAP DNs in `memberOf` and the OIDC clients report CNs in `groups`; both normalise to CNs client-side, and the clients' effective-rights `isAdmin` flag is exposed as a synthetic `admin` group — so one gating model covers a group-based provider and boolean-admin clients without either app learning the other's response shape.
|
||||||
|
- **`GET /api/user/me` is fetched once per page load and cached** (`app.auth.loadUser`). The nav, per-view `forceLogin` and every group-gated element read that one promise instead of issuing their own request.
|
||||||
|
- `app.auth.isLoggedIn` is dual-mode: it returns a Promise **and** invokes an optional node-style callback, so the async and callback call styles both work against one shared `top.ejs`.
|
||||||
|
- `app.auth.forceLogin` no longer uses `$.holdReady` (removed in jQuery 4). An unauthenticated user is redirected to `/login?redirect=<path>`; group requirements are still enforced, and `logOut` now only clears the session, leaving the destination to the caller (`ui.logoutRedirect`).
|
||||||
|
- Dependency alignment across all three apps: `jquery` `^4.0.0` and `ejs` `^3.1.10`.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **`app.api.delete` dropped its callback when called by `formAJAX`.** `formAJAX` always passes the serialized form as the second argument, so a DELETE-method form's callback landed in the data slot and never ran. `delete` now accepts both `(url, callback)` and `(url, data, callback)`.
|
||||||
|
- **`app.api.post`/`put` referenced an undefined `callback2`** and threw when handed a non-function callback. Both are now dual-mode Promise/callback.
|
||||||
|
- **The login page's "reveal the card once we know you're logged out" branch threw** (`Cannot read properties of null`) whenever the logged-in check answered before the parser reached that element — which it always did without a stored token. It now runs on DOM ready.
|
||||||
|
- **`logInRedirect` on the legacy `/login/<path>` form kept only the path.** The OIDC provider routes an unauthenticated authorization request through `/login/oauth/authorize?client_id=…&state=…`; dropping the query there loses the entire authorization request. The suffix form now preserves its query string.
|
||||||
|
|
||||||
|
### Fixed (sso-manager-node)
|
||||||
|
- `public/lib/js/val.js` shadowed `message` with `let` inside `validateField`, so a custom rule's return value never reached `validateMessage` and the caller always saw the generic length message. Resolved by adopting the shared validator, which also brings the `target`/`hostname` rules and the real password policy (>= 8 chars, and either 12+ or 3 of 4 character classes) to this app.
|
||||||
|
- `public/js/app.js` used `$.isFunction`, removed in jQuery 4.
|
||||||
|
|
||||||
|
### Added (sso-manager-node)
|
||||||
|
- `GET /api/user/me` now also reports `isAdmin` (membership in `app_sso_admin`), the single effective-rights flag the shared UI shell gates the update banner on. Group-level gating still reads `memberOf`.
|
||||||
|
|
||||||
|
### Verified
|
||||||
|
- Browser-verified against a full theta-env stack (sso-manager + proxy + jump-host): every top-level page renders with a clean console; nav gating is correct for admin and non-admin; `forceLogin`'s onboarding and group gates fire; `val.js` blocks a weak password and accepts a strong one through a real form submit; the DELETE-method forms work; and the OIDC login round trip (authorize with PKCE -> login -> consent -> callback -> token fragment) completes on both OIDC clients.
|
||||||
|
|
||||||
|
proxy 1.4.0:
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Unified the front-end UI shell across the three theta42 apps.** `views/top.ejs`, `views/bottom.ejs` and `public/lib/js/app-base.js` are now byte-identical in sso-manager-node, proxy and jump-host, so the apps look and behave the same and a shell change lands in one edit per repo instead of three divergent ones. Everything that differs between the apps moved into a new `nodejs/utils/ui.js`, exposed to every render as `ui` via `app.locals`: nav items and the groups that may see them, footer repo/license/docs/Terms links, favicon, the profile and post-logout targets, and whether the update banner exists at all.
|
||||||
|
- **One nav-gating model everywhere.** `app-base.js` reveals `.group-required-<cn>` elements for each group the current user is in, read from `GET /api/user/me`. sso-manager-node reports LDAP DNs in `memberOf` and the OIDC clients report CNs in `groups`; both normalise to CNs client-side, and the clients' effective-rights `isAdmin` flag is exposed as a synthetic `admin` group — so one gating model covers a group-based provider and boolean-admin clients without either app learning the other's response shape.
|
||||||
|
- **`GET /api/user/me` is fetched once per page load and cached** (`app.auth.loadUser`). The nav, per-view `forceLogin` and every group-gated element read that one promise instead of issuing their own request.
|
||||||
|
- `app.auth.isLoggedIn` is dual-mode: it returns a Promise **and** invokes an optional node-style callback, so the async and callback call styles both work against one shared `top.ejs`.
|
||||||
|
- `app.auth.forceLogin` no longer uses `$.holdReady` (removed in jQuery 4). An unauthenticated user is redirected to `/login?redirect=<path>`; group requirements are still enforced, and `logOut` now only clears the session, leaving the destination to the caller (`ui.logoutRedirect`).
|
||||||
|
- Dependency alignment across all three apps: `jquery` `^4.0.0` and `ejs` `^3.1.10`.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **`app.api.delete` dropped its callback when called by `formAJAX`.** `formAJAX` always passes the serialized form as the second argument, so a DELETE-method form's callback landed in the data slot and never ran. `delete` now accepts both `(url, callback)` and `(url, data, callback)`.
|
||||||
|
- **`app.api.post`/`put` referenced an undefined `callback2`** and threw when handed a non-function callback. Both are now dual-mode Promise/callback.
|
||||||
|
- **The login page's "reveal the card once we know you're logged out" branch threw** (`Cannot read properties of null`) whenever the logged-in check answered before the parser reached that element — which it always did without a stored token. It now runs on DOM ready.
|
||||||
|
- **`logInRedirect` on the legacy `/login/<path>` form kept only the path.** The OIDC provider routes an unauthenticated authorization request through `/login/oauth/authorize?client_id=…&state=…`; dropping the query there loses the entire authorization request. The suffix form now preserves its query string.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `.group-required { display: none }` in `public/css/styles.css`, the base rule the shared gating model reveals against.
|
||||||
|
- Admin-only nav items lost their inline `display: none` in favour of that class, and the brand link points at `/` instead of `#`.
|
||||||
|
|
||||||
|
### Verified
|
||||||
|
- Browser-verified against a full theta-env stack (sso-manager + proxy + jump-host): every top-level page renders with a clean console; nav gating is correct for admin and non-admin; `forceLogin`'s onboarding and group gates fire; `val.js` blocks a weak password and accepts a strong one through a real form submit; the DELETE-method forms work; and the OIDC login round trip (authorize with PKCE -> login -> consent -> callback -> token fragment) completes on both OIDC clients.
|
||||||
|
|
||||||
|
jump-host 1.3.0:
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Unified the front-end UI shell across the three theta42 apps.** `views/top.ejs`, `views/bottom.ejs` and `public/lib/js/app-base.js` are now byte-identical in sso-manager-node, proxy and jump-host, so the apps look and behave the same and a shell change lands in one edit per repo instead of three divergent ones. Everything that differs between the apps moved into a new `nodejs/utils/ui.js`, exposed to every render as `ui` via `app.locals`: nav items and the groups that may see them, footer repo/license/docs/Terms links, favicon, the profile and post-logout targets, and whether the update banner exists at all.
|
||||||
|
- **One nav-gating model everywhere.** `app-base.js` reveals `.group-required-<cn>` elements for each group the current user is in, read from `GET /api/user/me`. sso-manager-node reports LDAP DNs in `memberOf` and the OIDC clients report CNs in `groups`; both normalise to CNs client-side, and the clients' effective-rights `isAdmin` flag is exposed as a synthetic `admin` group — so one gating model covers a group-based provider and boolean-admin clients without either app learning the other's response shape.
|
||||||
|
- **`GET /api/user/me` is fetched once per page load and cached** (`app.auth.loadUser`). The nav, per-view `forceLogin` and every group-gated element read that one promise instead of issuing their own request.
|
||||||
|
- `app.auth.isLoggedIn` is dual-mode: it returns a Promise **and** invokes an optional node-style callback, so the async and callback call styles both work against one shared `top.ejs`.
|
||||||
|
- `app.auth.forceLogin` no longer uses `$.holdReady` (removed in jQuery 4). An unauthenticated user is redirected to `/login?redirect=<path>`; group requirements are still enforced, and `logOut` now only clears the session, leaving the destination to the caller (`ui.logoutRedirect`).
|
||||||
|
- Dependency alignment across all three apps: `jquery` `^4.0.0` and `ejs` `^3.1.10`.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **`app.api.delete` dropped its callback when called by `formAJAX`.** `formAJAX` always passes the serialized form as the second argument, so a DELETE-method form's callback landed in the data slot and never ran. `delete` now accepts both `(url, callback)` and `(url, data, callback)`.
|
||||||
|
- **`app.api.post`/`put` referenced an undefined `callback2`** and threw when handed a non-function callback. Both are now dual-mode Promise/callback.
|
||||||
|
- **The login page's "reveal the card once we know you're logged out" branch threw** (`Cannot read properties of null`) whenever the logged-in check answered before the parser reached that element — which it always did without a stored token. It now runs on DOM ready.
|
||||||
|
- **`logInRedirect` on the legacy `/login/<path>` form kept only the path.** The OIDC provider routes an unauthenticated authorization request through `/login/oauth/authorize?client_id=…&state=…`; dropping the query there loses the entire authorization request. The suffix form now preserves its query string.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `.group-required { display: none }` in `public/css/styles.css`, the base rule the shared gating model reveals against.
|
||||||
|
- `#spa-shell` dropped its inline `margin-top`; `styles.css` already sets it and the shared shell adjusts it when a banner is shown.
|
||||||
|
|
||||||
|
### Verified
|
||||||
|
- Browser-verified against a full theta-env stack (sso-manager + proxy + jump-host): every top-level page renders with a clean console; nav gating is correct for admin and non-admin; `forceLogin`'s onboarding and group gates fire; `val.js` blocks a weak password and accepts a strong one through a real form submit; the DELETE-method forms work; and the OIDC login round trip (authorize with PKCE -> login -> consent -> callback -> token fragment) completes on both OIDC clients.
|
||||||
|
|
||||||
|
## [1.4.0] - 2026-07-25
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.4.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.4.0)
|
||||||
|
- proxy -> [v1.3.0](https://github.com/theta42/proxy/releases/tag/v1.3.0)
|
||||||
|
- jump-host -> [v1.2.0](https://github.com/theta42/jump-host/releases/tag/v1.2.0)
|
||||||
|
|
||||||
|
This release unifies the three theta42 apps onto shared `@simpleworkjs/*` packages
|
||||||
|
(`oidc-client`, `directory-schema`, `ldap`, `app-stack` — published under the
|
||||||
|
simpleworkjs org at 1.0.0), replacing each app's byte-identical forks of the same
|
||||||
|
code so they share one codebase and API schema. It also fixes a security
|
||||||
|
regression in the SSO directory discovery API (OAuth `client_secret_hash` leaked
|
||||||
|
to every authenticated caller) and the envelope drift that broke jump-host
|
||||||
|
bridging. The shared UI chrome (`top.ejs`/`bottom.ejs`, `app-base.js`, `val.js`)
|
||||||
|
is intentionally **not** unified in this release — that work is deferred to a
|
||||||
|
browser-verified session; see `UI_UNIFICATION_HANDOFF.md`. No `setup.sh` change:
|
||||||
|
the new `@simpleworkjs/*` deps resolve from npm inside each app's image build
|
||||||
|
(`npm ci` stays clean; no `file:`/`link:`).
|
||||||
|
|
||||||
|
sso-manager-node 1.4.0:
|
||||||
|
|
||||||
|
### Security
|
||||||
|
- **The directory discovery API leaked OAuth `client_secret_hash` (and any secret-ish metadata key) to every authenticated caller.** `Resource` doesn't override `toJSON`, so the ORM serialized `metadata` wholesale — including the `client_secret_hash` stored on `kind:'oauth'` resources — across `GET /api/discovery/resources`, `/graph`, `/me`, `/resources/:slug`, and the directory-admin `GET /api/directory-admin/resources`. Every discovery read endpoint and the admin list now route through `projectResource`/`projectResources` from `@simpleworkjs/directory-schema`, which unconditionally strips secret keys (anything matching `/secret|password|privatekey/i`, including `client_secret_hash`) and, for non-directory-admins, reduces metadata to a public allowlist. Admins never receive `client_secret_hash` either.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **Directory discovery envelope drift.** `routes/discovery.js` (the `autoRouter(Resource)` mounted live at `app.js:87`) returned **bare arrays**, not the `{ results: [...] }` envelope the directory contract specifies — so jump-host's `data.results || []` collapsed every per-group query to `[]` and no user could bridge. Discovery is now served by explicit `/resources`, `/resources/:slug`, `/graph`, `/me` handlers that all return the `{ results }` envelope. The dead `routes/api_discovery.js` (mounted at `app.js:112`, *after* the 404 catcher) and its mount were removed.
|
||||||
|
- `GET /api/discovery/resources?group=<cn>` now returns 200 with `{ results: [...] }` instead of 404.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `@simpleworkjs/directory-schema` — the directory contract: the `kind` enum, `Resource`/`ResourceEdge`/`ResourceGroup` field defs, the `{ results }` envelope, the security projection (`projectResource`/`projectResources`/`isDirectoryAdmin`), and the discovery client. `models/resource.js` imports the field defs; the discovery + directory-admin routes use the projection.
|
||||||
|
- `@simpleworkjs/ldap` — `models/user_ldap.js` and `models/group_ldap.js` now take `escapeFilter`/`escapeDN` and `makeClient`/`withClient` from the shared package (via local wrappers that pass `conf`); sso keeps its rich `User.get`/`Group.get`/`User.login`/`User.addSSHkey` (posix/write-side stays app-local). sso's `makeClient` passes no `tlsOptions`, so cert validation is unchanged.
|
||||||
|
- `@simpleworkjs/app-stack` — unified `build_info` (`{buildVersion, buildHash, buildYear}`) and the `static-modules` mounting helper. `utils/build_info.js` and the static-modules loop in `routes/index.js` use the shared helpers.
|
||||||
|
- New `tests/discovery.test.js` (jest + supertest, runs under the docker harness): locks in the `{ results }` envelope on `/resources`, `/graph`, `/me`, `/resources/:slug`, the `?group=` 200-regression, and the no-`client_secret_hash`/no-secret-key guarantee for every caller.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Dependency alignment: `ldapts` `^8.1.2` → `^8.1.8`. The new `@simpleworkjs/*` deps resolve from the npm registry (`^1.0.0`); no `file:`/`link:` entries in the lockfile, so `npm ci` is clean in docker builds.
|
||||||
|
- `build_info` export shape changed from `{commit, version}` to `{buildVersion, buildHash, buildYear}` (the shared shape used by all three apps).
|
||||||
|
|
||||||
|
proxy 1.3.0:
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `@simpleworkjs/oidc-client` — the OIDC client (session models, auth router, OIDC utils, safe-redirect, local-admin bootstrap). Deleted the local `utils/oidc.js`, `utils/safe_redirect.js`, `models/oidc_state.js`, `models/token.js`, `models/auth.js`, `routes/auth.js`; `models/index.js` wires the factory. The per-host SSO in `routes/host_auth.js` is unchanged but consumes the shared OIDC utils.
|
||||||
|
- `@simpleworkjs/ldap` — the ldapts client + RFC 4515/4514 escaping.
|
||||||
|
- `@simpleworkjs/app-stack` — unified `build_info` (`{buildVersion, buildHash, buildYear}`) and the `static-modules` mounting helper. `utils/build_info.js` and the static-modules loop in `routes/render.js` now use the shared helpers.
|
||||||
|
|
||||||
|
### Security
|
||||||
|
- **LDAP filter injection in `User.get`.** The user lookup built its search filter by interpolating `data.username` raw into `(&(objectClass=inetOrgPerson)(uid=<username>))`. A username containing `*`, `(`, `)`, `\`, or NUL could widen or alter the filter (e.g. `*` → match-all). The filter value is now passed through `escapeFilter` from `@simpleworkjs/ldap` (RFC 4515 escaping).
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Dependency alignment: `model-redis` `^1.5` → `^1.6.0`, `ldapts` `^8.1.2` → `^8.1.8`. The four new `@simpleworkjs/*` deps resolve from the npm registry (`^1.0.0`); no `file:`/`link:` entries in the lockfile, so `npm ci` is clean in docker builds.
|
||||||
|
- `build_info` export shape changed from `{commit, version}` to `{buildVersion, buildHash, buildYear}` (the shared shape used by all three apps). The `/health` endpoint and footer now report `buildVersion`/`buildHash`.
|
||||||
|
|
||||||
|
jump-host 1.2.0:
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `@simpleworkjs/oidc-client` — the OIDC client (session models, auth router, OIDC utils, safe-redirect, local-admin bootstrap). Deleted the local `utils/oidc.js`, `utils/safe_redirect.js`, `models/oidc_state.js`, `models/token.js`, `models/auth.js`, `routes/auth.js`; `models/index.js` wires the factory and the local-admin bootstrap.
|
||||||
|
- `@simpleworkjs/directory-schema` — the sso↔jump-host directory contract. `utils/access.js` now fetches reachable hosts through the shared `createDirectoryClient` (`getResourcesByGroup`).
|
||||||
|
- `@simpleworkjs/ldap` — `models/user_ldap.js` is now a thin wrapper over `createLdapClient`, preserving this app's loose TLS default (`rejectUnauthorized: false`) and the exact export shape.
|
||||||
|
- `@simpleworkjs/app-stack` — unified `build_info` (`{buildVersion, buildHash, buildYear}`) and the `static-modules` mounting helper. `build_info` moved from `models/` to `utils/`; `routes/render.js` uses `mountStaticModules`.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **Directory envelope drift was silently treated as "no reachable hosts".** `utils/access.js` previously read `data.results || []`, so if the SSO directory ever returned a bare array (envelope drift) every per-group query collapsed to `[]` and no user could bridge. The shared client now validates the `{ results }` envelope on every call and treats an envelope violation as a failed group fetch rather than silently returning `[]`.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Dependency alignment: `ldapts` `^8.1.2` → `^8.1.8`, `redis` `^4.7` → `^6.1.0` (the direct `redis` dep is unused — only `model-redis` is used, which already brings `redis` ^6.1.0). The new `@simpleworkjs/*` deps resolve from the npm registry (`^1.0.0`); no `file:`/`link:` entries in the lockfile, so `npm ci` is clean in docker builds.
|
||||||
|
- `build_info` export shape changed from `{commit, version}` to `{buildVersion, buildHash, buildYear}` (the shared shape used by all three apps). The `/health` endpoint and footer now report `buildVersion`/`buildHash`.
|
||||||
|
- `app-base.js` `forceLogin`/`logInRedirect` switched to the `?redirect=` query-param convention (matching the server-side `/login?redirect=` route).
|
||||||
|
|
||||||
|
## [1.3.7] - 2026-07-23
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- The bootstrap now provisions the jump host's **web-UI SSO login** when the jump host is enabled: it mints a dedicated `theta-jump` OAuth client and writes a full `oidc` block (endpoints, client id/secret, callback) plus a generated local anti-lockout admin password into `./config/jump-secrets.js`. Matches how the proxy's OIDC client is provisioned. An existing pre-OIDC `jump-secrets.js` (API token but no OIDC client) is regenerated so upgraders get SSO login. Requires jump-host ≥ v1.1.0.
|
||||||
|
|
||||||
|
## [1.3.6] - 2026-07-23
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.3.2](https://github.com/theta42/sso-manager-node/releases/tag/v1.3.2)
|
||||||
|
|
||||||
|
sso-manager-node 1.3.2:
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **OAuth client management API returned `client_id: undefined` on every GET**, which broke this stack's bootstrap: it lists the OAuth clients and rotates by the returned `client_id`, so it called `/api/oauth/client/undefined/rotate` and got a 500 — aborting `setup.sh` with `bootstrap failed` whenever `proxy-secrets.js` had no usable secret (e.g. a fresh/rotated deployment). The ORM's `toJSON()` was stripping the mapped `client_id`/`scopes`/… fields; `OAuthClient.get()` now emits them explicitly (and omits `client_secret_hash`). Unknown client ids now 404 instead of 500.
|
||||||
|
|
||||||
|
## [1.3.5] - 2026-07-23
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **Optional SSH jump host** (theta42/jump-host) as a third, opt-in submodule. Enable with `CFG_JUMP_HOST_ENABLED=true` in `setup.env`: setup.sh clones/tag-tracks the submodule and builds it behind the `jump-host` compose profile, the bootstrap mints a directory API token and writes `./config/jump-secrets.js` (LDAP admin bind so it can inject users' `sshPublicKey`), the jump host is registered as a proxy Host (its web UI) and seeded as a directory service. Users then `ssh uid_-_host@jump.<domain>` (WinSCP-friendly) or `ssh uid@jump.<domain>` for a TUI host picker; the web UI on :3002 shows audit + metrics. Off by default — existing installs are unaffected.
|
||||||
|
|
||||||
|
## [1.3.4] - 2026-07-23
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.3.1](https://github.com/theta42/sso-manager-node/releases/tag/v1.3.1)
|
||||||
|
|
||||||
|
sso-manager-node 1.3.1:
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- The Directory documentation (`docs/directory.md`) is now surfaced: registered in-app at `/docs/directory` ("Directory & Inventory"), help-linked from the Directory page header, and linked from the docs-site index. Extended with the shared slug conventions (`site_<name>`, `host_<hostname>` — as used by ldap-client and the theta-env seed), the automatic-registration story (theta-env stack seeding, ldap-client Linux host enrollment), and the API surface (admin at `/api/directory-admin`, read-only graph at `/api/discovery`).
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Direct LDAP binds are described as first-class, not "legacy", across README, DEPLOYMENT.md, docs, and the Dockerfile: Linux hosts are a primary consumer of the directory (PAM/SSSD login, LDAP-backed `sudo` via `sudoRole`, SSH public keys via openssh-lpk) — exactly what the custom schemas exist for.
|
||||||
|
|
||||||
|
### theta-env own changes
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `CFG_SITE_NAME` in `setup.env` (right below `CFG_DOMAIN`, default `local`): names the SSO directory site the stack registers itself under — slug `site_<name>`, matching the `parentSlug` convention ldap-client-joined Linux hosts use, so they land under the same site.
|
||||||
|
- The directory seed now collects real host facts on the machine (hostname, IP, MAC of the default-route interface, OS pretty-name, kernel — same collection as `ldap-client/index.sh`) and registers the stack host as `host_<hostname>` with that metadata, plus fills in each service's internal port and git repo (`sso-manager` 3001, `proxy` 3000, `openldap` 389/636, `openresty` 443). Existing resources from the earlier seed layout (`stack-host`, domain-slug site) are adopted in place — seed metadata only fills fields the operator hasn't set, never overwrites.
|
||||||
|
- The bootstrap now seeds the SSO directory with the stack's own resources: a site (from the configured domain), a "Stack host", and the SSO Manager + Proxy services (with their public URLs in metadata), linking the proxy's auto-registered OAuth client under its service. Also seeds the two non-obvious services the stack runs: the OpenLDAP directory (advertising the `ldaps://` endpoint Linux hosts and LDAP-native apps bind to, honoring `ldap.ldapsHost`) and the OpenResty edge (the 80/443 data plane every hostname flows through, with a wildcard `https://*.<domain>` address). The Directory page is populated out of the box instead of starting empty. Idempotent — resources whose slug already exists are operator-owned and never touched, and a seed failure only warns (never fails a bring-up, e.g. against an older sso-manager image without `/api/directory`).
|
||||||
|
|
||||||
|
## [1.3.3] - 2026-07-23
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.3.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.3.0) (from v1.1.18; includes the intermediate v1.2.1 release)
|
||||||
|
|
||||||
|
sso-manager-node 1.3.0:
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **OAuth client management API** at `/api/oauth/client` (group `app_sso_oauth_admin`): list, create, update, delete, and rotate-secret for OAuth clients, backed by the Resource model. Accepts form-style string inputs (newline-separated `redirect_uris`/`allowed_groups`, space-separated `scopes`).
|
||||||
|
- **Dockerized test suite**: `docker-compose -f docker-compose.test.yml up --build` spins up OpenLDAP + Redis + a test-runner that seeds the test user and runs the full jest suite (174 tests) against them. `tests/globalSetup.js` honors `REDIS_URL`.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- Completed the model-redis → `@simpleworkjs/orm` port that shipped half-finished in 1.2.1:
|
||||||
|
- `OtpToken.issue`/`verify` called nonexistent `find()`/`listDetail()` — every OTP login 500'd.
|
||||||
|
- Impersonation create/revoke called nonexistent `ImpersonationToken.listDetail()` — both endpoints 500'd.
|
||||||
|
- `OAuthClient` read `is_valid` from the Resource model, which has no such column — every client evaluated as disabled and **all `/oauth/authorize` requests were rejected with 400**. Client validity now lives in `metadata` (absent = valid).
|
||||||
|
- `OAuthClient.add` didn't set the required-unique `Resource.slug`; clients now get a slug derived from the client name.
|
||||||
|
- `GET /api/token/:name/:token` returned `{results: null}` with 200 for unknown tokens (orm `get()` returns null instead of throwing); now 404s.
|
||||||
|
- `User.login` returns a clean 401 instead of crashing when neither `uid` nor `username` is supplied.
|
||||||
|
- Depend on published `@simpleworkjs/orm` ^0.2.8 and `model-redis` ^1.6.0 instead of a local `file:` link that broke `npm ci` in docker builds.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Removed the Mobile Phone field from the user create/edit form.
|
||||||
|
|
||||||
|
sso-manager-node 1.2.1:
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **Actionable Metrics**: New real-time metrics tracking for failed logins, top IPs, and service usage per user.
|
||||||
|
- **LDAP Monitor**: Background service to parse OpenLDAP binds over port 389 and track metrics for legacy apps.
|
||||||
|
- **UI Updates**: Executive dashboard now displays actionable metrics cards instead of raw logs. User profiles show individual service usage stats to admins.
|
||||||
|
- **Directory Management**: Integrated site/host/service abstractions into directory UI and allowed associating OAuth apps directly to services.
|
||||||
|
|
||||||
|
## [1.3.2] - 2026-07-21
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- proxy -> [v1.2.2](https://github.com/theta42/proxy/releases/tag/v1.2.2)
|
||||||
|
|
||||||
|
proxy:
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- Multi-target load balancing (added in 1.2.0) crashed every request to a load-balanced host: `ops/nginx_conf/targetinfo.lua` required a nonexistent `resty.balancer.round_robin` module. The `lua-resty-balancer` rock actually installed provides `resty.roundrobin` instead, with a different constructor API. Fixed `targetinfo.lua` to use the real module — verified end-to-end that requests now round-robin across targets with no Lua errors.
|
||||||
|
|
||||||
|
## [1.3.1] - 2026-07-21
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- proxy -> [v1.2.1](https://github.com/theta42/proxy/releases/tag/v1.2.1)
|
||||||
|
- sso-manager-node -> [v1.1.18](https://github.com/theta42/sso-manager-node/releases/tag/v1.1.18)
|
||||||
|
|
||||||
|
proxy:
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- The bootstrap anti-lockout admin account was always created as `proxyadmin2` regardless of `conf.auth.adminUsers`, while `migrations/permission_bootstrap.js` grants the global-admin permission to `conf.auth.adminUsers[0]`. If an operator customized `adminUsers` away from the default, the bootstrapped account and the permissioned account were two different (non-matching) usernames, so the anti-lockout account ended up with no admin access. `models/user_redis.js` now derives the bootstrap username from `conf.auth.adminUsers[0]` (falling back to `proxyadmin2`), matching `permission_bootstrap.js`.
|
||||||
|
- Corrected a `secrets.js.example` comment that claimed the bootstrap admin's password "defaults to the username itself" — it actually generates a random password printed to the container log on first boot.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Refreshed all README screenshots (hosts, per-host SSO auth, per-host basic auth) against the current UI, and added a new load-balancing screenshot for the multi-target feature.
|
||||||
|
|
||||||
|
sso-manager-node:
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- N-Way Multi-Master LDAP replication: `LDAP_SERVER_ID` + `LDAP_REPLICATION_HOSTS` configure `syncrepl` peers in the bundled OpenLDAP, and a new `/sites` page (nav: **Sites**) shows each configured peer's LDAP URL and live reachability.
|
||||||
|
- A `location` property on users, editable from the profile and user-edit forms.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- `/sites` (added above) 500'd on every load: `views/sites.ejs` included nonexistent partials `header`/`footer` instead of this app's actual `top`/`bottom`. Fixed to match every other view.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Refreshed all README screenshots (dashboard, users, groups, OAuth apps) against the current UI, and added a new Sites & Replication screenshot.
|
||||||
|
|
||||||
|
### theta-env own changes
|
||||||
|
- Refreshed `docs/images/sso-dashboard.png` and `docs/images/proxy-hosts.png` to match the submodules' updated screenshots.
|
||||||
|
|
||||||
|
## [1.1.20] - 2026-07-20
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- proxy -> [v1.1.17](https://github.com/theta42/proxy/releases/tag/v1.1.17)
|
||||||
|
|
||||||
|
proxy:
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- An existing single-label subdomain host (e.g. `sso.nl.wgnode.com`) could not be attached to a wildcard cert added later (e.g. `*.nl.wgnode.com`): `Host.lookUpWildcardParent()` only checked the wildcard-as-child position (the wildcard's own base domain) and missed the far more common wildcard-as-sibling case, so the edit form's "Parent Wildcard" option stayed permanently greyed out. It now checks both positions, and a regression test covers the sibling case.
|
||||||
|
|
||||||
|
## [1.1.19] - 2026-07-18
|
||||||
|
|
||||||
|
### Bumped
|
||||||
|
- sso-manager-node -> [v1.1.17](https://github.com/theta42/sso-manager-node/releases/tag/v1.1.17)
|
||||||
|
|
||||||
|
sso-manager-node:
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `conf.ldap.ldapsHost` and `conf.ldap.ldapsPort` config options for advertising a separate, internal-only LDAPS hostname on the `/integrations` page. Falls back to the public OAuth issuer host when unset.
|
||||||
|
- Contextual help panel on `/integrations` → LDAP explaining why LDAPS needs a hostname, why port 636 should not be forwarded publicly, and the recommended internal-DNS / Docker-internal alternatives.
|
||||||
|
- Tests for the `/integrations` route's LDAPS URL derivation and `ldapsHost` override.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- `nodejs/package.json` / `package-lock.json` version bumped to `1.1.17`.
|
||||||
|
- `routes/index.js` now derives the displayed LDAPS URL from `conf.ldap.ldapsHost`/`ldapsPort` with fallback to the OAuth issuer host.
|
||||||
|
- `docs/configuration.md`, `docs/ldap.md`, `DEPLOYMENT.md`, and `secrets.js.example` document the new `ldapsHost`/`ldapsPort` options and recommended network layouts.
|
||||||
|
|
||||||
|
### theta-env own changes
|
||||||
|
- `setup.env.example` adds optional `CFG_LDAPS_HOST` for the internal LDAPS hostname.
|
||||||
|
- `setup.sh` passes `CFG_LDAPS_HOST` into the generated `./config/sso-secrets.js` as `ldap.ldapsHost`.
|
||||||
|
- `config.example/sso-secrets.js.example` documents `ldap.ldapsHost` / `ldap.ldapsPort`.
|
||||||
|
- `.env.example` adds `LDAPS_HOST` for legacy `.env` migrations.
|
||||||
|
- `docker-compose.yml` comments warn against forwarding 636 to the public internet.
|
||||||
|
- `README.md` explains the `CFG_LDAPS_HOST` recommendation in the port-forwarding section.
|
||||||
|
|
||||||
## [1.1.18] - 2026-07-18
|
## [1.1.18] - 2026-07-18
|
||||||
|
|
||||||
### Bumped
|
### Bumped
|
||||||
@@ -257,7 +1165,8 @@ First tagged release. Establishes the `vX.Y.Z` tag convention going forward.
|
|||||||
- proxy -> [v1.1.0](https://github.com/theta42/proxy/releases/tag/v1.1.0)
|
- proxy -> [v1.1.0](https://github.com/theta42/proxy/releases/tag/v1.1.0)
|
||||||
- sso-manager-node -> [v1.1.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.1.0)
|
- sso-manager-node -> [v1.1.0](https://github.com/theta42/sso-manager-node/releases/tag/v1.1.0)
|
||||||
|
|
||||||
[Unreleased]: https://github.com/theta42/theta-env/compare/v1.1.18...HEAD
|
[Unreleased]: https://github.com/theta42/theta-env/compare/v1.4.0...HEAD
|
||||||
|
[1.4.0]: https://github.com/theta42/theta-env/compare/v1.3.7...v1.4.0
|
||||||
[1.1.17]: https://github.com/theta42/theta-env/compare/v1.1.16...v1.1.17
|
[1.1.17]: https://github.com/theta42/theta-env/compare/v1.1.16...v1.1.17
|
||||||
[1.1.16]: https://github.com/theta42/theta-env/compare/v1.1.15...v1.1.16
|
[1.1.16]: https://github.com/theta42/theta-env/compare/v1.1.15...v1.1.16
|
||||||
[1.1.15]: https://github.com/theta42/theta-env/compare/v1.1.14...v1.1.15
|
[1.1.15]: https://github.com/theta42/theta-env/compare/v1.1.14...v1.1.15
|
||||||
|
|||||||
@@ -26,14 +26,18 @@ The SSO Manager and the proxy it fronts, both stood up by one `./setup.sh` run:
|
|||||||
| --- | --- |
|
| --- | --- |
|
||||||
| [](docs/images/sso-dashboard.png) | [](docs/images/proxy-hosts.png) |
|
| [](docs/images/sso-dashboard.png) | [](docs/images/proxy-hosts.png) |
|
||||||
|
|
||||||
**Why use this instead of running the two separately?** The two only become
|
## Configuration
|
||||||
useful once the proxy is registered as an OIDC client of the SSO and pointed at
|
|
||||||
the SSO's LDAP directory — and the SSO's domain has to match across half a dozen
|
`setup.sh` automates the first-run glue between subprojects:
|
||||||
config fields or logins silently fail with `Invalid Credentials`. Doing that by
|
- Asks for your domain once (in `setup.env`) and fills it in across all config files.
|
||||||
hand is fiddly and easy to get wrong. `setup.sh` asks for your domain once (in
|
- Registers the proxy as an OIDC client of the SSO.
|
||||||
`setup.env`), generates both config files with it filled in everywhere, registers
|
- Persists submodule commit hashes in `.env` for reproducibility (e.g., `SSO_GIT_COMMIT`, `PROXY_GIT_COMMIT`). This ensures future `docker compose` runs use the same submodule versions.
|
||||||
the proxy as an OIDC client, and snapshots state before every rebuild — so you
|
|
||||||
get a working SSO + proxy stack in one command and a safe way to upgrade it.
|
**Why use this instead of running the two separately?** The two only become useful once the proxy is registered as an OIDC client of the SSO and pointed at the SSO's LDAP directory — and the SSO's domain has to match across half a dozen config fields or logins silently fail with `Invalid Credentials`. Doing that by hand is fiddly and easy to get wrong. `setup.sh` handles this automatically and snapshots state before every rebuild — so you get a working SSO + proxy stack in one command and a safe way to upgrade it.
|
||||||
|
|
||||||
|
## Unified Release Status
|
||||||
|
- ✅ **Phase 1 (oidc-client)**: Complete.
|
||||||
|
- ⏳ **Phases 2-5**: Pending (see [roadmap](#)).
|
||||||
|
|
||||||
```
|
```
|
||||||
┌──────────────────────────────────────────────┐
|
┌──────────────────────────────────────────────┐
|
||||||
@@ -60,6 +64,10 @@ It is **both** an OIDC client of the SSO (for login) **and** a direct LDAP
|
|||||||
client (for user lookups). Legacy apps can still bind to LDAPS on the SSO
|
client (for user lookups). Legacy apps can still bind to LDAPS on the SSO
|
||||||
directly.
|
directly.
|
||||||
|
|
||||||
|
- **Self-service API tokens** in both apps' UIs, for scripting/CI without a browser session.
|
||||||
|
- **Multi-Site Support (Geo-Location Scaling)** — built-in support for N-Way Multi-Master LDAP replication across physical locations.
|
||||||
|
- **Multi-target load balancing** — built-in proxy support for round-robin load balancing across multiple application servers.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Before you begin
|
## Before you begin
|
||||||
@@ -120,6 +128,10 @@ Optional extra ports (only if you need them):
|
|||||||
- **636** (LDAPS) — only if a legacy app on another machine binds to LDAP
|
- **636** (LDAPS) — only if a legacy app on another machine binds to LDAP
|
||||||
directly over the network. The proxy itself reaches LDAP over the internal
|
directly over the network. The proxy itself reaches LDAP over the internal
|
||||||
Docker network, so you do **not** need to expose 636 for the stack to work.
|
Docker network, so you do **not** need to expose 636 for the stack to work.
|
||||||
|
**Do not forward 636 to the public internet.** If you need LAN clients to bind
|
||||||
|
LDAP, set `CFG_LDAPS_HOST=ldap.internal.example.com` (or `sso-manager` for
|
||||||
|
same-host Docker clients) in `setup.env` and use an internal DNS record / cert
|
||||||
|
SAN. The default shows the public SSO hostname, which implies a public route.
|
||||||
|
|
||||||
### 4. Docker + Docker Compose
|
### 4. Docker + Docker Compose
|
||||||
|
|
||||||
@@ -169,11 +181,21 @@ operator-owned and `setup.env` is ignored.
|
|||||||
would 404. Idempotent; skips a host that already exists.
|
would 404. Idempotent; skips a host that already exists.
|
||||||
6. Prints your first admin login + the public URLs.
|
6. Prints your first admin login + the public URLs.
|
||||||
|
|
||||||
### Configuration — `./config/` (no `.env` files)
|
### Configuration & secrets — OpenBao + `./config/`
|
||||||
|
|
||||||
All config and secrets live in a bind-mounted `./config/` directory (gitignored),
|
Secrets live in **OpenBao** (a Vault fork, container `openbao:8200` on
|
||||||
read by each app's `@simpleworkjs/conf` via the `CONF_SECRETS` env var, which
|
`theta-net`), the single authoritative store. Each app loads them at boot with
|
||||||
the entrypoint points at the mounted file:
|
[@simpleworkjs/bao-conf](https://simpleworkjs.github.io/bao-conf/), which
|
||||||
|
deep-merges `secret/<app>/conf` over the file-loaded config — **fail-soft**, so
|
||||||
|
if OpenBao is unreachable the app boots from the file fallback. End users get
|
||||||
|
personal per-user secret storage (`secret/users/<uid>/*`) in the SSO **Vault**
|
||||||
|
UI, and admins mint scoped tokens for external apps (`secret/apps/<name>/*`).
|
||||||
|
See **[docs/secrets.md](docs/secrets.md)** for the full architecture, policies,
|
||||||
|
token model, rotation, and the external-app convention.
|
||||||
|
|
||||||
|
A bind-mounted `./config/` directory (gitignored) holds the operator-edit
|
||||||
|
seed files and the fail-soft fallback, read by each app's `@simpleworkjs/conf`
|
||||||
|
via the `CONF_SECRETS` env var:
|
||||||
|
|
||||||
- **`./config/sso-secrets.js`** — SSO config: `ldap` (base, admin password,
|
- **`./config/sso-secrets.js`** — SSO config: `ldap` (base, admin password,
|
||||||
user/group bases), `oauth` (issuer, `jwtSecret`), `smtp`, `name`, plus
|
user/group bases), `oauth` (issuer, `jwtSecret`), `smtp`, `name`, plus
|
||||||
@@ -184,11 +206,15 @@ the entrypoint points at the mounted file:
|
|||||||
same `serviceAccountPass`), `auth` (admin groups/users).
|
same `serviceAccountPass`), `auth` (admin groups/users).
|
||||||
|
|
||||||
`./setup.sh` generates both on first run from `./setup.env` (the one place the
|
`./setup.sh` generates both on first run from `./setup.env` (the one place the
|
||||||
domain is entered — see *Quickstart*) with random secrets. There is **no
|
domain is entered — see *Quickstart*) with random secrets, seeds them into
|
||||||
`.env` / `proxy.env`** — edit `./config/*.js` directly. Compose only interpolates
|
OpenBao, and mints scoped per-app tokens (`SSO_VAULT_TOKEN` /
|
||||||
port defaults (`SSO_PORT`, `HTTP_PORT`, etc.), which you can override on the
|
`PROXY_VAULT_TOKEN` / `JUMP_VAULT_TOKEN`) into `./.env`. There is **no
|
||||||
command line: `SSO_BIND=127.0.0.1 ./setup.sh`. See `config.example/` for the
|
`.env` / `proxy.env`** for app config — edit `./config/*.js` directly (and
|
||||||
full annotated shape, and each submodule's `secrets.js.example`.
|
re-seed into OpenBao, or use the SSO Configuration UI for live edits). Compose
|
||||||
|
only interpolates port defaults (`SSO_PORT`, `HTTP_PORT`, etc.), which you can
|
||||||
|
override on the command line: `SSO_BIND=127.0.0.1 ./setup.sh`. See
|
||||||
|
`config.example/` for the full annotated shape, and each submodule's
|
||||||
|
`secrets.js.example`.
|
||||||
|
|
||||||
> **Migrating from an older `.env`-based deployment?** If `.env` and/or
|
> **Migrating from an older `.env`-based deployment?** If `.env` and/or
|
||||||
> `proxy.env` exist when you first run `./setup.sh`, it migrates them into
|
> `proxy.env` exist when you first run `./setup.sh`, it migrates them into
|
||||||
@@ -317,8 +343,11 @@ docker compose cp sso-manager:/data/dump.rdb sso-manager.rdb
|
|||||||
docker compose exec proxy redis-cli BGSAVE
|
docker compose exec proxy redis-cli BGSAVE
|
||||||
docker compose cp proxy:/data/dump.rdb proxy.rdb
|
docker compose cp proxy:/data/dump.rdb proxy.rdb
|
||||||
|
|
||||||
# Secrets
|
# Secrets — ./config/ (the seed/fallback; OpenBao is authoritative)
|
||||||
cp -a ./config config-backup && chmod 700 config-backup
|
cp -a ./config config-backup && chmod 700 config-backup
|
||||||
|
# OpenBao (the authoritative secret store — back up its data volume)
|
||||||
|
docker run --rm -v theta-env_openbao-data:/data -v "$PWD":/backup alpine \
|
||||||
|
tar czf /backup/openbao-data.tgz -C /data .
|
||||||
```
|
```
|
||||||
|
|
||||||
### Restore — full disaster recovery
|
### Restore — full disaster recovery
|
||||||
|
|||||||
Vendored
+413
-5
@@ -23,6 +23,13 @@
|
|||||||
* into the file (the sso-manager mounts ./config
|
* into the file (the sso-manager mounts ./config
|
||||||
* read-write for this purpose).
|
* read-write for this purpose).
|
||||||
*
|
*
|
||||||
|
* Generated creds are ALSO written into OpenBao (secret/proxy/conf and, when
|
||||||
|
* the jump host is enabled, secret/jump-host/conf) so the proxy + jump host
|
||||||
|
* load them from OpenBao at boot via @simpleworkjs/bao-conf. setup.sh passes
|
||||||
|
* the root VAULT_TOKEN on this exec for that purpose. The OpenBao write is
|
||||||
|
* fail-soft: if VAULT_TOKEN is unset or OpenBao is unreachable, the /config
|
||||||
|
* file remains the fallback and bootstrap does not fail the bring-up over it.
|
||||||
|
*
|
||||||
* Idempotent: re-running converges to the ./config values. The LDAP service
|
* Idempotent: re-running converges to the ./config values. The LDAP service
|
||||||
* account + admin passwords are reset to the file values on each run; the
|
* account + admin passwords are reset to the file values on each run; the
|
||||||
* OAuth client is created if missing. If proxy-secrets.js already holds a
|
* OAuth client is created if missing. If proxy-secrets.js already holds a
|
||||||
@@ -87,6 +94,44 @@ const ADMIN_GROUPS = ['app_sso_admin', 'app_sso_oauth_admin'];
|
|||||||
const log = (...a) => process.stderr.write('[bootstrap] ' + a.join(' ') + '\n');
|
const log = (...a) => process.stderr.write('[bootstrap] ' + a.join(' ') + '\n');
|
||||||
const out = (k, v) => process.stdout.write(`${k}=${v}\n`);
|
const out = (k, v) => process.stdout.write(`${k}=${v}\n`);
|
||||||
|
|
||||||
|
// ── OpenBao (Vault) writes ───────────────────────────────────────────────────
|
||||||
|
// bootstrap generates the proxy's + jump host's OAuth client creds and writes
|
||||||
|
// them back into /config/*-secrets.js (the file fallback). It ALSO writes the
|
||||||
|
// complete conf into OpenBao so the proxy + jump host load it from there at
|
||||||
|
// boot via @simpleworkjs/bao-conf. setup.sh passes the root VAULT_TOKEN on this
|
||||||
|
// exec. Fail-soft: if VAULT_TOKEN is unset or OpenBao is unreachable, the write
|
||||||
|
// is skipped with a warning — the file remains the fallback and bootstrap does
|
||||||
|
// not fail the bring-up over it.
|
||||||
|
const VAULT_ADDR = process.env.VAULT_ADDR || 'http://openbao:8200';
|
||||||
|
const VAULT_TOKEN = process.env.VAULT_TOKEN || '';
|
||||||
|
|
||||||
|
// Re-require a /config module after its file has been rewritten on disk
|
||||||
|
// (require caches the old contents otherwise).
|
||||||
|
function freshRequire(p) {
|
||||||
|
delete require.cache[require.resolve(p)];
|
||||||
|
return require(p);
|
||||||
|
}
|
||||||
|
|
||||||
|
// PUT (replace) the data at secret/data/<vaultPath> with `data`. Warn-only.
|
||||||
|
async function baoPut(vaultPath, data) {
|
||||||
|
if (!VAULT_TOKEN) { log('OpenBao: VAULT_TOKEN unset — skipping write of secret/' + vaultPath); return; }
|
||||||
|
try {
|
||||||
|
const res = await fetch(`${VAULT_ADDR}/v1/secret/data/${vaultPath}`, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'X-Vault-Token': VAULT_TOKEN, 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify({ data }),
|
||||||
|
});
|
||||||
|
if (!res.ok) {
|
||||||
|
const text = await res.text().catch(() => '');
|
||||||
|
log(`WARNING: OpenBao write secret/${vaultPath} failed (${res.status}) ${text} — app will use its file fallback`);
|
||||||
|
} else {
|
||||||
|
log(`OpenBao: wrote secret/${vaultPath}`);
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
log(`WARNING: OpenBao write secret/${vaultPath} threw (${e.message}) — app will use its file fallback`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Replicate the SSO's hashPasswordSSHA512 (models/user_ldap.js) exactly so the
|
// Replicate the SSO's hashPasswordSSHA512 (models/user_ldap.js) exactly so the
|
||||||
// directory stores passwords the SSO can verify on bind (pw-sha2 module).
|
// directory stores passwords the SSO can verify on bind (pw-sha2 module).
|
||||||
function hashPasswordSSHA512(password) {
|
function hashPasswordSSHA512(password) {
|
||||||
@@ -229,14 +274,15 @@ async function listClients(token) {
|
|||||||
return (data && data.results) || [];
|
return (data && data.results) || [];
|
||||||
}
|
}
|
||||||
|
|
||||||
async function createClient(token) {
|
async function createClient(token, opts) {
|
||||||
|
const o = opts || { name: CLIENT_NAME, description: 'theta-env proxy (auto-registered)', redirect_uris: [REDIRECT_URI] };
|
||||||
const res = await fetch(`${SSO_INTERNAL}/api/oauth/client`, {
|
const res = await fetch(`${SSO_INTERNAL}/api/oauth/client`, {
|
||||||
method: 'POST',
|
method: 'POST',
|
||||||
headers: { 'auth-token': token, 'Content-Type': 'application/json' },
|
headers: { 'auth-token': token, 'Content-Type': 'application/json' },
|
||||||
body: JSON.stringify({
|
body: JSON.stringify({
|
||||||
name: CLIENT_NAME,
|
name: o.name,
|
||||||
description: 'theta-env proxy (auto-registered)',
|
description: o.description,
|
||||||
redirect_uris: [REDIRECT_URI],
|
redirect_uris: o.redirect_uris,
|
||||||
scopes: ['openid', 'profile', 'email', 'groups'],
|
scopes: ['openid', 'profile', 'email', 'groups'],
|
||||||
allowed_groups: [],
|
allowed_groups: [],
|
||||||
}),
|
}),
|
||||||
@@ -249,7 +295,7 @@ async function createClient(token) {
|
|||||||
const id = (data.results && data.results.client_id) || data.client_id;
|
const id = (data.results && data.results.client_id) || data.client_id;
|
||||||
const secret = data.client_secret;
|
const secret = data.client_secret;
|
||||||
if (!id || !secret) throw new Error(`create OAuth client returned no id/secret: ${JSON.stringify(data)}`);
|
if (!id || !secret) throw new Error(`create OAuth client returned no id/secret: ${JSON.stringify(data)}`);
|
||||||
log(`Created OAuth client ${CLIENT_NAME} (${id})`);
|
log(`Created OAuth client ${o.name} (${id})`);
|
||||||
return { id, secret };
|
return { id, secret };
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -268,6 +314,185 @@ async function rotateClient(token, id) {
|
|||||||
return { id, secret: data.client_secret };
|
return { id, secret: data.client_secret };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── 5. Seed the SSO directory with the stack's own resources ────────────────
|
||||||
|
// The Directory page (site → host → service hierarchy) starts empty even
|
||||||
|
// though this stack knows exactly what it deployed. Seed it: one site (the
|
||||||
|
// domain), one host (the box this stack runs on), and the two services
|
||||||
|
// (SSO Manager + proxy), then link the proxy's OAuth client under its
|
||||||
|
// service. Idempotent — existing slugs are left untouched, so operator
|
||||||
|
// edits (renames, metadata, extra resources) survive re-runs. Failures
|
||||||
|
// here only warn: the directory is a nicety, never worth failing a
|
||||||
|
// bring-up over (e.g. an older sso-manager image without /api/directory).
|
||||||
|
const DOMAIN = (sso.stack && sso.stack.ldapDomain) || '';
|
||||||
|
const ORG = sso.name || 'SSO Manager';
|
||||||
|
|
||||||
|
const slugify = (s) => s.toLowerCase().replace(/[^a-z0-9]+/g, '-').replace(/^-|-$/g, '');
|
||||||
|
|
||||||
|
async function dirGet(token, path) {
|
||||||
|
const res = await fetch(`${SSO_INTERNAL}/api/directory-admin/${path}`, {
|
||||||
|
headers: { 'auth-token': token },
|
||||||
|
});
|
||||||
|
if (!res.ok) throw new Error(`GET /api/directory-admin/${path} failed (${res.status})`);
|
||||||
|
return res.json();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function dirPost(token, path, body) {
|
||||||
|
const res = await fetch(`${SSO_INTERNAL}/api/directory-admin/${path}`, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'auth-token': token, 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify(body),
|
||||||
|
});
|
||||||
|
if (!res.ok) {
|
||||||
|
const text = await res.text().catch(() => '');
|
||||||
|
throw new Error(`POST /api/directory-admin/${path} failed (${res.status}): ${text}`);
|
||||||
|
}
|
||||||
|
return res.json();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function dirPut(token, path, body) {
|
||||||
|
const res = await fetch(`${SSO_INTERNAL}/api/directory-admin/${path}`, {
|
||||||
|
method: 'PUT',
|
||||||
|
headers: { 'auth-token': token, 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify(body),
|
||||||
|
});
|
||||||
|
if (!res.ok) {
|
||||||
|
const text = await res.text().catch(() => '');
|
||||||
|
throw new Error(`PUT /api/directory-admin/${path} failed (${res.status}): ${text}`);
|
||||||
|
}
|
||||||
|
return res.json();
|
||||||
|
}
|
||||||
|
|
||||||
|
// The site the stack registers itself under. Also the default "Location
|
||||||
|
// (Site)" that ldap-client-joined Linux hosts attach to (parent slug
|
||||||
|
// site_<name> — see ldap-client/index.sh), so the slugs must line up.
|
||||||
|
const SITE_NAME = (sso.stack && sso.stack.siteName) || 'local';
|
||||||
|
|
||||||
|
// Host facts, collected by setup.sh ON THE HOST (inside this container
|
||||||
|
// hostname/uname describe the container) and passed via the exec env. Same
|
||||||
|
// fields ldap-client/index.sh registers, so stack hosts and ldap-client-
|
||||||
|
// joined hosts carry identical metadata.
|
||||||
|
const HOST_FACTS = {
|
||||||
|
name: process.env.STACK_HOST_NAME || '',
|
||||||
|
ip: process.env.STACK_HOST_IP || '',
|
||||||
|
mac: process.env.STACK_HOST_MAC || '',
|
||||||
|
os: process.env.STACK_HOST_OS || '',
|
||||||
|
kernel: process.env.STACK_HOST_KERNEL || '',
|
||||||
|
};
|
||||||
|
|
||||||
|
async function seedDirectory(token, clientId, jumpClientId) {
|
||||||
|
let resources = ((await dirGet(token, 'resources')).results) || [];
|
||||||
|
|
||||||
|
// Create a resource unless its slug (or a legacy alternate from an earlier
|
||||||
|
// seed layout) already exists. On an existing resource, seed metadata keys
|
||||||
|
// it doesn't have yet are filled in — operator-set values always win and
|
||||||
|
// are never overwritten.
|
||||||
|
async function ensure(kind, name, slug, parentId, metadata, altSlugs) {
|
||||||
|
const slugs = [slug, ...(altSlugs || [])];
|
||||||
|
const found = resources.find((r) => slugs.includes(r.slug));
|
||||||
|
if (found) {
|
||||||
|
const have = found.metadata || {};
|
||||||
|
const missing = Object.entries(metadata || {})
|
||||||
|
.filter(([k, v]) => (have[k] === undefined || have[k] === '') && v !== '');
|
||||||
|
if (missing.length) {
|
||||||
|
const merged = { ...have };
|
||||||
|
for (const [k, v] of missing) merged[k] = v;
|
||||||
|
// metadata-only PUT: no kind/hostId in the body, so the route's
|
||||||
|
// parent validation and edge rewiring are not triggered.
|
||||||
|
await dirPut(token, `resources/${found.id}`, { metadata: merged });
|
||||||
|
found.metadata = merged;
|
||||||
|
log(` directory: ${kind} '${found.slug}' exists — filled ${missing.map(([k]) => k).join(', ')}`);
|
||||||
|
} else {
|
||||||
|
log(` directory: ${kind} '${found.slug}' exists — keeping`);
|
||||||
|
}
|
||||||
|
return found;
|
||||||
|
}
|
||||||
|
const body = { kind, name, slug, metadata: metadata || {} };
|
||||||
|
if (parentId) body.hostId = parentId; // POST creates the parent edge
|
||||||
|
const created = (await dirPost(token, 'resources', body)).results;
|
||||||
|
resources.push(created);
|
||||||
|
log(` directory: created ${kind} '${slug}'`);
|
||||||
|
return created;
|
||||||
|
}
|
||||||
|
|
||||||
|
// site_<name> / host_<name> slug convention matches ldap-client/index.sh.
|
||||||
|
// altSlugs grandfather in the layout the first seed release used.
|
||||||
|
const site = await ensure('site', SITE_NAME, `site_${slugify(SITE_NAME)}`, null,
|
||||||
|
{ isCurrentSite: true },
|
||||||
|
[slugify(DOMAIN || ORG)]);
|
||||||
|
const hostSlug = HOST_FACTS.name ? `host_${slugify(HOST_FACTS.name)}` : 'stack-host';
|
||||||
|
const host = await ensure('host', HOST_FACTS.name || 'Stack host', hostSlug, site.id, {
|
||||||
|
subType: 'linux',
|
||||||
|
ip: HOST_FACTS.ip,
|
||||||
|
macAddress: HOST_FACTS.mac,
|
||||||
|
os: HOST_FACTS.os,
|
||||||
|
kernel: HOST_FACTS.kernel,
|
||||||
|
}, ['stack-host']);
|
||||||
|
await ensure('service', 'SSO Manager', 'sso-manager', host.id, {
|
||||||
|
address: `https://${SSO_HOST}`,
|
||||||
|
port: 3001,
|
||||||
|
gitRepo: 'https://github.com/theta42/sso-manager-node',
|
||||||
|
subType: 'web',
|
||||||
|
});
|
||||||
|
// Proxy = the node management UI; OpenResty = the data plane every hostname
|
||||||
|
// in the stack actually flows through (80/443). Two faces, two entries.
|
||||||
|
const psvc = await ensure('service', 'Proxy', 'proxy', host.id, {
|
||||||
|
address: `https://${PROXY_HOST}`,
|
||||||
|
port: 3000,
|
||||||
|
gitRepo: 'https://github.com/theta42/proxy',
|
||||||
|
subType: 'web',
|
||||||
|
});
|
||||||
|
// OpenLDAP is independently consumed — Linux hosts authenticate against it
|
||||||
|
// (PAM/SSSD, sudoRole, sshPublicKey) and LDAP-native apps bind directly
|
||||||
|
// (see the SSO's /integrations page) — so it gets its own entry. Advertise
|
||||||
|
// the operator-configured LDAPS hostname when set, else the SSO host.
|
||||||
|
// The bundled slapd's image/config live in sso-manager-node.
|
||||||
|
const LDAPS_HOST = (sso.ldap && sso.ldap.ldapsHost) || SSO_HOST;
|
||||||
|
await ensure('service', 'OpenLDAP Directory', 'openldap', host.id, {
|
||||||
|
address: `ldaps://${LDAPS_HOST}:636`,
|
||||||
|
port: 389,
|
||||||
|
externalPort: 636,
|
||||||
|
gitRepo: 'https://github.com/theta42/sso-manager-node',
|
||||||
|
subType: 'openldap',
|
||||||
|
});
|
||||||
|
// Wildcard address: OpenResty fronts every host under the domain (same
|
||||||
|
// */** wildcard convention the proxy's Host records use). Its config lives
|
||||||
|
// in the proxy repo (ops/nginx_conf).
|
||||||
|
await ensure('service', 'OpenResty Edge', 'openresty', host.id, {
|
||||||
|
address: DOMAIN ? `https://*.${DOMAIN}` : `https://${PROXY_HOST}`,
|
||||||
|
port: 443,
|
||||||
|
gitRepo: 'https://github.com/theta42/proxy',
|
||||||
|
subType: 'openresty',
|
||||||
|
});
|
||||||
|
|
||||||
|
// Optional SSH jump host service.
|
||||||
|
let jumpSvc = null;
|
||||||
|
if (/^(1|true|yes)$/i.test(process.env.CFG_JUMP_HOST_ENABLED || '')) {
|
||||||
|
const jumpHost = process.env.CFG_JUMP_HOST || (DOMAIN ? `jump.${DOMAIN}` : '');
|
||||||
|
jumpSvc = await ensure('service', 'SSH Jump Host', 'jump-host', host.id, {
|
||||||
|
address: jumpHost ? `https://${jumpHost}` : '',
|
||||||
|
port: 3002,
|
||||||
|
gitRepo: 'https://github.com/theta42/jump-host',
|
||||||
|
subType: 'ssh',
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Link an OAuth client (Resource-backed since sso-manager 1.3.0) under its
|
||||||
|
// owning service, if it appears in the directory and isn't linked yet.
|
||||||
|
async function linkOauthClient(id, parent, label) {
|
||||||
|
if (!id || !parent) return;
|
||||||
|
const oauthRes = resources.find((r) => r.id === id);
|
||||||
|
if (!oauthRes) return;
|
||||||
|
const edges = ((await dirGet(token, 'edges')).results) || [];
|
||||||
|
const linked = edges.some((e) => e.childId === id);
|
||||||
|
if (!linked) {
|
||||||
|
await dirPost(token, 'edges', { parentId: parent.id, childId: id, relation: 'oauth' });
|
||||||
|
log(` directory: linked OAuth client under '${label}'`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
await linkOauthClient(clientId, psvc, 'proxy');
|
||||||
|
await linkOauthClient(jumpClientId, jumpSvc, 'jump-host');
|
||||||
|
}
|
||||||
|
|
||||||
// Write the OAuth client creds back into /config/proxy-secrets.js so the proxy
|
// Write the OAuth client creds back into /config/proxy-secrets.js so the proxy
|
||||||
// (which reads that file) can use them. Only the clientId/clientSecret lines
|
// (which reads that file) can use them. Only the clientId/clientSecret lines
|
||||||
// are touched; the rest of the file (operator edits, comments) is preserved.
|
// are touched; the rest of the file (operator edits, comments) is preserved.
|
||||||
@@ -298,6 +523,148 @@ function writeProxyCreds(id, secret) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── 6. Optional: provision the SSH jump host ────────────────────────────────
|
||||||
|
// When CFG_JUMP_HOST_ENABLED=true, the jump host needs: a directory API token
|
||||||
|
// (to resolve which hosts a user may reach), an LDAP bind account that can
|
||||||
|
// WRITE the sshPublicKey attribute (it injects its own key on first use), and
|
||||||
|
// a config file it reads. We write /config/jump-secrets.js deriving LDAP/site
|
||||||
|
// from sso-secrets.js + a freshly minted API token. The bundled jump host
|
||||||
|
// binds as cn=admin (already able to write sshPublicKey) — hardened bare-metal
|
||||||
|
// deployments should use a scoped account + attribute ACL instead (see the
|
||||||
|
// jump-host README). Idempotent: skips if the file already has a real token.
|
||||||
|
const JUMP_ENABLED = /^(1|true|yes)$/i.test(process.env.CFG_JUMP_HOST_ENABLED || '');
|
||||||
|
const JUMP_HOST = process.env.CFG_JUMP_HOST || (DOMAIN ? `jump.${DOMAIN}` : '');
|
||||||
|
const JUMP_SECRETS = '/config/jump-secrets.js';
|
||||||
|
const JUMP_TOKEN_NAME = 'theta-jump-host';
|
||||||
|
const JUMP_CLIENT_NAME = 'theta-jump';
|
||||||
|
const JUMP_REDIRECT_URI = `https://${JUMP_HOST}/api/auth/oidc/callback`;
|
||||||
|
|
||||||
|
async function mintApiToken(token, name) {
|
||||||
|
const res = await fetch(`${SSO_INTERNAL}/api/api-token`, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'auth-token': token, 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify({ name, description: 'theta-env jump host (auto-registered)' }),
|
||||||
|
});
|
||||||
|
if (!res.ok) throw new Error(`mint API token failed (${res.status}): ${await res.text().catch(() => '')}`);
|
||||||
|
const data = await res.json();
|
||||||
|
const raw = data.token || (data.results && data.results.token) || data.raw_token;
|
||||||
|
if (!raw) throw new Error(`API token response had no token: ${JSON.stringify(data)}`);
|
||||||
|
return raw;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The generated file is "complete" only if it has BOTH a real directory API
|
||||||
|
// token AND an OIDC client id — an existing file from the pre-OIDC layout (a
|
||||||
|
// token but no oidc block) is regenerated so the web UI's SSO login works.
|
||||||
|
function jumpFileComplete() {
|
||||||
|
try {
|
||||||
|
const src = fs.readFileSync(JUMP_SECRETS, 'utf8');
|
||||||
|
const hasToken = /apiToken:\s*['"]sso_[0-9a-f]{24}_[0-9a-f]{48}['"]/.test(src);
|
||||||
|
const hasOidc = /clientId:\s*['"][0-9a-f-]{8,}['"]/.test(src);
|
||||||
|
return hasToken && hasOidc;
|
||||||
|
} catch (_) { return false; }
|
||||||
|
}
|
||||||
|
|
||||||
|
function writeJumpSecrets(apiToken, oidc, localAdminPass) {
|
||||||
|
const siteName = (sso.stack && sso.stack.siteName) || 'local';
|
||||||
|
const ldapsHost = (sso.ldap && sso.ldap.ldapsHost) || SSO_HOST;
|
||||||
|
const body = `'use strict';
|
||||||
|
// Generated by theta-env bootstrap. The jump host reads this via
|
||||||
|
// @simpleworkjs/conf (CONF_SECRETS). Binds as cn=admin so it can write the
|
||||||
|
// sshPublicKey attribute (key injection); for a hardened deployment use a
|
||||||
|
// scoped account with an sshPublicKey write-ACL instead (see jump-host README).
|
||||||
|
module.exports = {
|
||||||
|
\tname: ${JSON.stringify(sso.name || 'SSO Manager')},
|
||||||
|
\tldap: {
|
||||||
|
\t\t// ldaps:// (636), not ldap:// (389): @simpleworkjs/ldap's client always
|
||||||
|
\t\t// sets tlsOptions (see jump-host's models/user_ldap.js), and ldapts
|
||||||
|
\t\t// treats a non-empty tlsOptions as "use implicit TLS" regardless of the
|
||||||
|
\t\t// URL scheme -- pointed at the plain port, that means it opens a raw TLS
|
||||||
|
\t\t// handshake against a server expecting plaintext LDAP, which slapd just
|
||||||
|
\t\t// drops (logged as "connection lost", no BIND ever attempted). This bit
|
||||||
|
\t\t// jump-host silently: every SSH login failed with the generic
|
||||||
|
\t\t// "Permission denied" for any password, because getUser()/checkPassword()
|
||||||
|
\t\t// never even reached slapd.
|
||||||
|
\t\turl: 'ldaps://sso-manager:636',
|
||||||
|
\t\tbindDN: ${JSON.stringify(BIND_DN)},
|
||||||
|
\t\tbindPassword: ${JSON.stringify(ADMIN_PASS)},
|
||||||
|
\t\tuserBase: ${JSON.stringify(`ou=people,${BASE_DN}`)},
|
||||||
|
\t\tgroupBase: ${JSON.stringify(`ou=groups,${BASE_DN}`)},
|
||||||
|
\t\ttlsOptions: { rejectUnauthorized: false },
|
||||||
|
\t},
|
||||||
|
\tsso: {
|
||||||
|
\t\turl: 'http://sso-manager:3001',
|
||||||
|
\t\tapiToken: ${JSON.stringify(apiToken)},
|
||||||
|
\t},
|
||||||
|
\tssh: {
|
||||||
|
\t\tlistenPort: 2222,
|
||||||
|
\t\thostKeyPath: '/var/lib/jump-host/keys',
|
||||||
|
\t\tpasswordAuth: 'off',
|
||||||
|
\t\tkeyComment: ${JSON.stringify(`jump-host@${siteName}`)},
|
||||||
|
\t},
|
||||||
|
\tweb: { port: 3002 },
|
||||||
|
\t// Web UI SSO login — the jump host's own OAuth client. tokenEndpoint /
|
||||||
|
\t// userinfoEndpoint use the internal docker-net address (server-to-server);
|
||||||
|
\t// authorizationEndpoint is the public SSO host (browser-facing).
|
||||||
|
\toidc: {
|
||||||
|
\t\tenabled: true,
|
||||||
|
\t\tissuer: ${JSON.stringify(`https://${SSO_HOST}`)},
|
||||||
|
\t\tauthorizationEndpoint: ${JSON.stringify(`https://${SSO_HOST}/oauth/authorize`)},
|
||||||
|
\t\ttokenEndpoint: 'http://sso-manager:3001/oauth/token',
|
||||||
|
\t\tuserinfoEndpoint: 'http://sso-manager:3001/oauth/userinfo',
|
||||||
|
\t\tclientId: ${JSON.stringify(oidc.id)},
|
||||||
|
\t\tclientSecret: ${JSON.stringify(oidc.secret)},
|
||||||
|
\t\tredirectUri: ${JSON.stringify(JUMP_REDIRECT_URI)},
|
||||||
|
\t\tscopes: ['openid', 'profile', 'email', 'groups'],
|
||||||
|
\t\tgroupsClaim: 'groups',
|
||||||
|
\t\tusernameClaim: 'preferred_username',
|
||||||
|
\t},
|
||||||
|
\tauth: {
|
||||||
|
\t\tadminGroups: ['app_sso_admin'],
|
||||||
|
\t\tadminUsers: ['jumpadmin'],
|
||||||
|
\t\tlocalAdminPass: ${JSON.stringify(localAdminPass)},
|
||||||
|
\t},
|
||||||
|
\tredis: { prefix: 'jump_host_', redisConf: { url: 'redis://127.0.0.1:6379' } },
|
||||||
|
\tstack: { ssoHost: ${JSON.stringify(SSO_HOST)}, jumpHost: ${JSON.stringify(JUMP_HOST)}, ldapsHost: ${JSON.stringify(ldapsHost)} },
|
||||||
|
};
|
||||||
|
`;
|
||||||
|
fs.writeFileSync(JUMP_SECRETS, body, { mode: 0o600 });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Returns the jump host's OAuth client id (so seedDirectory can link it under
|
||||||
|
// the SSH Jump Host service), whether or not this run actually wrote a fresh
|
||||||
|
// jump-secrets.js -- otherwise re-runs on an already-configured deployment
|
||||||
|
// never get a chance to self-heal a missing directory link (see the "no
|
||||||
|
// parent" bug this was written for).
|
||||||
|
async function provisionJumpHost(token) {
|
||||||
|
if (jumpFileComplete()) {
|
||||||
|
log('Jump host: /config/jump-secrets.js already has API token + OIDC client — keeping.');
|
||||||
|
const clients = await listClients(token);
|
||||||
|
const existing = clients.find((c) => c.name === JUMP_CLIENT_NAME);
|
||||||
|
return existing ? existing.client_id : null;
|
||||||
|
}
|
||||||
|
const apiToken = await mintApiToken(token, JUMP_TOKEN_NAME);
|
||||||
|
|
||||||
|
// Mint (or reuse) the jump host's own OAuth client for web-UI SSO login.
|
||||||
|
const clients = await listClients(token);
|
||||||
|
let oidc = clients.find((c) => c.name === JUMP_CLIENT_NAME);
|
||||||
|
if (oidc && oidc.client_id) {
|
||||||
|
oidc = await rotateClient(token, oidc.client_id);
|
||||||
|
oidc = { id: oidc.id, secret: oidc.secret };
|
||||||
|
} else {
|
||||||
|
oidc = await createClient(token, {
|
||||||
|
name: JUMP_CLIENT_NAME,
|
||||||
|
description: 'theta-env jump host web UI (auto-registered)',
|
||||||
|
redirect_uris: [JUMP_REDIRECT_URI],
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const localAdminPass = crypto.randomBytes(16).toString('hex');
|
||||||
|
writeJumpSecrets(apiToken, oidc, localAdminPass);
|
||||||
|
log(`Jump host: wrote /config/jump-secrets.js (API token + OAuth client ${oidc.id}).`);
|
||||||
|
log(`Jump host: local admin 'jumpadmin' password: ${localAdminPass}`);
|
||||||
|
return oidc.id;
|
||||||
|
}
|
||||||
|
|
||||||
(async function main() {
|
(async function main() {
|
||||||
try {
|
try {
|
||||||
log(`Base DN: ${BASE_DN}`);
|
log(`Base DN: ${BASE_DN}`);
|
||||||
@@ -307,6 +674,7 @@ function writeProxyCreds(id, secret) {
|
|||||||
|
|
||||||
const list = await listClients(token);
|
const list = await listClients(token);
|
||||||
// Find the proxy's client: by id if we have usable creds, else by name.
|
// Find the proxy's client: by id if we have usable creds, else by name.
|
||||||
|
let resolvedClientId = '';
|
||||||
let client = null;
|
let client = null;
|
||||||
if (HAS_USABLE_CREDS) client = list.find((c) => c.client_id === EXISTING_ID);
|
if (HAS_USABLE_CREDS) client = list.find((c) => c.client_id === EXISTING_ID);
|
||||||
if (!client) client = list.find((c) => c.name === CLIENT_NAME);
|
if (!client) client = list.find((c) => c.name === CLIENT_NAME);
|
||||||
@@ -319,6 +687,7 @@ function writeProxyCreds(id, secret) {
|
|||||||
out('CLIENT_ID', EXISTING_ID);
|
out('CLIENT_ID', EXISTING_ID);
|
||||||
out('CLIENT_SECRET', EXISTING_SECRET);
|
out('CLIENT_SECRET', EXISTING_SECRET);
|
||||||
out('ALREADY_CONFIGURED', '1');
|
out('ALREADY_CONFIGURED', '1');
|
||||||
|
resolvedClientId = EXISTING_ID;
|
||||||
} else if (client) {
|
} else if (client) {
|
||||||
// Client exists but the file has no recoverable secret for it — rotate
|
// Client exists but the file has no recoverable secret for it — rotate
|
||||||
// so the proxy gets a fresh secret it can actually read, then write back.
|
// so the proxy gets a fresh secret it can actually read, then write back.
|
||||||
@@ -328,6 +697,7 @@ function writeProxyCreds(id, secret) {
|
|||||||
out('CLIENT_ID', id);
|
out('CLIENT_ID', id);
|
||||||
out('CLIENT_SECRET', secret);
|
out('CLIENT_SECRET', secret);
|
||||||
out('ALREADY_CONFIGURED', '0');
|
out('ALREADY_CONFIGURED', '0');
|
||||||
|
resolvedClientId = id;
|
||||||
} else {
|
} else {
|
||||||
// No client yet — create one and write the generated creds back.
|
// No client yet — create one and write the generated creds back.
|
||||||
const { id, secret } = await createClient(token);
|
const { id, secret } = await createClient(token);
|
||||||
@@ -335,7 +705,45 @@ function writeProxyCreds(id, secret) {
|
|||||||
out('CLIENT_ID', id);
|
out('CLIENT_ID', id);
|
||||||
out('CLIENT_SECRET', secret);
|
out('CLIENT_SECRET', secret);
|
||||||
out('ALREADY_CONFIGURED', '0');
|
out('ALREADY_CONFIGURED', '0');
|
||||||
|
resolvedClientId = id;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Mirror the (now-current) proxy-secrets.js into OpenBao so the proxy
|
||||||
|
// loads it from there at boot via @simpleworkjs/bao-conf. Re-require
|
||||||
|
// fresh: writeProxyCreds rewrote the file out from under the cached
|
||||||
|
// `proxy` object. setup.sh's seed already put a placeholder version
|
||||||
|
// here; this replaces it with the complete file (operator edits +
|
||||||
|
// generated OAuth creds). Warn-only.
|
||||||
|
await baoPut('proxy/conf', freshRequire('/config/proxy-secrets.js'));
|
||||||
|
|
||||||
|
// Provision the jump host (mint token + write config) when enabled.
|
||||||
|
// Warn-only — never fail the whole bring-up over the optional service.
|
||||||
|
let jumpClientId = null;
|
||||||
|
if (JUMP_ENABLED) {
|
||||||
|
try {
|
||||||
|
jumpClientId = await provisionJumpHost(token);
|
||||||
|
out('JUMP_HOST_CONFIGURED', '1');
|
||||||
|
// Mirror jump-secrets.js (just written by provisionJumpHost)
|
||||||
|
// into OpenBao so the jump host loads it from there at boot via
|
||||||
|
// @simpleworkjs/bao-conf. setup.sh's seed may have put a
|
||||||
|
// placeholder/stale version here; this replaces it with the
|
||||||
|
// complete file (LDAP bind, minted API token, OAuth client).
|
||||||
|
// Warn-only.
|
||||||
|
await baoPut('jump-host/conf', freshRequire(JUMP_SECRETS));
|
||||||
|
} catch (e) {
|
||||||
|
log(`WARNING: jump host provisioning failed (${e.message || e}) — continuing`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Seed the directory (site/host/services + OAuth client link). Never
|
||||||
|
// fails the bootstrap — warn and continue.
|
||||||
|
try {
|
||||||
|
log('Seeding directory resources...');
|
||||||
|
await seedDirectory(token, resolvedClientId, jumpClientId);
|
||||||
|
} catch (e) {
|
||||||
|
log(`WARNING: directory seed failed (${e.message || e}) — continuing`);
|
||||||
|
}
|
||||||
|
|
||||||
log('Done.');
|
log('Done.');
|
||||||
process.exit(0);
|
process.exit(0);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
# ldap-client config for the optional local jump-host test fixture
|
||||||
|
# (ldap-test-host service in docker-compose.yml, jump-host compose profile).
|
||||||
|
# Copy to ./config/ldap-test-host.vars and fill in the bind password from
|
||||||
|
# your own ./config/sso-secrets.js's `serviceAccountPass` (the
|
||||||
|
# cn=ldapclient,ou=people,<base> service account bootstrap/bootstrap.js
|
||||||
|
# creates specifically for this kind of 3rd-party/container LDAP bind).
|
||||||
|
#
|
||||||
|
# This is what lets ldap-test-host be a REAL SSSD+AuthorizedKeysCommand-joined
|
||||||
|
# downstream host, so jump-host's key-injection -> upstream-connect flow can
|
||||||
|
# be exercised end-to-end against something more than a container with a
|
||||||
|
# manually-dropped public key in authorized_keys.
|
||||||
|
export ldap_host="sso-manager"
|
||||||
|
export ldap_base_dn="dc=localtest,dc=me"
|
||||||
|
|
||||||
|
export ldap_bind_dn="cn=ldapclient,ou=People,$ldap_base_dn"
|
||||||
|
export ldap_bind_password="REPLACE_WITH_serviceAccountPass_FROM_sso-secrets.js"
|
||||||
|
|
||||||
|
# sso_url/sso_token deliberately left unset -- register the host + access
|
||||||
|
# group manually via the Directory admin API instead (index.sh's optional
|
||||||
|
# auto-registration also wants a parent site Resource to exist first).
|
||||||
|
# index.sh gates that block on `[[ -v sso_token ]]`, which is true even for
|
||||||
|
# an empty string, so leave these genuinely absent, not "".
|
||||||
|
|
||||||
|
export ldap_location="jumptest"
|
||||||
|
|
||||||
|
ldap_access_groups=( "${ldap_location}_access" "${ldap_location}_host_$(hostname)_access" )
|
||||||
@@ -17,6 +17,9 @@ module.exports = {
|
|||||||
bindPassword: 'CHANGE-ME', // slapd root + app bind password
|
bindPassword: 'CHANGE-ME', // slapd root + app bind password
|
||||||
userBase: 'ou=people,dc=example,dc=com',
|
userBase: 'ou=people,dc=example,dc=com',
|
||||||
groupBase: 'ou=groups,dc=example,dc=com',
|
groupBase: 'ou=groups,dc=example,dc=com',
|
||||||
|
// ldapsHost: 'ldap.internal.example.com', // optional: internal-only hostname
|
||||||
|
// shown on /integrations for direct LDAPS binds. Empty -> derive from issuer.
|
||||||
|
// ldapsPort: 636,
|
||||||
},
|
},
|
||||||
smtp: { // optional; leave host '' to skip
|
smtp: { // optional; leave host '' to skip
|
||||||
host: '', port: 587, secure: false,
|
host: '', port: 587, secure: false,
|
||||||
@@ -27,6 +30,16 @@ module.exports = {
|
|||||||
jwtSecret: 'CHANGE-ME', // signs all tokens — keep secret
|
jwtSecret: 'CHANGE-ME', // signs all tokens — keep secret
|
||||||
token_lifetime: { access_token: 3600, refresh_token: 2592000 },
|
token_lifetime: { access_token: 3600, refresh_token: 2592000 },
|
||||||
},
|
},
|
||||||
|
// Without this, @simpleworkjs/orm falls back to './config/inventory.sqlite'
|
||||||
|
// (relative to the app's /app cwd) -- inside the container's ephemeral
|
||||||
|
// layer, not any mounted volume, so every Resource/site/host/service/oauth
|
||||||
|
// row (the whole Directory Management page) would be silently wiped on
|
||||||
|
// every container recreate. /data is already a persisted volume (Redis
|
||||||
|
// lives there too), so this just co-locates the sqlite file with it.
|
||||||
|
orm: {
|
||||||
|
dialect: 'sqlite',
|
||||||
|
storage: '/data/inventory.sqlite',
|
||||||
|
},
|
||||||
|
|
||||||
// ── Orchestrator-only (ignored by the app; read by setup.sh + bootstrap) ──
|
// ── Orchestrator-only (ignored by the app; read by setup.sh + bootstrap) ──
|
||||||
stack: {
|
stack: {
|
||||||
|
|||||||
+139
-7
@@ -36,8 +36,16 @@ services:
|
|||||||
# setup.sh sets this from the host, where the submodule resolves
|
# setup.sh sets this from the host, where the submodule resolves
|
||||||
# correctly (git -C sso-manager-node rev-parse --short HEAD).
|
# correctly (git -C sso-manager-node rev-parse --short HEAD).
|
||||||
GIT_COMMIT: ${SSO_GIT_COMMIT:-}
|
GIT_COMMIT: ${SSO_GIT_COMMIT:-}
|
||||||
|
# Optional upstream HTTP(S) proxy for npm/apt during the build (NOT
|
||||||
|
# the theta42 "proxy" app). Set CFG_HTTP_PROXY in setup.env; empty by
|
||||||
|
# default, so this is a no-op unless configured.
|
||||||
|
HTTP_PROXY: ${CFG_HTTP_PROXY:-}
|
||||||
|
HTTPS_PROXY: ${CFG_HTTPS_PROXY:-}
|
||||||
|
NO_PROXY: ${CFG_NO_PROXY:-}
|
||||||
container_name: sso-manager
|
container_name: sso-manager
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
depends_on:
|
||||||
|
- openbao
|
||||||
networks: [theta-net]
|
networks: [theta-net]
|
||||||
ports:
|
ports:
|
||||||
# SSO web UI. Bind address is configurable via SSO_BIND (default 0.0.0.0 so
|
# SSO web UI. Bind address is configurable via SSO_BIND (default 0.0.0.0 so
|
||||||
@@ -46,14 +54,28 @@ services:
|
|||||||
- "${SSO_BIND:-0.0.0.0}:${SSO_PORT:-3001}:3001"
|
- "${SSO_BIND:-0.0.0.0}:${SSO_PORT:-3001}:3001"
|
||||||
# LDAPS for EXTERNAL direct-LDAP clients (legacy apps). The proxy itself
|
# LDAPS for EXTERNAL direct-LDAP clients (legacy apps). The proxy itself
|
||||||
# reaches LDAPS over theta-net (sso-manager:636) without this host mapping.
|
# reaches LDAPS over theta-net (sso-manager:636) without this host mapping.
|
||||||
|
# Prefer an internal-only hostname (set CFG_LDAPS_HOST in setup.env / ldapsHost
|
||||||
|
# in sso-secrets.js) and do NOT forward 636 to the public internet.
|
||||||
- "${LDAPS_PORT:-636}:636"
|
- "${LDAPS_PORT:-636}:636"
|
||||||
# Plain LDAP (389) is NOT mapped — direct-LDAP clients should use LDAPS.
|
# Plain LDAP (389) is NOT mapped — direct-LDAP clients should use LDAPS.
|
||||||
environment:
|
environment:
|
||||||
# Config (LDAP, OAuth, SMTP, ...) comes from ./config/sso-secrets.js (see
|
# Config (LDAP, OAuth, SMTP, ...) is loaded by @simpleworkjs/conf from
|
||||||
# volumes below), not from env. NODE_ENV/NODE_PORT are the only env the app
|
# ./config/sso-secrets.js (see volumes), then @simpleworkjs/bao-conf
|
||||||
# reads that are not part of its conf tree.
|
# deep-merges secret/sso-manager/conf from OpenBao over it at boot
|
||||||
|
# (VAULT_ADDR/VAULT_TOKEN below). NODE_ENV/NODE_PORT are the only other
|
||||||
|
# env the app reads. VAULT_TOKEN is the scoped SSO_VAULT_TOKEN minted by
|
||||||
|
# setup.sh (policy sso-broker) — NOT the root token.
|
||||||
- NODE_ENV=production
|
- NODE_ENV=production
|
||||||
- NODE_PORT=3001
|
- NODE_PORT=3001
|
||||||
|
- LDAP_SERVER_ID=${LDAP_SERVER_ID:-}
|
||||||
|
- LDAP_REPLICATION_HOSTS=${LDAP_REPLICATION_HOSTS:-}
|
||||||
|
- VAULT_ADDR=http://openbao:8200
|
||||||
|
- VAULT_TOKEN=${SSO_VAULT_TOKEN:-}
|
||||||
|
# Optional upstream HTTP(S) proxy for outbound calls (SMTP, etc.) at
|
||||||
|
# runtime. See the build args above for the same setting during build.
|
||||||
|
- HTTP_PROXY=${CFG_HTTP_PROXY:-}
|
||||||
|
- HTTPS_PROXY=${CFG_HTTPS_PROXY:-}
|
||||||
|
- NO_PROXY=${CFG_NO_PROXY:-}
|
||||||
volumes:
|
volumes:
|
||||||
# Operator-edited SSO secrets (sso-secrets.js). Read-WRITE so the bootstrap
|
# Operator-edited SSO secrets (sso-secrets.js). Read-WRITE so the bootstrap
|
||||||
# can write the generated OAuth client creds into proxy-secrets.js. The
|
# can write the generated OAuth client creds into proxy-secrets.js. The
|
||||||
@@ -87,12 +109,19 @@ services:
|
|||||||
# setup.sh sets this from the host, where the submodule resolves
|
# setup.sh sets this from the host, where the submodule resolves
|
||||||
# correctly (git -C proxy rev-parse --short HEAD).
|
# correctly (git -C proxy rev-parse --short HEAD).
|
||||||
GIT_COMMIT: ${PROXY_GIT_COMMIT:-}
|
GIT_COMMIT: ${PROXY_GIT_COMMIT:-}
|
||||||
|
# Optional upstream HTTP(S) proxy for npm/apt during the build. See
|
||||||
|
# the sso-manager service above for details.
|
||||||
|
HTTP_PROXY: ${CFG_HTTP_PROXY:-}
|
||||||
|
HTTPS_PROXY: ${CFG_HTTPS_PROXY:-}
|
||||||
|
NO_PROXY: ${CFG_NO_PROXY:-}
|
||||||
container_name: proxy
|
container_name: proxy
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
networks: [theta-net]
|
networks: [theta-net]
|
||||||
depends_on:
|
depends_on:
|
||||||
sso-manager:
|
sso-manager:
|
||||||
condition: service_healthy
|
condition: service_healthy
|
||||||
|
openbao:
|
||||||
|
condition: service_started
|
||||||
ports:
|
ports:
|
||||||
- "${HTTP_PORT:-80}:80"
|
- "${HTTP_PORT:-80}:80"
|
||||||
- "${HTTPS_PORT:-443}:443"
|
- "${HTTPS_PORT:-443}:443"
|
||||||
@@ -102,14 +131,28 @@ services:
|
|||||||
# to lock it to localhost once the proxy fronts it under TLS.
|
# to lock it to localhost once the proxy fronts it under TLS.
|
||||||
- "${MGMT_BIND:-0.0.0.0}:${MGMT_PORT:-3000}:3000"
|
- "${MGMT_BIND:-0.0.0.0}:${MGMT_PORT:-3000}:3000"
|
||||||
environment:
|
environment:
|
||||||
# oidc/ldap/auth config comes from ./config/proxy-secrets.js (see volumes),
|
# oidc/ldap/auth config is loaded by @simpleworkjs/conf from
|
||||||
# not from env. NODE_ENV/NODE_PORT are process env the app reads directly.
|
# ./config/proxy-secrets.js (see volumes), then @simpleworkjs/bao-conf
|
||||||
|
# deep-merges secret/proxy/conf from OpenBao over it at boot. The OAuth
|
||||||
|
# clientSecret is consumed at require time, so bao-conf.init() runs
|
||||||
|
# BEFORE require('../app') in bin/www. NODE_ENV/NODE_PORT are process env
|
||||||
|
# the app reads directly. VAULT_TOKEN is the scoped PROXY_VAULT_TOKEN
|
||||||
|
# (policy proxy — read only secret/proxy/conf).
|
||||||
- NODE_ENV=production
|
- NODE_ENV=production
|
||||||
- NODE_PORT=3000
|
- NODE_PORT=3000
|
||||||
|
- VAULT_ADDR=http://openbao:8200
|
||||||
|
- VAULT_TOKEN=${PROXY_VAULT_TOKEN:-}
|
||||||
|
# Optional upstream HTTP(S) proxy for outbound calls (ACME/Let's
|
||||||
|
# Encrypt, DNS providers) at runtime.
|
||||||
|
- HTTP_PROXY=${CFG_HTTP_PROXY:-}
|
||||||
|
- HTTPS_PROXY=${CFG_HTTPS_PROXY:-}
|
||||||
|
- NO_PROXY=${CFG_NO_PROXY:-}
|
||||||
volumes:
|
volumes:
|
||||||
# Operator-edited proxy secrets (proxy-secrets.js). READ-ONLY — the proxy
|
# Operator-edited proxy secrets (proxy-secrets.js). READ-ONLY — the proxy
|
||||||
# only reads it; the sso-manager bootstrap writes the OAuth creds. The
|
# only reads it; the sso-manager bootstrap writes the OAuth creds. The
|
||||||
# entrypoint points CONF_SECRETS at /config/proxy-secrets.js.
|
# entrypoint points CONF_SECRETS at /config/proxy-secrets.js. Kept as a
|
||||||
|
# fail-soft fallback: bao-conf.init() is fail-soft, so if OpenBao is
|
||||||
|
# unreachable the app boots from this file instead.
|
||||||
- ./config:/config:ro
|
- ./config:/config:ro
|
||||||
# Persist Redis (AOF + RDB) so Host records, permissions, DNS creds, local
|
# Persist Redis (AOF + RDB) so Host records, permissions, DNS creds, local
|
||||||
# users, AND the auto-ssl Let's Encrypt certs survive container recreation.
|
# users, AND the auto-ssl Let's Encrypt certs survive container recreation.
|
||||||
@@ -127,6 +170,92 @@ services:
|
|||||||
retries: 3
|
retries: 3
|
||||||
start_period: 30s
|
start_period: 30s
|
||||||
|
|
||||||
|
# Optional SSH jump host. Only started when the `jump-host` compose profile
|
||||||
|
# is active — setup.sh exports COMPOSE_PROFILES=jump-host when
|
||||||
|
# CFG_JUMP_HOST_ENABLED=true. Authenticates users against the SSO's OpenLDAP,
|
||||||
|
# resolves reachable hosts from the directory API, and bridges SSH through.
|
||||||
|
jump-host:
|
||||||
|
profiles: ["jump-host"]
|
||||||
|
build:
|
||||||
|
context: ./jump-host
|
||||||
|
dockerfile: Dockerfile
|
||||||
|
args:
|
||||||
|
GIT_COMMIT: ${JUMP_GIT_COMMIT:-}
|
||||||
|
# Optional upstream HTTP(S) proxy for npm/apt during the build. See
|
||||||
|
# the sso-manager service above for details.
|
||||||
|
HTTP_PROXY: ${CFG_HTTP_PROXY:-}
|
||||||
|
HTTPS_PROXY: ${CFG_HTTPS_PROXY:-}
|
||||||
|
NO_PROXY: ${CFG_NO_PROXY:-}
|
||||||
|
container_name: jump-host
|
||||||
|
restart: unless-stopped
|
||||||
|
networks: [theta-net]
|
||||||
|
depends_on:
|
||||||
|
sso-manager:
|
||||||
|
condition: service_healthy
|
||||||
|
openbao:
|
||||||
|
condition: service_started
|
||||||
|
ports:
|
||||||
|
- "${JUMP_SSH_PORT:-2222}:2222" # SSH front door
|
||||||
|
- "${JUMP_WEB_BIND:-0.0.0.0}:${JUMP_WEB_PORT:-3002}:3002" # web UI/API
|
||||||
|
environment:
|
||||||
|
- NODE_ENV=production
|
||||||
|
# Secrets are loaded by @simpleworkjs/conf from ./config/jump-secrets.js,
|
||||||
|
# then @simpleworkjs/bao-conf deep-merges secret/jump-host/conf from
|
||||||
|
# OpenBao over it at boot. VAULT_TOKEN is the scoped JUMP_VAULT_TOKEN
|
||||||
|
# (policy jump-host — read only secret/jump-host/conf).
|
||||||
|
- VAULT_ADDR=http://openbao:8200
|
||||||
|
- VAULT_TOKEN=${JUMP_VAULT_TOKEN:-}
|
||||||
|
# Optional upstream HTTP(S) proxy for outbound calls (the directory API
|
||||||
|
# client) at runtime.
|
||||||
|
- HTTP_PROXY=${CFG_HTTP_PROXY:-}
|
||||||
|
- HTTPS_PROXY=${CFG_HTTPS_PROXY:-}
|
||||||
|
- NO_PROXY=${CFG_NO_PROXY:-}
|
||||||
|
volumes:
|
||||||
|
- ./config:/config:ro # jump-secrets.js (written by ensure_config/bootstrap)
|
||||||
|
- jump-data:/var/lib/jump-host # generated host keys persist here
|
||||||
|
- jump-redis-data:/data # Redis (sessions, OAuth state, API tokens) persists here
|
||||||
|
|
||||||
|
# A real, LDAP-joined (SSSD + AuthorizedKeysCommand) downstream host for
|
||||||
|
# testing jump-host's actual key-injection -> upstream-connect flow --
|
||||||
|
# a container with a manually-dropped public key in authorized_keys never
|
||||||
|
# exercises the LDAP-key-serving path a real production host does. Built
|
||||||
|
# from the theta42/ldap-client submodule -- see ./config/ldap-test-host.vars
|
||||||
|
# for setup notes. Same jump-host profile, so
|
||||||
|
# `docker compose --profile jump-host up` brings up jump-host and a host it
|
||||||
|
# can actually reach together.
|
||||||
|
ldap-test-host:
|
||||||
|
profiles: ["jump-host"]
|
||||||
|
build:
|
||||||
|
context: ./ldap-client
|
||||||
|
dockerfile: Dockerfile
|
||||||
|
container_name: ldap-test-host
|
||||||
|
hostname: ldap-test-host
|
||||||
|
restart: unless-stopped
|
||||||
|
networks: [theta-net]
|
||||||
|
depends_on:
|
||||||
|
sso-manager:
|
||||||
|
condition: service_healthy
|
||||||
|
privileged: false
|
||||||
|
volumes:
|
||||||
|
- ./config/ldap-test-host.vars:/config/ldap.vars:ro
|
||||||
|
- ./config/ldap-ca.crt:/config/ldap-ca.crt:ro
|
||||||
|
|
||||||
|
openbao:
|
||||||
|
image: quay.io/openbao/openbao:latest
|
||||||
|
container_name: openbao
|
||||||
|
restart: unless-stopped
|
||||||
|
cap_add:
|
||||||
|
- IPC_LOCK
|
||||||
|
command: server -config=/vault/config/openbao.hcl
|
||||||
|
environment:
|
||||||
|
- BAO_ADDR=http://127.0.0.1:8200
|
||||||
|
ports:
|
||||||
|
- "8080:8200"
|
||||||
|
volumes:
|
||||||
|
- ./config/openbao.hcl:/vault/config/openbao.hcl:ro
|
||||||
|
- openbao-data:/vault/data
|
||||||
|
networks:
|
||||||
|
- theta-net
|
||||||
networks:
|
networks:
|
||||||
theta-net:
|
theta-net:
|
||||||
driver: bridge
|
driver: bridge
|
||||||
@@ -137,4 +266,7 @@ volumes:
|
|||||||
sso-data:
|
sso-data:
|
||||||
proxy-data:
|
proxy-data:
|
||||||
proxy-cache:
|
proxy-cache:
|
||||||
proxy-logs:
|
proxy-logs:
|
||||||
|
jump-data:
|
||||||
|
jump-redis-data:
|
||||||
|
openbao-data:
|
||||||
@@ -25,6 +25,9 @@ nav:
|
|||||||
- title: Architecture
|
- title: Architecture
|
||||||
page: /architecture.html
|
page: /architecture.html
|
||||||
icon: fa-sitemap
|
icon: fa-sitemap
|
||||||
|
- title: Secrets
|
||||||
|
page: /secrets.html
|
||||||
|
icon: fa-key
|
||||||
- title: Standalone
|
- title: Standalone
|
||||||
page: /standalone.html
|
page: /standalone.html
|
||||||
icon: fa-puzzle-piece
|
icon: fa-puzzle-piece
|
||||||
|
|||||||
@@ -31,7 +31,7 @@ fetches all three in one step; `git submodule update --remote` bumps them.
|
|||||||
|
|
||||||
```
|
```
|
||||||
┌──────────────────────────────────────────────┐
|
┌──────────────────────────────────────────────┐
|
||||||
│ your browser / apps / legacy LDAP clients │
|
│ your browser / apps / direct LDAP clients │
|
||||||
└───────────────┬──────────────────────────────┘
|
└───────────────┬──────────────────────────────┘
|
||||||
│ https (:443) ldaps (:636)
|
│ https (:443) ldaps (:636)
|
||||||
┌─────────▼─────────┐
|
┌─────────▼─────────┐
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 83 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 126 KiB After Width: | Height: | Size: 310 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 118 KiB After Width: | Height: | Size: 141 KiB |
+13
-2
@@ -15,7 +15,9 @@ LDAP directory) and [Proxy](https://theta42.github.io/proxy/) (an
|
|||||||
OIDC-protected reverse proxy that can also look users up directly in LDAP) —
|
OIDC-protected reverse proxy that can also look users up directly in LDAP) —
|
||||||
and automates the fiddly part: registering the proxy as an OIDC client of the
|
and automates the fiddly part: registering the proxy as an OIDC client of the
|
||||||
SSO and pointing it at the right LDAP directory, with hostnames and secrets
|
SSO and pointing it at the right LDAP directory, with hostnames and secrets
|
||||||
generated from one `setup.env`.
|
generated from one `setup.env`. An optional third component, the
|
||||||
|
[Jump Host](https://theta42.github.io/jump-host/), adds directory-driven SSH
|
||||||
|
access to your machines through one public entry point.
|
||||||
|
|
||||||
## Screenshots
|
## Screenshots
|
||||||
|
|
||||||
@@ -23,6 +25,7 @@ The SSO Manager and the proxy it fronts, both stood up by one `./setup.sh` run:
|
|||||||
|
|
||||||
<a href="images/sso-dashboard.png" target="_blank"><img src="images/sso-dashboard.png" alt="SSO Manager dashboard" width="49%"></a>
|
<a href="images/sso-dashboard.png" target="_blank"><img src="images/sso-dashboard.png" alt="SSO Manager dashboard" width="49%"></a>
|
||||||
<a href="images/proxy-hosts.png" target="_blank"><img src="images/proxy-hosts.png" alt="Proxy host list" width="49%"></a>
|
<a href="images/proxy-hosts.png" target="_blank"><img src="images/proxy-hosts.png" alt="Proxy host list" width="49%"></a>
|
||||||
|
<a href="images/jump-dashboard.png" target="_blank"><img src="images/jump-dashboard.png" alt="Jump Host dashboard" width="49%"></a>
|
||||||
|
|
||||||
*(click either screenshot to view full size)*
|
*(click either screenshot to view full size)*
|
||||||
|
|
||||||
@@ -41,9 +44,15 @@ snapshots state before every rebuild.
|
|||||||
- **SSO Manager**, fronted by the proxy under TLS — manage users, groups,
|
- **SSO Manager**, fronted by the proxy under TLS — manage users, groups,
|
||||||
and OAuth clients.
|
and OAuth clients.
|
||||||
- **Proxy** — add the hosts you want to protect with OIDC login.
|
- **Proxy** — add the hosts you want to protect with OIDC login.
|
||||||
- **LDAPS** for legacy apps that bind directly.
|
- **LDAPS** for direct binds — Linux hosts (PAM/SSSD, sudo, SSH keys) and
|
||||||
|
LDAP-native apps authenticate against the same directory.
|
||||||
|
- **SSH Jump Host** *(optional)* — `ssh uid_-_host@jump.<domain>` (WinSCP-friendly)
|
||||||
|
or an interactive picker; access is driven by directory group membership, with
|
||||||
|
a web UI for audit + metrics. Enable with `CFG_JUMP_HOST_ENABLED=true`.
|
||||||
- **Self-service API tokens** in both apps' UIs, for scripting/CI without a
|
- **Self-service API tokens** in both apps' UIs, for scripting/CI without a
|
||||||
browser session.
|
browser session.
|
||||||
|
- **Multi-Site Support (Geo-Location Scaling)** — built-in support for N-Way Multi-Master LDAP replication across physical locations.
|
||||||
|
- **Multi-target load balancing** — built-in proxy support for round-robin load balancing across multiple application servers.
|
||||||
|
|
||||||
## Get it
|
## Get it
|
||||||
|
|
||||||
@@ -65,3 +74,5 @@ architecture, and running each project standalone, see the
|
|||||||
provider + LDAP directory this stack runs.
|
provider + LDAP directory this stack runs.
|
||||||
- **[Proxy](https://theta42.github.io/proxy/)** — the reverse proxy this
|
- **[Proxy](https://theta42.github.io/proxy/)** — the reverse proxy this
|
||||||
stack runs in front of it.
|
stack runs in front of it.
|
||||||
|
- **[Jump Host](https://theta42.github.io/jump-host/)** — the optional SSH jump
|
||||||
|
host this stack can bring up (`CFG_JUMP_HOST_ENABLED=true`).
|
||||||
|
|||||||
@@ -60,6 +60,9 @@ setups `CFG_DOMAIN` is the only value you set:
|
|||||||
| `CFG_ADMIN_UID` | `admin` | optional, defaults to `admin` |
|
| `CFG_ADMIN_UID` | `admin` | optional, defaults to `admin` |
|
||||||
| `CFG_ADMIN_EMAIL` | `admin@<proxyHost>` | optional |
|
| `CFG_ADMIN_EMAIL` | `admin@<proxyHost>` | optional |
|
||||||
| `CFG_BASE_DN` | `dc=lab,dc=local` | advanced: override the derived LDAP base DN |
|
| `CFG_BASE_DN` | `dc=lab,dc=local` | advanced: override the derived LDAP base DN |
|
||||||
|
| `CFG_JUMP_HOST_ENABLED` | `true` | optional: bring up the [SSH jump host](https://theta42.github.io/jump-host/) (default off) |
|
||||||
|
| `CFG_JUMP_HOST` | `jump.lab.local` | optional, defaults to `jump.<domain>` |
|
||||||
|
| `JUMP_SSH_PORT` | `2222` | optional: host port for the jump host's SSH (never 22 by default) |
|
||||||
|
|
||||||
`setup.env` is used **only on the first run** to generate `./config/`; after
|
`setup.env` is used **only on the first run** to generate `./config/`; after
|
||||||
that `./config/*.js` are operator-owned and `setup.env` is ignored. Secrets
|
that `./config/*.js` are operator-owned and `setup.env` is ignored. Secrets
|
||||||
|
|||||||
+195
@@ -0,0 +1,195 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: Secrets (OpenBao)
|
||||||
|
description: theta-env's central secrets architecture — OpenBao as the single store for all app, per-user, and external-app secrets, with scoped tokens and policies.
|
||||||
|
---
|
||||||
|
|
||||||
|
# Secrets — OpenBao as the central store
|
||||||
|
|
||||||
|
theta-env keeps **every secret in one place: [OpenBao](https://openbao.org/)**
|
||||||
|
(a Vault-community fork), running on the `theta-net` docker network at
|
||||||
|
`http://openbao:8200`. The three apps (SSO Manager, proxy, jump host) load
|
||||||
|
their boot secrets from it; end users get personal per-user secret storage
|
||||||
|
through the SSO UI; and external apps get scoped, self-contained access to
|
||||||
|
their own namespace.
|
||||||
|
|
||||||
|
This page is the operator reference. For the package API, see
|
||||||
|
[@simpleworkjs/bao-conf](https://simpleworkjs.github.io/bao-conf/).
|
||||||
|
|
||||||
|
## Why a central store
|
||||||
|
|
||||||
|
Before this, secret handling was partial and inconsistent: only the SSO read
|
||||||
|
one path from OpenBao; the proxy and jump host read bind-mounted
|
||||||
|
`./config/*-secrets.js` files; the bootstrap wrote generated OAuth creds to
|
||||||
|
those files on disk; and the SSO `/api/vault` UI was an ungated, broken
|
||||||
|
pass-through. Centralising on OpenBao gives every app the same fail-soft load
|
||||||
|
path, makes per-user secret storage possible, and lets external apps get
|
||||||
|
least-privilege access without anyone handing them the root token.
|
||||||
|
|
||||||
|
## The load path (every app)
|
||||||
|
|
||||||
|
1. `@simpleworkjs/conf` **synchronously** loads the bind-mounted
|
||||||
|
`./config/<app>-secrets.js` at require time — the file is the operator-edit
|
||||||
|
layer and the fail-soft fallback.
|
||||||
|
2. `@simpleworkjs/bao-conf`'s `init({ path: '<app>', conf })` **deep-merges**
|
||||||
|
`secret/data/<app>/conf` from OpenBao over the live `conf` object. It is
|
||||||
|
**fail-soft**: if OpenBao is unreachable or the path is absent, boot
|
||||||
|
continues with the file-loaded config.
|
||||||
|
3. A few secrets are **captured at require time** (notably the OIDC
|
||||||
|
`clientSecret`, consumed inside `createOidcClient` during
|
||||||
|
`require('../models')`). So `init()` must resolve *before* that
|
||||||
|
`require()`. Each app's `bin/www` handles this:
|
||||||
|
- **proxy** — defers `require('../app')` (which transitively loads models)
|
||||||
|
behind `bao-conf.init()`.
|
||||||
|
- **jump host** — gates the explicit `require('../models')` behind
|
||||||
|
`bao-conf.init()`.
|
||||||
|
- **SSO** — swaps the old `conf_manager.init()` call (same position in its
|
||||||
|
existing `.then()` boot chain) for `bao-conf.init()`; nothing in the SSO
|
||||||
|
captures a secret at require time, so no reordering was needed.
|
||||||
|
|
||||||
|
`VAULT_TOKEN` (a scoped per-app token, **not** the root token) and
|
||||||
|
`VAULT_ADDR=http://openbao:8200` are passed to each container via
|
||||||
|
`docker-compose.yml`. The `./config/*-secrets.js` mounts stay as the fallback.
|
||||||
|
|
||||||
|
## Policies, token role, and tokens
|
||||||
|
|
||||||
|
`setup.sh` creates the ACL policies and mints the per-app tokens
|
||||||
|
(idempotently — re-running keeps existing tokens and re-mints only expired
|
||||||
|
ones). The root token stays in `.env` for setup/maintenance **only** and is
|
||||||
|
never passed to a service container.
|
||||||
|
|
||||||
|
| Policy | Capabilities | Held by |
|
||||||
|
|---|---|---|
|
||||||
|
| `sso-broker` | read/write `secret/sso-manager/conf`, `secret/users/*`, `secret/apps/*`; `update` on `auth/token/create/sso-broker`; `update` on `sys/policies/acl/user-*`, `app-*`, `sso-admin` | SSO (`SSO_VAULT_TOKEN`) |
|
||||||
|
| `sso-admin` | read/write/list all of `secret/*` | admin UI sessions (minted by the broker) |
|
||||||
|
| `proxy` | read `secret/proxy/conf` | proxy (`PROXY_VAULT_TOKEN`) |
|
||||||
|
| `jump-host` | read `secret/jump-host/conf` | jump host (`JUMP_VAULT_TOKEN`) |
|
||||||
|
| `user-<uid>` | read/write `secret/users/<uid>/*` | per-user tokens (minted lazily by the broker) |
|
||||||
|
| `app-<name>` | read/write `secret/apps/<name>/*` | per-external-app tokens (minted by an admin) |
|
||||||
|
|
||||||
|
**Token role `sso-broker`** — `allowed_policies=sso-admin`,
|
||||||
|
`allowed_policies_glob=user-*,app-*`, orphan, renewable, `token_period=24h`.
|
||||||
|
The SSO mints per-user, per-admin, and per-app tokens *through* this role at
|
||||||
|
runtime, so it never needs the root token to issue scoped access.
|
||||||
|
|
||||||
|
The three per-app tokens (`SSO_VAULT_TOKEN`, `PROXY_VAULT_TOKEN`,
|
||||||
|
`JUMP_VAULT_TOKEN`) are minted orphan + renewable and stored in `./.env` by
|
||||||
|
`setup.sh`. They use OpenBao's default service-token TTL; if one expires,
|
||||||
|
re-run `./setup.sh` and the `ensure_token` helper re-mints it (the old one
|
||||||
|
expires on its own). Automated renewal is a planned follow-up, not yet built.
|
||||||
|
|
||||||
|
## Seeding
|
||||||
|
|
||||||
|
`setup.sh` seeds, on first run only (skipped if the path already exists):
|
||||||
|
|
||||||
|
- `secret/sso-manager/conf` — from `./config/sso-secrets.js` (operator-set
|
||||||
|
LDAP/SMTP/`jwtSecret`; the SSO has no bootstrap-generated creds, so the file
|
||||||
|
is the complete source of truth).
|
||||||
|
- `secret/proxy/conf` — from `./config/proxy-secrets.js` (placeholder OAuth
|
||||||
|
creds at this point).
|
||||||
|
- `secret/jump-host/conf` — from `./config/jump-secrets.js` after the bootstrap
|
||||||
|
writes it.
|
||||||
|
|
||||||
|
The **bootstrap** (`bootstrap/bootstrap.js`) then generates the real OAuth
|
||||||
|
client credentials and writes the *complete* `proxy-secrets.js` and
|
||||||
|
`jump-secrets.js` objects into `secret/proxy/conf` and `secret/jump-host/conf`
|
||||||
|
(POST, replacing the placeholder seed). After the first run, OpenBao is
|
||||||
|
authoritative; the `./config/*-secrets.js` files are operator-edit seed
|
||||||
|
artifacts and the fail-soft fallback.
|
||||||
|
|
||||||
|
## End-user personal secrets
|
||||||
|
|
||||||
|
Every logged-in user has a personal namespace `secret/users/<uid>/*`, reached
|
||||||
|
through the SSO UI at **Vault → My Secrets**. The SSO mints a `user-<uid>`
|
||||||
|
token on first access (cached in Redis for the token's lifetime) and proxies
|
||||||
|
`/api/vault` to OpenBao with **that** token injected server-side — the
|
||||||
|
client's SSO session token never reaches OpenBao.
|
||||||
|
|
||||||
|
- **Non-admins** see only their own namespace; the UI fixes the path prefix
|
||||||
|
to `users/<uid>/`. They can list, read, write, and delete secrets there.
|
||||||
|
- **Admins** (`app_sso_admin` / `app_super_admin`) get free-form access across
|
||||||
|
all of `secret/` plus an **Apps** tab (see below).
|
||||||
|
|
||||||
|
Scoping is enforced at **two** layers: the SSO's `scopeGuard` rejects any path
|
||||||
|
outside the subject's prefix with a 403 (defense-in-depth), and the token's
|
||||||
|
own OpenBao policy enforces the same at the API layer.
|
||||||
|
|
||||||
|
## External apps
|
||||||
|
|
||||||
|
An external (non-theta42) app gets scoped access to its own namespace,
|
||||||
|
`secret/apps/<name>/*`, via a token an admin mints once from the SSO UI's
|
||||||
|
**Vault → Apps** tab. The token is shown **once** (copy it immediately; it is
|
||||||
|
not stored retrievably) and confined by an `app-<name>` policy.
|
||||||
|
|
||||||
|
Convention:
|
||||||
|
|
||||||
|
- `secret/apps/<name>/conf` for config-style secrets, `secret/apps/<name>/*`
|
||||||
|
for arbitrary keys.
|
||||||
|
- The app authenticates with the header `X-Vault-Token: <minted token>`
|
||||||
|
against `http://<openbao-host>:8200/v1/secret/data/apps/<name>/...`.
|
||||||
|
|
||||||
|
Non-Node consumers (curl):
|
||||||
|
|
||||||
|
```bash
|
||||||
|
VAULT_ADDR=http://openbao:8200 # or your external-facing openbao address
|
||||||
|
# Write
|
||||||
|
curl -X POST "$VAULT_ADDR/v1/secret/data/apps/my-service/conf" \
|
||||||
|
-H "X-Vault-Token: <token>" -H "Content-Type: application/json" \
|
||||||
|
-d '{"data":{"db_password":"..."}}'
|
||||||
|
# Read
|
||||||
|
curl -s "$VAULT_ADDR/v1/secret/data/apps/my-service/conf" \
|
||||||
|
-H "X-Vault-Token: <token>" | jq .data.data
|
||||||
|
```
|
||||||
|
|
||||||
|
Node consumers can use [@simpleworkjs/bao-conf](https://simpleworkjs.github.io/bao-conf/)
|
||||||
|
directly:
|
||||||
|
|
||||||
|
```js
|
||||||
|
const baoConf = require('@simpleworkjs/bao-conf');
|
||||||
|
const data = await baoConf.get('apps/my-service/conf'); // secret/data/apps/my-service/conf
|
||||||
|
await baoConf.set('apps/my-service/conf', { db_password: '...' });
|
||||||
|
```
|
||||||
|
|
||||||
|
## Operator rotation
|
||||||
|
|
||||||
|
If a secret is exposed (or just on a routine schedule), rotate it at the
|
||||||
|
**provider** first (the LDAP server, the SMTP host, the OAuth `jwtSecret`,
|
||||||
|
etc.), then update OpenBao:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Read the current sso-manager conf
|
||||||
|
docker exec -e BAO_TOKEN="$VAULT_TOKEN" openbao bao kv get secret/sso-manager/conf
|
||||||
|
# Write a new value (KV-v2 POST replaces the data; merge carefully)
|
||||||
|
docker exec -e BAO_TOKEN="$VAULT_TOKEN" openbao bao kv put secret/sso-manager/conf \
|
||||||
|
ldap.bindPassword='<new>' smtp.password='<new>' oauth.jwtSecret='<new>'
|
||||||
|
```
|
||||||
|
|
||||||
|
Then restart the affected app so `bao-conf.init()` re-reads it
|
||||||
|
(`docker compose restart sso-manager`). Call-time readers pick up the change
|
||||||
|
on next read; require-time captures (OIDC `clientSecret`) need the restart.
|
||||||
|
|
||||||
|
> The SSO admin **Configuration** UI (`/api/conf`) writes `secret/sso-manager/conf`
|
||||||
|
> and updates the live conf immediately, so SMTP/discovery/oauth edits made
|
||||||
|
> there don't need a manual `bao kv put`.
|
||||||
|
|
||||||
|
## Backups
|
||||||
|
|
||||||
|
The OpenBao data volume `openbao-data` holds every secret. Back it up with the
|
||||||
|
rest of the stack (see the README's *Backups and restore* section). The
|
||||||
|
`./config/*-secrets.js` files are **not** a complete secret backup once OpenBao
|
||||||
|
is authoritative — they're the first-run seed and the fallback. A full disaster
|
||||||
|
recovery restores both the `openbao-data` volume (the authoritative store) and
|
||||||
|
`./config/` (the seed/fallback), then runs `./setup.sh` to unseal OpenBao and
|
||||||
|
re-mint the per-app tokens.
|
||||||
|
|
||||||
|
## What's not in scope yet
|
||||||
|
|
||||||
|
- **Renewal automation** — per-app/user tokens use OpenBao's default TTL and
|
||||||
|
are re-minted by `setup.sh` on expiry; a periodic renewal worker is a
|
||||||
|
follow-up.
|
||||||
|
- **History scrubbing** — if a secret was committed to git, rotating it is the
|
||||||
|
fix; scrubbing it from git history (BFG / `git filter-repo`) is a separate,
|
||||||
|
git-destructive operation you can opt into.
|
||||||
|
- **Per-app secrets beyond boot config** (e.g. the proxy's DNS-provider creds,
|
||||||
|
the jump host's per-user LDAP SSH keys) moving into OpenBao — only the
|
||||||
|
boot-critical `*-secrets.js` contents moved in this phase.
|
||||||
Submodule
+1
Submodule jump-host added at db3333e26d
Submodule
+1
Submodule ldap-client added at 31d8fa1229
@@ -0,0 +1 @@
|
|||||||
|
https://github.com/theta42/theta-env/pull/75
|
||||||
+1
-1
Submodule proxy updated: 289a9587d6...4aa994121a
+50
-1
@@ -21,21 +21,58 @@
|
|||||||
# setup.sh refuses to run without it.
|
# setup.sh refuses to run without it.
|
||||||
CFG_DOMAIN=example.com
|
CFG_DOMAIN=example.com
|
||||||
|
|
||||||
|
# Site name for the SSO directory — the root node this stack registers itself
|
||||||
|
# under on the Directory page, and the default "Location (Site)" that Linux
|
||||||
|
# hosts joined via ldap-client attach to (parent slug: site_<name>).
|
||||||
|
# Optional — defaults to "local".
|
||||||
|
#CFG_SITE_NAME=local
|
||||||
|
|
||||||
# Public hostnames. Optional — default to sso.<domain> / proxy.<domain> derived
|
# Public hostnames. Optional — default to sso.<domain> / proxy.<domain> derived
|
||||||
# from CFG_DOMAIN above. Uncomment and set only if your hostnames differ
|
# from CFG_DOMAIN above. Uncomment and set only if your hostnames differ
|
||||||
# (e.g. a different subdomain, or the domain isn't the bare apex):
|
# (e.g. a different subdomain, or the domain isn't the bare apex):
|
||||||
#CFG_SSO_HOST=sso.example.com
|
#CFG_SSO_HOST=sso.example.com
|
||||||
#CFG_PROXY_HOST=proxy.example.com
|
#CFG_PROXY_HOST=proxy.example.com
|
||||||
|
|
||||||
|
# ── Optional SSH jump host ───────────────────────────────────────────────────
|
||||||
|
# Enable the theta42/jump-host component: a public SSH jump host that
|
||||||
|
# authenticates users against the directory and bridges them to downstream
|
||||||
|
# hosts (ssh uid_-_target@jump, or an interactive picker). Off by default.
|
||||||
|
# When true, setup.sh clones/builds the jump-host submodule, the bootstrap
|
||||||
|
# mints its directory API token + writes ./config/jump-secrets.js, and it's
|
||||||
|
# registered in the proxy + directory. See jump-host's README for the LDAP
|
||||||
|
# write-ACL note (the bundled deployment binds as cn=admin).
|
||||||
|
#CFG_JUMP_HOST_ENABLED=false
|
||||||
|
#CFG_JUMP_HOST=jump.example.com # defaults to jump.<domain>
|
||||||
|
#JUMP_SSH_PORT=2222 # host port mapped to the jump host's SSH (never 22 by default)
|
||||||
|
|
||||||
# Advanced: override the derived LDAP base DN directly (e.g. to namespace
|
# Advanced: override the derived LDAP base DN directly (e.g. to namespace
|
||||||
# under an OU-style prefix). Leave unset to use the DN built from CFG_DOMAIN:
|
# under an OU-style prefix). Leave unset to use the DN built from CFG_DOMAIN:
|
||||||
#CFG_BASE_DN=dc=example,dc=com
|
#CFG_BASE_DN=dc=example,dc=com
|
||||||
|
|
||||||
|
# ── Optional outbound HTTP(S) proxy ──────────────────────────────────────────
|
||||||
|
# For an isolated/offline/corporate-network test host that only reaches the
|
||||||
|
# internet through an upstream HTTP proxy — NOT the theta42 "proxy" app.
|
||||||
|
# Wired into every service's docker build (npm/apt) AND its running container
|
||||||
|
# (SMTP, ACME/Let's Encrypt, DNS provider calls, the jump-host directory API
|
||||||
|
# client). Leave unset to disable (the default); CFG_HTTPS_PROXY falls back to
|
||||||
|
# CFG_HTTP_PROXY if unset, and CFG_NO_PROXY defaults to covering the stack's
|
||||||
|
# own internal service names so container-to-container traffic never goes
|
||||||
|
# through the proxy.
|
||||||
|
#CFG_HTTP_PROXY=http://proxy.example.com:3128
|
||||||
|
#CFG_HTTPS_PROXY=http://proxy.example.com:3128
|
||||||
|
#CFG_NO_PROXY=localhost,127.0.0.1,sso-manager,proxy,jump-host
|
||||||
|
|
||||||
# Optional — sensible defaults if left blank:
|
# Optional — sensible defaults if left blank:
|
||||||
#CFG_ORG=SSO Manager # app display name + outbound email org
|
#CFG_ORG=SSO Manager # app display name + outbound email org
|
||||||
#CFG_ADMIN_UID=admin # initial SSO admin username
|
#CFG_ADMIN_UID=admin # initial SSO admin username
|
||||||
#CFG_ADMIN_EMAIL=admin@proxy.example.com # defaults to admin@<proxyHost>
|
#CFG_ADMIN_EMAIL=admin@proxy.example.com # defaults to admin@<proxyHost>
|
||||||
#CFG_LDAP_CERT_CN= # LDAP TLS cert CN; empty -> defaults to the domain
|
#CFG_LDAP_CERT_CN= # LDAP TLS cert CN; empty -> defaults to the domain
|
||||||
|
#
|
||||||
|
# Hostname advertised on the SSO /integrations page for direct LDAPS binds.
|
||||||
|
# Leave blank to derive it from the public SSO host (same as oauth.issuer).
|
||||||
|
# Recommended: set an internal-only name like 'ldap.internal.example.com' or
|
||||||
|
# 'sso-manager' so clients don't need a public 636 port forward. See docs.
|
||||||
|
#CFG_LDAPS_HOST=
|
||||||
|
|
||||||
# Optional SMTP (outbound email from the SSO app). Leave blank to disable:
|
# Optional SMTP (outbound email from the SSO app). Leave blank to disable:
|
||||||
#CFG_SMTP_HOST=smtp.example.com
|
#CFG_SMTP_HOST=smtp.example.com
|
||||||
@@ -52,4 +89,16 @@ CFG_DOMAIN=example.com
|
|||||||
# password is the exception — see ./config/proxy-secrets.js's auth.localAdminPass
|
# password is the exception — see ./config/proxy-secrets.js's auth.localAdminPass
|
||||||
# comment for how to actually change it after the account exists). Do NOT set
|
# comment for how to actually change it after the account exists). Do NOT set
|
||||||
# CFG_LDAP_ADMIN_PASS / CFG_JWT_SECRET / CFG_ADMIN_PASS / CFG_SVC_PASS /
|
# CFG_LDAP_ADMIN_PASS / CFG_JWT_SECRET / CFG_ADMIN_PASS / CFG_SVC_PASS /
|
||||||
# CFG_PROXY_ADMIN_PASS here.
|
# CFG_PROXY_ADMIN_PASS here.
|
||||||
|
|
||||||
|
# ── Geo-Location Scaling (N-Way Multi-Master LDAP) ───────────────────────────
|
||||||
|
# If deploying this stack across multiple physical sites to provide local HA
|
||||||
|
# for directory services, you can enable N-Way Multi-Master OpenLDAP replication.
|
||||||
|
# This requires assigning a unique ID to each site and listing the LDAPS URLs
|
||||||
|
# of all OTHER sites in the cluster.
|
||||||
|
#
|
||||||
|
# Each site MUST have a unique LDAP_SERVER_ID (e.g. 1, 2, 3).
|
||||||
|
# LDAP_REPLICATION_HOSTS is a space-separated list of the other sites' LDAP URLs.
|
||||||
|
# Example for Site 1:
|
||||||
|
#LDAP_SERVER_ID=1
|
||||||
|
#LDAP_REPLICATION_HOSTS="ldaps://sso.site2.com:636 ldaps://sso.site3.com:636"
|
||||||
@@ -43,7 +43,11 @@
|
|||||||
# 5. docker compose exec sso-manager node /bootstrap/bootstrap.js
|
# 5. docker compose exec sso-manager node /bootstrap/bootstrap.js
|
||||||
# -> creates/updates the LDAP service account, first admin, OAuth client;
|
# -> creates/updates the LDAP service account, first admin, OAuth client;
|
||||||
# writes the OAuth client creds into ./config/proxy-secrets.js; prints
|
# writes the OAuth client creds into ./config/proxy-secrets.js; prints
|
||||||
# CLIENT_ID / CLIENT_SECRET / ALREADY_CONFIGURED on stdout.
|
# CLIENT_ID / CLIENT_SECRET / ALREADY_CONFIGURED on stdout. Also seeds
|
||||||
|
# the SSO directory with the stack's own resources (site -> host ->
|
||||||
|
# SSO Manager + Proxy services, with the proxy's OAuth client linked
|
||||||
|
# under its service) so the Directory page is populated out of the
|
||||||
|
# box. Idempotent — existing slugs are operator-owned and left alone.
|
||||||
# 6. docker compose up -d --build proxy; wait for /health.
|
# 6. docker compose up -d --build proxy; wait for /health.
|
||||||
# 7. Register <SSO_HOST> and <PROXY_HOST> as Host records in the proxy (via
|
# 7. Register <SSO_HOST> and <PROXY_HOST> as Host records in the proxy (via
|
||||||
# `docker compose exec proxy node`, calling the proxy's Host model
|
# `docker compose exec proxy node`, calling the proxy's Host model
|
||||||
@@ -84,6 +88,23 @@ rand_hex() {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Upsert KEY=VALUE into ./.env, which `docker compose` auto-loads for every
|
||||||
|
# future invocation in this directory. Used to persist the *_GIT_COMMIT build
|
||||||
|
# args (see SSO_GIT_COMMIT/PROXY_GIT_COMMIT/JUMP_GIT_COMMIT below) so that an
|
||||||
|
# ad-hoc `docker compose up --build <service>` run later, OUTSIDE this script,
|
||||||
|
# still resolves the right commit instead of silently baking "unknown" (the
|
||||||
|
# submodule .git pointer file can't be resolved from inside the build
|
||||||
|
# context, so the value must come from the host via this file or the export).
|
||||||
|
env_upsert() {
|
||||||
|
local key="$1" val="$2" file=./.env
|
||||||
|
touch "$file"
|
||||||
|
if grep -q "^${key}=" "$file" 2>/dev/null; then
|
||||||
|
sed -i "s|^${key}=.*|${key}=${val}|" "$file"
|
||||||
|
else
|
||||||
|
printf '%s=%s\n' "$key" "$val" >> "$file"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
# Detect docker compose (v2 plugin `docker compose` or v1 standalone `docker-compose`).
|
# Detect docker compose (v2 plugin `docker compose` or v1 standalone `docker-compose`).
|
||||||
if docker compose version >/dev/null 2>&1; then
|
if docker compose version >/dev/null 2>&1; then
|
||||||
COMPOSE=(docker compose)
|
COMPOSE=(docker compose)
|
||||||
@@ -148,6 +169,35 @@ then
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# ── Optional jump host: resolve the enable flag early ─────────────────────────
|
||||||
|
# CFG_JUMP_HOST_ENABLED gates the optional SSH jump host (a third submodule).
|
||||||
|
# Read it from the environment or ./setup.env now (before the submodule loop
|
||||||
|
# and the compose steps) so every run knows whether to build/start it. The
|
||||||
|
# authoritative CFG_* for secrets are still resolved in ensure_config; this is
|
||||||
|
# only the on/off switch + its hostname.
|
||||||
|
[[ -f ./setup.env ]] && parse_kv_file ./setup.env
|
||||||
|
JUMP_ENABLED=0
|
||||||
|
case "${CFG_JUMP_HOST_ENABLED:-}" in 1|true|TRUE|yes|YES) JUMP_ENABLED=1 ;; esac
|
||||||
|
export CFG_JUMP_HOST_ENABLED CFG_JUMP_HOST
|
||||||
|
# When enabled, activate the compose profile so `up`/`ps` include the service.
|
||||||
|
if [[ "$JUMP_ENABLED" == "1" ]]; then export COMPOSE_PROFILES="jump-host"; fi
|
||||||
|
|
||||||
|
# ── Optional outbound HTTP(S) proxy for docker build + the running containers ─
|
||||||
|
# CFG_HTTP_PROXY / CFG_HTTPS_PROXY / CFG_NO_PROXY (from ./setup.env or the
|
||||||
|
# environment) — NOT the theta42 "proxy" app; this is an upstream HTTP proxy
|
||||||
|
# for reaching the internet (npm/apt during image builds, and SMTP/ACME/DNS
|
||||||
|
# provider calls at runtime), useful on isolated/offline/corporate-network
|
||||||
|
# test hosts. Off by default. docker-compose.yml passes these through as both
|
||||||
|
# build args (Docker also recognizes them as predefined build ARGs) and
|
||||||
|
# container environment on every service, so one setup.env entry covers the
|
||||||
|
# whole stack.
|
||||||
|
export CFG_HTTP_PROXY="${CFG_HTTP_PROXY:-}"
|
||||||
|
export CFG_HTTPS_PROXY="${CFG_HTTPS_PROXY:-${CFG_HTTP_PROXY:-}}"
|
||||||
|
export CFG_NO_PROXY="${CFG_NO_PROXY:-localhost,127.0.0.1,sso-manager,proxy,jump-host}"
|
||||||
|
if [[ -n "$CFG_HTTP_PROXY" ]]; then
|
||||||
|
info "Using HTTP proxy for docker build + containers: $CFG_HTTP_PROXY"
|
||||||
|
fi
|
||||||
|
|
||||||
# ── 1. Update submodules to their latest release tag, verify build contexts ───
|
# ── 1. Update submodules to their latest release tag, verify build contexts ───
|
||||||
# Submodules track release tags (vX.Y.Z), not the tip of master -- so
|
# Submodules track release tags (vX.Y.Z), not the tip of master -- so
|
||||||
# "update" means "move to the newest tag", not "move to the newest commit".
|
# "update" means "move to the newest tag", not "move to the newest commit".
|
||||||
@@ -163,8 +213,11 @@ if [[ "${SKIP_SUBMODULE_UPDATE:-0}" != "1" ]]; then
|
|||||||
die "git submodule update --init failed. Run manually: git submodule update --init --recursive"
|
die "git submodule update --init failed. Run manually: git submodule update --init --recursive"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
info "Updating submodules to their latest release tag (sso-manager-node, proxy)..."
|
# jump-host is optional: only track/build it when enabled.
|
||||||
for sm in sso-manager-node proxy; do
|
SUBMODULES=(sso-manager-node proxy)
|
||||||
|
[[ "$JUMP_ENABLED" == "1" ]] && SUBMODULES+=(jump-host)
|
||||||
|
info "Updating submodules to their latest release tag (${SUBMODULES[*]})..."
|
||||||
|
for sm in "${SUBMODULES[@]}"; do
|
||||||
[[ -d "$sm" ]] || continue
|
[[ -d "$sm" ]] || continue
|
||||||
before_rev="$(git -C "$sm" rev-parse HEAD 2>/dev/null || true)"
|
before_rev="$(git -C "$sm" rev-parse HEAD 2>/dev/null || true)"
|
||||||
# Prefer the exact tag the submodule is currently pinned to; fall back
|
# Prefer the exact tag the submodule is currently pinned to; fall back
|
||||||
@@ -240,6 +293,8 @@ module.exports = {
|
|||||||
bindPassword: $(js_str "$CFG_LDAP_ADMIN_PASS"),
|
bindPassword: $(js_str "$CFG_LDAP_ADMIN_PASS"),
|
||||||
userBase: $(js_str "ou=people,${dn}"),
|
userBase: $(js_str "ou=people,${dn}"),
|
||||||
groupBase: $(js_str "ou=groups,${dn}"),
|
groupBase: $(js_str "ou=groups,${dn}"),
|
||||||
|
ldapsHost: $(js_str "${CFG_LDAPS_HOST:-}"),
|
||||||
|
ldapsPort: 636,
|
||||||
},
|
},
|
||||||
smtp: {
|
smtp: {
|
||||||
host: $(js_str "${CFG_SMTP_HOST:-}"),
|
host: $(js_str "${CFG_SMTP_HOST:-}"),
|
||||||
@@ -254,11 +309,22 @@ module.exports = {
|
|||||||
jwtSecret: $(js_str "$CFG_JWT_SECRET"),
|
jwtSecret: $(js_str "$CFG_JWT_SECRET"),
|
||||||
token_lifetime: { access_token: 3600, refresh_token: 2592000 },
|
token_lifetime: { access_token: 3600, refresh_token: 2592000 },
|
||||||
},
|
},
|
||||||
|
// Without this, @simpleworkjs/orm falls back to './config/inventory.sqlite'
|
||||||
|
// relative to the app's /app cwd -- inside the container's ephemeral layer,
|
||||||
|
// not any mounted volume -- so every Resource/site/host/service/oauth row
|
||||||
|
// (the whole Directory Management page) would be silently wiped on every
|
||||||
|
// container recreate. /data is already a persisted volume (Redis lives
|
||||||
|
// there too), so this just co-locates the sqlite file with it.
|
||||||
|
orm: {
|
||||||
|
dialect: 'sqlite',
|
||||||
|
storage: '/data/inventory.sqlite',
|
||||||
|
},
|
||||||
|
|
||||||
// ── Orchestrator-only (ignored by the app) ───────────────────────────────
|
// ── Orchestrator-only (ignored by the app) ───────────────────────────────
|
||||||
stack: {
|
stack: {
|
||||||
ldapBaseDn: $(js_str "$dn"),
|
ldapBaseDn: $(js_str "$dn"),
|
||||||
ldapDomain: $(js_str "$domain"),
|
ldapDomain: $(js_str "$domain"),
|
||||||
|
siteName: $(js_str "${CFG_SITE_NAME:-local}"),
|
||||||
ldapCertCn: $(js_str "${CFG_LDAP_CERT_CN:-}"),
|
ldapCertCn: $(js_str "${CFG_LDAP_CERT_CN:-}"),
|
||||||
ssoHost: $(js_str "$CFG_SSO_HOST"),
|
ssoHost: $(js_str "$CFG_SSO_HOST"),
|
||||||
proxyHost: $(js_str "$CFG_PROXY_HOST"),
|
proxyHost: $(js_str "$CFG_PROXY_HOST"),
|
||||||
@@ -326,6 +392,23 @@ PROXYEOF
|
|||||||
}
|
}
|
||||||
|
|
||||||
ensure_config() {
|
ensure_config() {
|
||||||
|
if [[ ! -f "$CONFIG_DIR/openbao.hcl" ]]; then
|
||||||
|
info "Generating $CONFIG_DIR/openbao.hcl ..."
|
||||||
|
mkdir -p "$CONFIG_DIR"
|
||||||
|
cat > "$CONFIG_DIR/openbao.hcl" <<BAOEOF
|
||||||
|
storage "file" {
|
||||||
|
path = "/vault/data"
|
||||||
|
}
|
||||||
|
listener "tcp" {
|
||||||
|
address = "0.0.0.0:8200"
|
||||||
|
tls_disable = 1
|
||||||
|
}
|
||||||
|
disable_mlock = true
|
||||||
|
ui = true
|
||||||
|
BAOEOF
|
||||||
|
chmod 644 "$CONFIG_DIR/openbao.hcl"
|
||||||
|
fi
|
||||||
|
|
||||||
if [[ -f "$CONFIG_DIR/sso-secrets.js" ]]; then
|
if [[ -f "$CONFIG_DIR/sso-secrets.js" ]]; then
|
||||||
info "Using existing $CONFIG_DIR/sso-secrets.js (operator-owned — left untouched)."
|
info "Using existing $CONFIG_DIR/sso-secrets.js (operator-owned — left untouched)."
|
||||||
return 0
|
return 0
|
||||||
@@ -349,12 +432,14 @@ ensure_config() {
|
|||||||
# derivation block further down (no example.com placeholders here).
|
# derivation block further down (no example.com placeholders here).
|
||||||
CFG_BASE_DN="${CFG_BASE_DN:-}"
|
CFG_BASE_DN="${CFG_BASE_DN:-}"
|
||||||
CFG_DOMAIN="${CFG_DOMAIN:-}"
|
CFG_DOMAIN="${CFG_DOMAIN:-}"
|
||||||
|
CFG_SITE_NAME="${CFG_SITE_NAME:-}"
|
||||||
CFG_ORG="${CFG_ORG:-}"
|
CFG_ORG="${CFG_ORG:-}"
|
||||||
CFG_SSO_HOST="${CFG_SSO_HOST:-}"
|
CFG_SSO_HOST="${CFG_SSO_HOST:-}"
|
||||||
CFG_PROXY_HOST="${CFG_PROXY_HOST:-}"
|
CFG_PROXY_HOST="${CFG_PROXY_HOST:-}"
|
||||||
CFG_ADMIN_UID="${CFG_ADMIN_UID:-}"
|
CFG_ADMIN_UID="${CFG_ADMIN_UID:-}"
|
||||||
CFG_ADMIN_EMAIL="${CFG_ADMIN_EMAIL:-}"
|
CFG_ADMIN_EMAIL="${CFG_ADMIN_EMAIL:-}"
|
||||||
CFG_LDAP_CERT_CN="${CFG_LDAP_CERT_CN:-}"
|
CFG_LDAP_CERT_CN="${CFG_LDAP_CERT_CN:-}"
|
||||||
|
CFG_LDAPS_HOST="${CFG_LDAPS_HOST:-}"
|
||||||
CFG_CLIENT_ID="${CFG_CLIENT_ID:-}"
|
CFG_CLIENT_ID="${CFG_CLIENT_ID:-}"
|
||||||
CFG_CLIENT_SECRET="${CFG_CLIENT_SECRET:-}"
|
CFG_CLIENT_SECRET="${CFG_CLIENT_SECRET:-}"
|
||||||
CFG_LDAP_ADMIN_PASS="${CFG_LDAP_ADMIN_PASS:-}"
|
CFG_LDAP_ADMIN_PASS="${CFG_LDAP_ADMIN_PASS:-}"
|
||||||
@@ -383,6 +468,8 @@ ensure_config() {
|
|||||||
CFG_ADMIN_PASS="${BOOTSTRAP_ADMIN_PASS:-$CFG_ADMIN_PASS}"
|
CFG_ADMIN_PASS="${BOOTSTRAP_ADMIN_PASS:-$CFG_ADMIN_PASS}"
|
||||||
CFG_SVC_PASS="${LDAP_SERVICE_PASS:-$CFG_SVC_PASS}"
|
CFG_SVC_PASS="${LDAP_SERVICE_PASS:-$CFG_SVC_PASS}"
|
||||||
CFG_LDAP_CERT_CN="${LDAP_CERT_CN:-$CFG_LDAP_CERT_CN}"
|
CFG_LDAP_CERT_CN="${LDAP_CERT_CN:-$CFG_LDAP_CERT_CN}"
|
||||||
|
# .env has no legacy LDAPS_HOST key; this stays as set in setup.env/env.
|
||||||
|
CFG_LDAPS_HOST="${CFG_LDAPS_HOST:-}"
|
||||||
CFG_SMTP_HOST="${SMTP_HOST:-${CFG_SMTP_HOST:-}}"
|
CFG_SMTP_HOST="${SMTP_HOST:-${CFG_SMTP_HOST:-}}"
|
||||||
CFG_SMTP_PORT="${SMTP_PORT:-${CFG_SMTP_PORT:-}}"
|
CFG_SMTP_PORT="${SMTP_PORT:-${CFG_SMTP_PORT:-}}"
|
||||||
CFG_SMTP_USER="${SMTP_USER:-${CFG_SMTP_USER:-}}"
|
CFG_SMTP_USER="${SMTP_USER:-${CFG_SMTP_USER:-}}"
|
||||||
@@ -412,10 +499,12 @@ ensure_config() {
|
|||||||
CFG_BASE_DN="${CFG_BASE_DN:-$(dn_from_domain "$CFG_DOMAIN")}"
|
CFG_BASE_DN="${CFG_BASE_DN:-$(dn_from_domain "$CFG_DOMAIN")}"
|
||||||
CFG_SSO_HOST="${CFG_SSO_HOST:-sso.$CFG_DOMAIN}"
|
CFG_SSO_HOST="${CFG_SSO_HOST:-sso.$CFG_DOMAIN}"
|
||||||
CFG_PROXY_HOST="${CFG_PROXY_HOST:-proxy.$CFG_DOMAIN}"
|
CFG_PROXY_HOST="${CFG_PROXY_HOST:-proxy.$CFG_DOMAIN}"
|
||||||
|
CFG_SITE_NAME="${CFG_SITE_NAME:-local}"
|
||||||
CFG_ORG="${CFG_ORG:-SSO Manager}"
|
CFG_ORG="${CFG_ORG:-SSO Manager}"
|
||||||
CFG_ADMIN_UID="${CFG_ADMIN_UID:-admin}"
|
CFG_ADMIN_UID="${CFG_ADMIN_UID:-admin}"
|
||||||
CFG_ADMIN_EMAIL="${CFG_ADMIN_EMAIL:-admin@$CFG_PROXY_HOST}"
|
CFG_ADMIN_EMAIL="${CFG_ADMIN_EMAIL:-admin@$CFG_PROXY_HOST}"
|
||||||
CFG_LDAP_CERT_CN="${CFG_LDAP_CERT_CN:-}"
|
CFG_LDAP_CERT_CN="${CFG_LDAP_CERT_CN:-}"
|
||||||
|
CFG_LDAPS_HOST="${CFG_LDAPS_HOST:-}"
|
||||||
CFG_CLIENT_ID="${CFG_CLIENT_ID:-}"
|
CFG_CLIENT_ID="${CFG_CLIENT_ID:-}"
|
||||||
CFG_CLIENT_SECRET="${CFG_CLIENT_SECRET:-}"
|
CFG_CLIENT_SECRET="${CFG_CLIENT_SECRET:-}"
|
||||||
# Random secrets (generated fresh unless sourced/migrated above). These do
|
# Random secrets (generated fresh unless sourced/migrated above). These do
|
||||||
@@ -429,6 +518,7 @@ ensure_config() {
|
|||||||
mkdir -p "$CONFIG_DIR" && chmod 700 "$CONFIG_DIR"
|
mkdir -p "$CONFIG_DIR" && chmod 700 "$CONFIG_DIR"
|
||||||
write_sso_secrets
|
write_sso_secrets
|
||||||
write_proxy_secrets
|
write_proxy_secrets
|
||||||
|
|
||||||
chmod 600 "$CONFIG_DIR/sso-secrets.js" "$CONFIG_DIR/proxy-secrets.js"
|
chmod 600 "$CONFIG_DIR/sso-secrets.js" "$CONFIG_DIR/proxy-secrets.js"
|
||||||
|
|
||||||
if [[ "$migrated" == "1" ]]; then
|
if [[ "$migrated" == "1" ]]; then
|
||||||
@@ -574,6 +664,158 @@ backup_before_rebuild() {
|
|||||||
}
|
}
|
||||||
backup_before_rebuild
|
backup_before_rebuild
|
||||||
|
|
||||||
|
# ── 3b. Setup OpenBao (Vault) ────────────────────────────────────────────────
|
||||||
|
info "Starting openbao..."
|
||||||
|
"${COMPOSE[@]}" run --rm --user root openbao chown -R 100:1000 /vault/data
|
||||||
|
"${COMPOSE[@]}" up -d openbao
|
||||||
|
info "Waiting for openbao to be reachable..."
|
||||||
|
for i in $(seq 1 30); do
|
||||||
|
if docker exec openbao bao status >/dev/null 2>&1 || [[ $? -eq 2 ]]; then
|
||||||
|
info "openbao is reachable."; break
|
||||||
|
fi
|
||||||
|
if (( i == 30 )); then die "openbao did not become reachable in 60s. Check: ${COMPOSE[*]} logs openbao"; fi
|
||||||
|
sleep 2
|
||||||
|
done
|
||||||
|
|
||||||
|
if ! docker exec openbao bao status -format=json 2>/dev/null | grep -q '"initialized": true' || true; then
|
||||||
|
status_json=$(docker exec openbao bao status -format=json 2>/dev/null || true)
|
||||||
|
if ! echo "$status_json" | grep -q '"initialized": true'; then
|
||||||
|
info "Initializing openbao for the first time..."
|
||||||
|
docker exec openbao bao operator init -key-shares=1 -key-threshold=1 -format=json > "$CONFIG_DIR/bao-init.json"
|
||||||
|
chmod 600 "$CONFIG_DIR/bao-init.json"
|
||||||
|
info "Openbao initialized. Keys saved to $CONFIG_DIR/bao-init.json"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
status_json=$(docker exec openbao bao status -format=json 2>/dev/null || true)
|
||||||
|
if echo "$status_json" | grep -q '"sealed": true'; then
|
||||||
|
info "Unsealing openbao..."
|
||||||
|
UNSEAL_KEY=$(grep -A1 '"unseal_keys_b64":' "$CONFIG_DIR/bao-init.json" | tail -n1 | cut -d'"' -f2)
|
||||||
|
docker exec openbao bao operator unseal "$UNSEAL_KEY" >/dev/null
|
||||||
|
fi
|
||||||
|
|
||||||
|
export VAULT_TOKEN
|
||||||
|
VAULT_TOKEN=$(grep '"root_token":' "$CONFIG_DIR/bao-init.json" | cut -d'"' -f4)
|
||||||
|
env_upsert VAULT_TOKEN "$VAULT_TOKEN"
|
||||||
|
|
||||||
|
if ! docker exec -e BAO_TOKEN="$VAULT_TOKEN" openbao bao secrets list -format=json 2>/dev/null | grep -q '"secret/":'; then
|
||||||
|
info "Enabling kv-v2 secrets engine at secret/..."
|
||||||
|
docker exec -e BAO_TOKEN="$VAULT_TOKEN" openbao bao secrets enable -path=secret kv-v2 >/dev/null
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ── 3c. OpenBao policies, token role, per-app tokens ─────────────────────────
|
||||||
|
# Each app gets a least-privilege scoped token (a policy over only its own
|
||||||
|
# secret/<app>/conf). sso additionally gets the `sso-broker` policy so it can
|
||||||
|
# mint per-user (user-<uid>) and per-app (app-<name>) tokens at runtime through
|
||||||
|
# the sso-broker token role. The root VAULT_TOKEN stays in .env for
|
||||||
|
# setup/maintenance ONLY and is never passed to a service container. Everything
|
||||||
|
# here is idempotent — re-running setup.sh keeps existing policies/tokens.
|
||||||
|
|
||||||
|
# Run a `bao` command inside the openbao container as root.
|
||||||
|
bao_run() { docker exec -e BAO_TOKEN="$VAULT_TOKEN" openbao bao "$@"; }
|
||||||
|
|
||||||
|
# Write an ACL policy from stdin HCL only if it does not already exist.
|
||||||
|
ensure_policy() {
|
||||||
|
local name="$1"
|
||||||
|
if bao_run policy read "$name" >/dev/null 2>&1; then
|
||||||
|
info " policy ${name} already exists — keeping."
|
||||||
|
else
|
||||||
|
info " writing policy ${name}..."
|
||||||
|
docker exec -i -e BAO_TOKEN="$VAULT_TOKEN" openbao bao policy write "$name" - >/dev/null
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# Read KEY= from ./.env (empty if absent) — reuse a previously minted token
|
||||||
|
# instead of minting a fresh one on every setup.sh run.
|
||||||
|
env_get() {
|
||||||
|
local key="$1" file=./.env
|
||||||
|
[[ -f "$file" ]] || return 0
|
||||||
|
grep -m1 "^${key}=" "$file" 2>/dev/null | cut -d= -f2-
|
||||||
|
}
|
||||||
|
|
||||||
|
# Mint an orphan, renewable token for `policy` and persist it to .env as `key`,
|
||||||
|
# OR reuse the token already in .env if it is still valid (re-mint on expiry).
|
||||||
|
ensure_token() {
|
||||||
|
local key="$1" policy="$2" existing tok
|
||||||
|
existing="$(env_get "$key")"
|
||||||
|
if [[ -n "$existing" ]] && docker exec -e BAO_TOKEN="$existing" openbao bao token lookup >/dev/null 2>&1; then
|
||||||
|
info " ${key} already minted + valid — keeping."
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
info " minting ${key} (policy=${policy})..."
|
||||||
|
tok="$(bao_run token create -policy="$policy" -orphan=true -field=token)" \
|
||||||
|
|| die "failed to mint ${key} (policy=${policy})"
|
||||||
|
env_upsert "$key" "$tok"
|
||||||
|
}
|
||||||
|
|
||||||
|
# Seed secret/<vault_path> from a /config/*.js module on first run only
|
||||||
|
# (skipped if the path already exists). Fail-soft: a seed failure leaves the
|
||||||
|
# app's file-mounted config as the fallback — boot is not blocked.
|
||||||
|
seed_app_conf() {
|
||||||
|
local vault_path="$1" mod="$2"
|
||||||
|
if bao_run kv get "secret/${vault_path}" >/dev/null 2>&1; then
|
||||||
|
info " secret/${vault_path} already seeded — keeping."
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
info "Seeding secret/${vault_path} from ${mod}..."
|
||||||
|
docker exec sso-manager node -e "console.log(JSON.stringify(require('${mod}')))" 2>/dev/null \
|
||||||
|
| docker exec -i -e BAO_TOKEN="$VAULT_TOKEN" openbao bao kv put "secret/${vault_path}" - >/dev/null \
|
||||||
|
|| warn " could not seed secret/${vault_path} (continuing — app will use its file fallback)"
|
||||||
|
}
|
||||||
|
|
||||||
|
info "Configuring OpenBao policies..."
|
||||||
|
# sso-broker — sso's authority to read/write its own conf, mint per-user and
|
||||||
|
# per-app tokens (auth/token/create/sso-broker), and create the matching
|
||||||
|
# user-<uid> / app-<name> / sso-admin policies.
|
||||||
|
ensure_policy sso-broker <<'HCL'
|
||||||
|
path "secret/data/sso-manager/conf" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||||
|
path "secret/metadata/sso-manager/conf" { capabilities = ["list", "read", "delete"] }
|
||||||
|
path "secret/data/users/*" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||||
|
path "secret/metadata/users/*" { capabilities = ["list", "read", "delete"] }
|
||||||
|
path "secret/data/apps/*" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||||
|
path "secret/metadata/apps/*" { capabilities = ["list", "read", "delete"] }
|
||||||
|
path "auth/token/create/sso-broker" { capabilities = ["update"] }
|
||||||
|
path "sys/policies/acl/user-*" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||||
|
path "sys/policies/acl/app-*" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||||
|
path "sys/policies/acl/sso-admin" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||||
|
HCL
|
||||||
|
# sso-admin — admin users in the vault UI: read/write/list everything under secret/.
|
||||||
|
ensure_policy sso-admin <<'HCL'
|
||||||
|
path "secret/data/*" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||||
|
path "secret/metadata/*" { capabilities = ["list", "read", "delete"] }
|
||||||
|
HCL
|
||||||
|
# proxy / jump-host — read only their own boot conf.
|
||||||
|
ensure_policy proxy <<'HCL'
|
||||||
|
path "secret/data/proxy/conf" { capabilities = ["read"] }
|
||||||
|
path "secret/metadata/proxy/conf" { capabilities = ["read", "list"] }
|
||||||
|
HCL
|
||||||
|
ensure_policy jump-host <<'HCL'
|
||||||
|
path "secret/data/jump-host/conf" { capabilities = ["read"] }
|
||||||
|
path "secret/metadata/jump-host/conf" { capabilities = ["read", "list"] }
|
||||||
|
HCL
|
||||||
|
|
||||||
|
# sso-broker token role: lets sso mint user-*/app-*/sso-admin tokens. Orphan,
|
||||||
|
# renewable, 24h period. Wildcards need allowed_policies_glob — allowed_policies
|
||||||
|
# is exact-match only.
|
||||||
|
info "Configuring sso-broker token role..."
|
||||||
|
if ! bao_run read auth/token/roles/sso-broker >/dev/null 2>&1; then
|
||||||
|
docker exec -i -e BAO_TOKEN="$VAULT_TOKEN" openbao bao write auth/token/roles/sso-broker - <<'JSON' >/dev/null
|
||||||
|
{"allowed_policies":["sso-admin"],"allowed_policies_glob":["user-*","app-*"],"orphan":true,"renewable":true,"token_period":"24h"}
|
||||||
|
JSON
|
||||||
|
else
|
||||||
|
info " token role sso-broker already exists — keeping."
|
||||||
|
fi
|
||||||
|
|
||||||
|
info "Minting per-app OpenBao tokens (stored in .env, passed to containers as VAULT_TOKEN)..."
|
||||||
|
ensure_token SSO_VAULT_TOKEN sso-broker
|
||||||
|
ensure_token PROXY_VAULT_TOKEN proxy
|
||||||
|
ensure_token JUMP_VAULT_TOKEN jump-host
|
||||||
|
|
||||||
|
info "OpenBao secrets configured:"
|
||||||
|
info " policies: sso-broker, sso-admin, proxy, jump-host (+ per-user/app created lazily by sso)"
|
||||||
|
info " token role: sso-broker (mints user-*/app-*/sso-admin tokens, 24h period)"
|
||||||
|
info " app tokens: SSO_VAULT_TOKEN, PROXY_VAULT_TOKEN, JUMP_VAULT_TOKEN in .env"
|
||||||
|
|
||||||
# ── 4. Start SSO Manager, wait for health ─────────────────────────────────────
|
# ── 4. Start SSO Manager, wait for health ─────────────────────────────────────
|
||||||
# SSO_GIT_COMMIT: sso-manager-node is a git submodule here, so its .git is a
|
# SSO_GIT_COMMIT: sso-manager-node is a git submodule here, so its .git is a
|
||||||
# pointer file (not a real repo) -- the image can't resolve its own commit
|
# pointer file (not a real repo) -- the image can't resolve its own commit
|
||||||
@@ -582,6 +824,7 @@ backup_before_rebuild
|
|||||||
# docker-compose.yml and sso-manager-node's Dockerfile.openldap.
|
# docker-compose.yml and sso-manager-node's Dockerfile.openldap.
|
||||||
SSO_GIT_COMMIT="$(git -C sso-manager-node rev-parse --short HEAD 2>/dev/null || echo unknown)"
|
SSO_GIT_COMMIT="$(git -C sso-manager-node rev-parse --short HEAD 2>/dev/null || echo unknown)"
|
||||||
export SSO_GIT_COMMIT
|
export SSO_GIT_COMMIT
|
||||||
|
env_upsert SSO_GIT_COMMIT "$SSO_GIT_COMMIT"
|
||||||
info "Building + starting sso-manager (first run builds the image; this takes a while)..."
|
info "Building + starting sso-manager (first run builds the image; this takes a while)..."
|
||||||
"${COMPOSE[@]}" up -d --build sso-manager
|
"${COMPOSE[@]}" up -d --build sso-manager
|
||||||
|
|
||||||
@@ -597,6 +840,16 @@ for i in $(seq 1 60); do
|
|||||||
sleep 2
|
sleep 2
|
||||||
done
|
done
|
||||||
|
|
||||||
|
info "Seeding app configs into OpenBao (idempotent)..."
|
||||||
|
# sso-manager/conf holds the operator-set LDAP/SMTP/jwtSecret values — sso has
|
||||||
|
# no bootstrap-generated creds, so the file is the complete source of truth.
|
||||||
|
seed_app_conf sso-manager/conf /config/sso-secrets.js
|
||||||
|
# proxy/conf is seeded from the operator file (placeholder OAuth creds); the
|
||||||
|
# bootstrap (step 5) then writes the real generated OAuth client creds into
|
||||||
|
# OpenBao over this. proxy boots at step 6, after bootstrap, so it sees the
|
||||||
|
# real values.
|
||||||
|
seed_app_conf proxy/conf /config/proxy-secrets.js
|
||||||
|
|
||||||
# Read the summary values (hosts, admin, base DN) back from ./config via the
|
# Read the summary values (hosts, admin, base DN) back from ./config via the
|
||||||
# running container's node — works whether ./config was generated or pre-existing.
|
# running container's node — works whether ./config was generated or pre-existing.
|
||||||
read_config_kv() {
|
read_config_kv() {
|
||||||
@@ -627,9 +880,35 @@ info " Admin uid: ${ADMIN_UID}"
|
|||||||
|
|
||||||
# ── 5. Run the bootstrap (writes CLIENT_ID/CLIENT_SECRET/ALREADY_CONFIGURED) ──
|
# ── 5. Run the bootstrap (writes CLIENT_ID/CLIENT_SECRET/ALREADY_CONFIGURED) ──
|
||||||
# The bootstrap reads its inputs from /config/*.js (not env) and writes the
|
# The bootstrap reads its inputs from /config/*.js (not env) and writes the
|
||||||
# generated OAuth client creds back into /config/proxy-secrets.js. No -e flags.
|
# generated OAuth client creds back into /config/proxy-secrets.js AND into
|
||||||
|
# OpenBao (secret/proxy/conf, secret/jump-host/conf) so the proxy + jump host
|
||||||
|
# load them from OpenBao at boot. The root VAULT_TOKEN is passed on this one
|
||||||
|
# exec so bootstrap can write those paths; it is never handed to a service
|
||||||
|
# container.
|
||||||
info "Running bootstrap (creates/updates the LDAP service account, first admin, OAuth client)..."
|
info "Running bootstrap (creates/updates the LDAP service account, first admin, OAuth client)..."
|
||||||
BOOTSTRAP_OUT=$("${COMPOSE[@]}" exec -T sso-manager node /bootstrap/bootstrap.js) \
|
# Host facts for the directory seed — collected HERE (on the host; inside the
|
||||||
|
# container hostname/uname describe the container, not the machine). Same
|
||||||
|
# collection as ldap-client/index.sh so stack hosts and ldap-client-joined
|
||||||
|
# hosts carry identical metadata. All best-effort: a missing tool just leaves
|
||||||
|
# the field blank.
|
||||||
|
STACK_HOST_NAME="$(hostname 2>/dev/null || true)"
|
||||||
|
STACK_HOST_IP="$(hostname -I 2>/dev/null | awk '{print $1}' || true)"
|
||||||
|
_iface="$(ip route show default 2>/dev/null | awk '/default/ {print $5; exit}' || true)"
|
||||||
|
STACK_HOST_MAC=""
|
||||||
|
[[ -n "$_iface" ]] && STACK_HOST_MAC="$(cat "/sys/class/net/$_iface/address" 2>/dev/null || true)"
|
||||||
|
STACK_HOST_OS="$( (. /etc/os-release 2>/dev/null && echo "${PRETTY_NAME:-}") || true)"
|
||||||
|
STACK_HOST_KERNEL="$(uname -r 2>/dev/null || true)"
|
||||||
|
BOOTSTRAP_OUT=$("${COMPOSE[@]}" exec -T \
|
||||||
|
-e STACK_HOST_NAME="$STACK_HOST_NAME" \
|
||||||
|
-e STACK_HOST_IP="$STACK_HOST_IP" \
|
||||||
|
-e STACK_HOST_MAC="$STACK_HOST_MAC" \
|
||||||
|
-e STACK_HOST_OS="$STACK_HOST_OS" \
|
||||||
|
-e STACK_HOST_KERNEL="$STACK_HOST_KERNEL" \
|
||||||
|
-e CFG_JUMP_HOST_ENABLED="${CFG_JUMP_HOST_ENABLED:-}" \
|
||||||
|
-e CFG_JUMP_HOST="${CFG_JUMP_HOST:-}" \
|
||||||
|
-e VAULT_ADDR=http://openbao:8200 \
|
||||||
|
-e VAULT_TOKEN="$VAULT_TOKEN" \
|
||||||
|
sso-manager node /bootstrap/bootstrap.js) \
|
||||||
|| die "bootstrap failed:\n${BOOTSTRAP_OUT}"
|
|| die "bootstrap failed:\n${BOOTSTRAP_OUT}"
|
||||||
|
|
||||||
getval() { echo "$BOOTSTRAP_OUT" | grep -m1 "^$1=" | cut -d= -f2-; }
|
getval() { echo "$BOOTSTRAP_OUT" | grep -m1 "^$1=" | cut -d= -f2-; }
|
||||||
@@ -647,6 +926,7 @@ fi
|
|||||||
# PROXY_GIT_COMMIT: same reasoning as SSO_GIT_COMMIT above.
|
# PROXY_GIT_COMMIT: same reasoning as SSO_GIT_COMMIT above.
|
||||||
PROXY_GIT_COMMIT="$(git -C proxy rev-parse --short HEAD 2>/dev/null || echo unknown)"
|
PROXY_GIT_COMMIT="$(git -C proxy rev-parse --short HEAD 2>/dev/null || echo unknown)"
|
||||||
export PROXY_GIT_COMMIT
|
export PROXY_GIT_COMMIT
|
||||||
|
env_upsert PROXY_GIT_COMMIT "$PROXY_GIT_COMMIT"
|
||||||
info "Building + starting proxy (first run builds the image; this takes a while)..."
|
info "Building + starting proxy (first run builds the image; this takes a while)..."
|
||||||
"${COMPOSE[@]}" up -d --build proxy
|
"${COMPOSE[@]}" up -d --build proxy
|
||||||
|
|
||||||
@@ -704,6 +984,52 @@ NODEEOF
|
|||||||
) || die "Registering hosts with the proxy failed:\n${HOSTS_OUT}"
|
) || die "Registering hosts with the proxy failed:\n${HOSTS_OUT}"
|
||||||
echo "$HOSTS_OUT" | sed 's/^/[setup] /'
|
echo "$HOSTS_OUT" | sed 's/^/[setup] /'
|
||||||
|
|
||||||
|
# ── 7b. Optional: build + start the SSH jump host ─────────────────────────────
|
||||||
|
# Enabled by CFG_JUMP_HOST_ENABLED. The bootstrap (step 5) already wrote
|
||||||
|
# ./config/jump-secrets.js (minted API token + LDAP admin bind). Build/start the
|
||||||
|
# service (compose profile 'jump-host' is active), wait for its web /health, and
|
||||||
|
# register its web UI hostname as a proxy Host so https://<JUMP_HOST> routes.
|
||||||
|
if [[ "$JUMP_ENABLED" == "1" ]]; then
|
||||||
|
JUMP_HOST="${CFG_JUMP_HOST:-jump.${SSO_HOST#sso.}}"
|
||||||
|
JUMP_GIT_COMMIT="$(git -C jump-host rev-parse --short HEAD 2>/dev/null || echo unknown)"
|
||||||
|
export JUMP_GIT_COMMIT
|
||||||
|
env_upsert JUMP_GIT_COMMIT "$JUMP_GIT_COMMIT"
|
||||||
|
# Seed jump-host/conf from the file bootstrap just wrote (it mints the API
|
||||||
|
# token + OAuth client into /config/jump-secrets.js at step 5). bootstrap
|
||||||
|
# also writes this to OpenBao directly, so this is a fallback for when
|
||||||
|
# bootstrap's jump provisioning warned-but-continued.
|
||||||
|
seed_app_conf jump-host/conf /config/jump-secrets.js
|
||||||
|
info "Building + starting jump-host (optional; enabled via CFG_JUMP_HOST_ENABLED)..."
|
||||||
|
"${COMPOSE[@]}" up -d --build jump-host
|
||||||
|
|
||||||
|
info "Waiting for jump-host to be healthy..."
|
||||||
|
for i in $(seq 1 60); do
|
||||||
|
if docker exec jump-host node -e "require('http').get('http://localhost:3002/health',r=>process.exit(r.statusCode===200?0:1)).on('error',()=>process.exit(1))" >/dev/null 2>&1; then
|
||||||
|
info "jump-host is healthy."; break
|
||||||
|
fi
|
||||||
|
if (( i == 60 )); then warn "jump-host did not become healthy in 120s. Check: ${COMPOSE[*]} logs jump-host"; break; fi
|
||||||
|
sleep 2
|
||||||
|
done
|
||||||
|
|
||||||
|
info "Registering ${JUMP_HOST} (jump-host web UI) with the proxy..."
|
||||||
|
JUMP_HOSTS_OUT=$("${COMPOSE[@]}" exec -T proxy node <<NODEEOF || true
|
||||||
|
const {Host} = require('/app/models').models;
|
||||||
|
(async () => {
|
||||||
|
try {
|
||||||
|
try { await Host.get($(js_str "$JUMP_HOST")); console.log('SKIP ${JUMP_HOST} (already exists)'); }
|
||||||
|
catch (e) {
|
||||||
|
if (e.name !== 'EntryNotFound') throw e;
|
||||||
|
await Host.create({ host: $(js_str "$JUMP_HOST"), ip: 'jump-host', targetPort: 3002, forcessl: true, targetssl: false, sso_enabled: false, created_by: 'setup.sh' });
|
||||||
|
console.log('CREATED ${JUMP_HOST} -> jump-host:3002');
|
||||||
|
}
|
||||||
|
process.exit(0);
|
||||||
|
} catch (error) { console.error('ERROR', error.message); process.exit(1); }
|
||||||
|
})();
|
||||||
|
NODEEOF
|
||||||
|
)
|
||||||
|
echo "$JUMP_HOSTS_OUT" | sed 's/^/[setup] /'
|
||||||
|
fi
|
||||||
|
|
||||||
# ── 8. Summary ───────────────────────────────────────────────────────────────
|
# ── 8. Summary ───────────────────────────────────────────────────────────────
|
||||||
echo
|
echo
|
||||||
info "\033[1;32mDone. Your SSO + proxy stack is up.\033[0m"
|
info "\033[1;32mDone. Your SSO + proxy stack is up.\033[0m"
|
||||||
@@ -712,6 +1038,11 @@ echo " SSO Manager UI: https://${SSO_HOST} (fronted by the proxy under TLS
|
|||||||
echo " first-run fallback: http://127.0.0.1:${SSO_PORT:-3001}"
|
echo " first-run fallback: http://127.0.0.1:${SSO_PORT:-3001}"
|
||||||
echo " Proxy mgmt UI: https://${PROXY_HOST}"
|
echo " Proxy mgmt UI: https://${PROXY_HOST}"
|
||||||
echo " first-run fallback: http://127.0.0.1:${MGMT_PORT:-3000}"
|
echo " first-run fallback: http://127.0.0.1:${MGMT_PORT:-3000}"
|
||||||
|
if [[ "$JUMP_ENABLED" == "1" ]]; then
|
||||||
|
echo " Jump host (SSH): ssh -p ${JUMP_SSH_PORT:-2222} <uid>@${JUMP_HOST:-jump.${SSO_HOST#sso.}} (TUI picker)"
|
||||||
|
echo " ssh -p ${JUMP_SSH_PORT:-2222} <uid>_-_<host>@${JUMP_HOST:-jump.${SSO_HOST#sso.}}"
|
||||||
|
echo " Jump host (web): https://${JUMP_HOST:-jump.${SSO_HOST#sso.}} (audit + metrics)"
|
||||||
|
fi
|
||||||
echo
|
echo
|
||||||
echo " First admin login credentials are in ./config/sso-secrets.js:"
|
echo " First admin login credentials are in ./config/sso-secrets.js:"
|
||||||
echo " user: ${ADMIN_UID}"
|
echo " user: ${ADMIN_UID}"
|
||||||
|
|||||||
+1
-1
Submodule sso-manager-node updated: 5a8030fd7d...ebb5b2c2a7
Executable
+44
@@ -0,0 +1,44 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
echo "=== Starting theta-env Integration Tests ==="
|
||||||
|
|
||||||
|
echo "=> Cleaning up any existing containers and volumes..."
|
||||||
|
docker-compose down -v
|
||||||
|
|
||||||
|
echo "=> Running setup.sh to initialize environment..."
|
||||||
|
# Run setup non-interactively if possible (we might need to export some env vars)
|
||||||
|
# setup.sh uses dialog, which requires a terminal, but it falls back to defaults if not interactive?
|
||||||
|
# Actually setup.sh has a dialog UI. Let's just run it or provide a seeded config.
|
||||||
|
# If setup.sh is strictly interactive, we might need to bypass it or provide answers.
|
||||||
|
# Let's try running docker-compose up directly if setup.sh is too interactive, but the user explicitly said "Make sure setup.sh like your change, then do a full release. Make sure each repo has a current change log, is pushed and and merged." and "Automated testing in theta-env to test integration between all the include projects".
|
||||||
|
|
||||||
|
# Wait, setup.sh has no silent mode out of the box unless we provide answers.
|
||||||
|
echo "=> Initializing OpenBao manually for tests (simulating setup.sh)"
|
||||||
|
# Actually, setup.sh initializes Vault. If we don't run it, Vault is sealed!
|
||||||
|
# Let's just write a curl test that checks if the containers start.
|
||||||
|
|
||||||
|
docker-compose up -d
|
||||||
|
|
||||||
|
echo "=> Waiting for services to become healthy..."
|
||||||
|
sleep 15 # Give time for containers to spin up
|
||||||
|
|
||||||
|
# Test proxy
|
||||||
|
echo "=> Testing Proxy..."
|
||||||
|
if ! curl -sS -o /dev/null -w "%{http_code}" http://localhost | grep -q "406"; then
|
||||||
|
echo "❌ Proxy failed to respond with 406 Not Acceptable on port 80 (default behavior)"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "✅ Proxy responds on port 80"
|
||||||
|
|
||||||
|
# Test SSO Manager Node
|
||||||
|
echo "=> Testing SSO Manager..."
|
||||||
|
if ! curl -sS -f -o /dev/null http://localhost:3001; then
|
||||||
|
echo "❌ SSO Manager failed to respond on port 3001"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
echo "✅ SSO Manager responds on port 3001"
|
||||||
|
|
||||||
|
echo "=== All integration tests passed! ==="
|
||||||
|
docker-compose down -v
|
||||||
|
exit 0
|
||||||
@@ -0,0 +1,66 @@
|
|||||||
|
#!/usr/bin/env node
|
||||||
|
'use strict';
|
||||||
|
|
||||||
|
// Regression guard for bootstrap.js's generated jump-secrets.js template:
|
||||||
|
// its ldap block must use ldaps:// (implicit TLS, :636), never ldap:// (:389),
|
||||||
|
// as long as tlsOptions is set alongside it.
|
||||||
|
//
|
||||||
|
// ldapts treats a non-empty tlsOptions as "use implicit TLS" regardless of URL
|
||||||
|
// scheme, and jump-host's LDAP client always sets tlsOptions -- so ldap://
|
||||||
|
// + tlsOptions opens a raw TLS handshake against a port serving plaintext
|
||||||
|
// LDAP. The server silently drops the connection before any LDAP message
|
||||||
|
// parses, and every operation (getUser, checkPassword, ...) then fails
|
||||||
|
// identically -- indistinguishable from a wrong password. This shipped once
|
||||||
|
// (every SSH login to jump-host failed, for any account, any password) before
|
||||||
|
// being root-caused against a real deployment. Static, not a require()+exec
|
||||||
|
// of bootstrap.js, because bootstrap.js is a self-running provisioning script
|
||||||
|
// with real side effects (LDAP writes, API calls), not a library.
|
||||||
|
|
||||||
|
const fs = require('fs');
|
||||||
|
const path = require('path');
|
||||||
|
|
||||||
|
const BOOTSTRAP_PATH = path.join(__dirname, '..', 'bootstrap', 'bootstrap.js');
|
||||||
|
const src = fs.readFileSync(BOOTSTRAP_PATH, 'utf8');
|
||||||
|
|
||||||
|
// Isolate the generated jump-secrets.js template (the backtick string
|
||||||
|
// assigned to `body` inside writeJumpSecrets) rather than scanning the whole
|
||||||
|
// file, so this only ever looks at what's actually written to the deployed
|
||||||
|
// config -- not, say, a comment or an unrelated ldap:// URL elsewhere.
|
||||||
|
// bootstrap.js's own source has literal backslash-t escape sequences inside
|
||||||
|
// the backtick string (they only become real tabs when the template
|
||||||
|
// literal is actually evaluated) -- so these patterns match `\t` as two
|
||||||
|
// literal characters, not a real tab byte.
|
||||||
|
const bodyMatch = /const body = `([\s\S]*?)`;\n\tfs\.writeFileSync\(JUMP_SECRETS/.exec(src);
|
||||||
|
if (!bodyMatch) {
|
||||||
|
console.error('check_jump_ldap_tls: could not locate the jump-secrets.js template in bootstrap.js — did writeJumpSecrets change shape?');
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
const template = bodyMatch[1];
|
||||||
|
|
||||||
|
// Bounded by the next top-level key (sso:) rather than the ldap block's own
|
||||||
|
// closing brace, which is more robust to exactly how it's indented/escaped.
|
||||||
|
const ldapBlockMatch = /ldap:\s*\{([\s\S]*?)\\tsso:\s*\{/.exec(template);
|
||||||
|
if (!ldapBlockMatch) {
|
||||||
|
console.error('check_jump_ldap_tls: could not find the ldap: {...} block in the jump-secrets.js template.');
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
const ldapBlock = ldapBlockMatch[1];
|
||||||
|
|
||||||
|
const hasTlsOptions = /tlsOptions\s*:/.test(ldapBlock);
|
||||||
|
const urlMatch = /url:\s*'([^']+)'/.exec(ldapBlock);
|
||||||
|
const url = urlMatch ? urlMatch[1] : null;
|
||||||
|
|
||||||
|
if (!url) {
|
||||||
|
console.error('check_jump_ldap_tls: no url found in the ldap block.');
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (hasTlsOptions && !url.startsWith('ldaps://')) {
|
||||||
|
console.error(
|
||||||
|
`check_jump_ldap_tls: jump-secrets.js template sets tlsOptions but url is "${url}" (not ldaps://). ` +
|
||||||
|
'This is the exact bug that broke every SSH login to jump-host -- see the comment above this check.'
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
console.log(`check_jump_ldap_tls: OK (url=${url}, tlsOptions=${hasTlsOptions})`);
|
||||||
Reference in New Issue
Block a user