Demo images / Build & push demo images (push) Failing after 2m28s
Scrubs the fleet SSH/UI password from every tracked file (22 occurrences) and removes inline credentials from the code paths that used them. Docs and trackers keep the surrounding context — these are published under docs/history/ per the open-source plan — with the literals replaced by <FLEET_PW> / <FLEET_PW_ALT> so the "two variants exist" detail survives without the values. Three of the eight files were in .planning/ and were NOT in the plan's enumerated list; the reworked audit-secrets.sh found them. Code changes: - neode-ui/test-openwrt.mjs: node URL and password come from ARCHY_NODE_URL / ARCHY_NODE_PW; the SSH target derives from the URL instead of a hardcoded tailnet IP; exits 2 when unset. - scripts/run-post-install-tests.sh: drops the built-in "testpass123!" default and adds --password-stdin; refuses to run unauthenticated instead of silently trying a known password. --phase1-only still needs no password. - .gitea/workflows/post-install-tests.yml: sshpass with an inline literal replaced by key auth (NODE_SSH_KEY secret); password comes from the NODE_UI_PASSWORD secret and is piped over stdin rather than argv, so it stays out of the node's process list and the job log. Default target IP removed. scripts/audit-secrets.sh now reports 5/5 pass, 0 fail. Note: rotation of the exposed credentials is deliberately deferred to the pre-publish gate and is NOT done by this commit — these values are still live. See Phase 0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
84 lines
2.7 KiB
YAML
84 lines
2.7 KiB
YAML
name: Post-Install Tests
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
target:
|
|
description: 'Target node IP or hostname'
|
|
required: true
|
|
password:
|
|
description: 'Node UI password (leave blank to use the NODE_UI_PASSWORD secret)'
|
|
required: false
|
|
|
|
jobs:
|
|
post-install-tests:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 1
|
|
|
|
- name: Install SSH key
|
|
env:
|
|
SSH_KEY: ${{ secrets.NODE_SSH_KEY }}
|
|
run: |
|
|
if [ -z "$SSH_KEY" ]; then
|
|
echo "ERROR: repository secret NODE_SSH_KEY is not configured."
|
|
echo "Post-install tests authenticate by key; password auth is not supported."
|
|
exit 1
|
|
fi
|
|
mkdir -p ~/.ssh && chmod 700 ~/.ssh
|
|
printf '%s\n' "$SSH_KEY" > ~/.ssh/id_ed25519
|
|
chmod 600 ~/.ssh/id_ed25519
|
|
|
|
- name: Run post-install tests on target
|
|
env:
|
|
TARGET: ${{ github.event.inputs.target }}
|
|
NODE_PASSWORD: ${{ github.event.inputs.password }}
|
|
NODE_UI_PASSWORD: ${{ secrets.NODE_UI_PASSWORD }}
|
|
SSH_USER: ${{ vars.NODE_SSH_USER }}
|
|
run: |
|
|
PASSWORD="${NODE_PASSWORD:-$NODE_UI_PASSWORD}"
|
|
if [ -z "$PASSWORD" ]; then
|
|
echo "ERROR: no node password supplied (input or NODE_UI_PASSWORD secret)."
|
|
exit 1
|
|
fi
|
|
USER_NAME="${SSH_USER:-archipelago}"
|
|
|
|
echo "══════════════════════════════════════════"
|
|
echo "Running post-install tests on $TARGET"
|
|
echo "══════════════════════════════════════════"
|
|
|
|
scp -o StrictHostKeyChecking=accept-new \
|
|
scripts/run-post-install-tests.sh \
|
|
"${USER_NAME}@${TARGET}:/tmp/run-post-install-tests.sh"
|
|
|
|
# Password is passed over stdin, never as an argv the node's process
|
|
# list (or this job's log) would expose.
|
|
printf '%s' "$PASSWORD" | ssh -o StrictHostKeyChecking=accept-new \
|
|
"${USER_NAME}@${TARGET}" \
|
|
"sudo bash /tmp/run-post-install-tests.sh --password-stdin"
|
|
|
|
frontend-tests:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 1
|
|
|
|
- name: Install dependencies
|
|
run: cd neode-ui && npm ci
|
|
|
|
- name: Type check
|
|
run: cd neode-ui && npx vue-tsc -b --noEmit
|
|
|
|
- name: Run tests
|
|
run: cd neode-ui && npx vitest run
|
|
|
|
- name: Audit dependencies
|
|
run: cd neode-ui && npm audit --omit=dev
|