Files
server-26/docker-compose.yml
Logan CusanoandClaude Opus 5 865b5b4317
Build & Deploy / Build & push images (push) Successful in 4m15s
Build & Deploy / Deploy to VM (push) Successful in 1m56s
Build & Deploy / Report a failed deploy (push) Skipped
Close the /admin/features side-door that needed a container shell to flip AI spend
Board minutes #62 Decision 2 (server-26#64), due 2026-08-31. CTO draft #60
finding 1 and CISO draft #61 finding 3 reached this independently.

GET/PUT /admin/features accepted only a Firebase admin token, so the unattended
runbook had no headless path and SSHed into the c2-core container to write
config/ai_features with the admin SDK. Moving a platform-wide AI cost switch
required a full container shell, and set_flags() wrote no audit entry either
way, so a flag flip was unattributable however it happened.

- New agent_service_key (AGENT_SERVICE_KEY), deliberately separate from the
  Discord bot's service_key. Sharing one key would collapse two principals into
  a single unattributable identity in every log line, and the bot has no
  business flipping AI flags regardless.
- require_agent_key_or_admin accepts the agent key or a Firebase admin, and
  rejects the Discord key. The "key is configured" guard is load-bearing:
  compare_digest("", "") is a match, so a deployment that never set the key
  would otherwise accept an empty credential.
- set_flags() writes an audit_log entry with before/after values and the actor,
  wrapped so an audit failure cannot lose the flag write or 500 the route.
- Cascade helper sets the global doc and every system carrying an ai_flags
  override in one call. A global False already beats everything, but a system
  False beats a global True, so turning AI *on* could half-apply and leave a
  radio system hot after shutoff. It scans for the override rather than
  hardcoding the two known system IDs, so a new system cannot silently defeat
  it.
- cascade defaults to False. PUT /systems/{id}/ai-flags and the AiFlagsPanel
  toggle mean a per-system override is deliberate operator intent; cascading by
  default would erase it on any unrelated global flip. The runbook opts in.

Issue items 5 and 6 (retiring the SSH path from drb-worksession.md) are NOT
done here and the runbook is untouched. The credential does not exist in
production yet, so the SSH path is still the only one that works; retiring it
now would break the next unattended run. Owner activation is recorded on #64.

Tests 273 -> 289.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-30 02:52:00 -04:00

67 lines
2.5 KiB
YAML

services:
# Auth is mosquitto's own built-in dynamic-security plugin (see
# mosquitto.conf + app/internal/dynsec.py) — NOT mosquitto-go-auth, that
# project is archived upstream (no CVE patches), rejected for a
# public-internet broker. Stock official image, pinned to an exact patch
# (not the floating `:2` tag). MOSQUITTO_DYNSEC_PASSWORD seeds the
# plugin's own one-time "admin" bootstrap client on first boot — read
# directly by the plugin's C code, no entrypoint scripting needed for it.
mosquitto:
image: eclipse-mosquitto:2.1.2-alpine
restart: unless-stopped
ports:
- "1883:1883"
- "8883:8883"
environment:
- MOSQUITTO_DYNSEC_PASSWORD=${MOSQUITTO_DYNSEC_PASSWORD}
volumes:
- ./drb-c2-core/mosquitto/mosquitto.conf:/mosquitto/config/mosquitto.conf:ro
- mosquitto_data:/mosquitto/data
- mosquitto_certs:/mosquitto/certs
# c2-core takes ALL of its configuration from ./drb-c2-core/.env — there is
# deliberately no `environment:` block here. An entry in that block wins over
# env_file, so listing a key here (e.g. AGENT_SERVICE_KEY=${AGENT_SERVICE_KEY})
# would let an unset top-level .env silently blank out a value the owner had
# correctly pasted into drb-c2-core/.env. New settings go in
# drb-c2-core/.env.example and, for the VM, in
# infra/ansible/roles/deploy/templates/c2-core.env.j2 + vault.yml.
# AGENT_SERVICE_KEY (server-26#64) is configured that way.
c2-core:
image: ${REGISTRY}/c2-core:${TAG:-latest}
build: ./drb-c2-core
restart: unless-stopped
ports:
- "8888:8000"
env_file: ./drb-c2-core/.env
depends_on:
- mosquitto
discord-bot:
image: ${REGISTRY}/discord-bot:${TAG:-latest}
build: ./drb-server-discord-bot
restart: unless-stopped
env_file: ./drb-server-discord-bot/.env
depends_on:
- c2-core
frontend:
image: ${REGISTRY}/frontend:${TAG:-latest}
build: ./drb-frontend
restart: unless-stopped
ports:
- "3000:3000"
env_file: ./drb-frontend/.env
depends_on:
- c2-core
volumes:
# Dev only for both. Prod overrides these to host bind mounts
# (/opt/drb/mosquitto-data, /opt/drb/mosquitto-certs — the latter fed by
# the Caddy cert-sync systemd unit) — see docker-compose.prod.yml and
# infra/ansible/roles/deploy/templates/. mosquitto_data holds
# dynamic-security.json (node MQTT credentials, see app/internal/dynsec.py)
# as well as the usual broker persistence state.
mosquitto_data:
mosquitto_certs: