Edge nodes are deployed to arbitrary locations by arbitrary people, so the
broker has to be reachable from the internet and secured on its own merits
rather than by a VPN.
Three defects made that impossible. The broker only had a plaintext 1883
listener; every node shared one drb-node password; and the ACL pattern used
%c, the client-supplied client id, so any holder of that shared password
could set client_id to another node and take over its namespace. The comment
claiming this cryptographically prevented cross-node access was wrong and is
gone.
Authentication now uses mosquitto 2.x's built-in dynamic-security plugin on
the stock eclipse-mosquitto image. c2-core administers it over the control
topic, creating each node's client on approval with username=<node_id> and
password=<its node_keys api_key>, attached to a role whose ACL is nodes/%u/#
against the authenticated username. One credential, one revocation point.
An HTTP-callback plugin was implemented first and rejected: that project is
archived upstream, which is not an acceptable dependency on an
internet-facing broker.
Because dynsec state is a second source of truth alongside Firestore,
approve/reissue/delete now write to the broker first and surface a 502
rather than drifting, and c2-core reconciles every approved node into dynsec
on startup.
Adds node self-enrollment (POST /nodes/enroll, GET /nodes/{id}/credentials)
so a new node can obtain its key over HTTPS without an operator handling
secrets by hand. Enrolling an already-approved node_id is refused on the
fleet token alone — otherwise a leaked token plus a guessable id would let
an attacker steal a live node's key before the real node asked for it.
Pickup secrets are stored hashed and returned once, and the endpoint is rate
limited per source IP.
Infrastructure: an 8883 TLS listener fed by Caddy's certificate via a
systemd path unit, a firewall rule for it, and Caddy now 404s /internal/*
so the api vhost cannot proxy internal routes.
Also fixes CORS, which allowed https://app.<domain> while the frontend is
served on the bare domain — every call from the portal would have failed —
and widens the vault gitignore to a glob, since ansible-vault leaves
backup siblings that the exact-name rule left committable.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
105 lines
3.3 KiB
YAML
105 lines
3.3 KiB
YAML
name: Build & Deploy
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
env:
|
|
# REGISTRY secret = "git.vpn.cusano.net/logan" (full image prefix)
|
|
REGISTRY: ${{ secrets.REGISTRY }}
|
|
|
|
jobs:
|
|
build:
|
|
name: Build & push images
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
|
|
- name: Log in to Gitea registry
|
|
uses: docker/login-action@v3
|
|
with:
|
|
registry: git.vpn.cusano.net
|
|
username: ${{ secrets.REGISTRY_USER }}
|
|
password: ${{ secrets.BUILD_TOKEN }}
|
|
|
|
- name: Build & push c2-core
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: ./drb-c2-core
|
|
push: true
|
|
tags: |
|
|
${{ env.REGISTRY }}/c2-core:latest
|
|
${{ env.REGISTRY }}/c2-core:${{ gitea.sha }}
|
|
|
|
- name: Build & push discord-bot
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: ./drb-server-discord-bot
|
|
push: true
|
|
tags: |
|
|
${{ env.REGISTRY }}/discord-bot:latest
|
|
${{ env.REGISTRY }}/discord-bot:${{ gitea.sha }}
|
|
|
|
- name: Build & push frontend
|
|
uses: docker/build-push-action@v5
|
|
with:
|
|
context: ./drb-frontend
|
|
push: true
|
|
tags: |
|
|
${{ env.REGISTRY }}/frontend:latest
|
|
${{ env.REGISTRY }}/frontend:${{ gitea.sha }}
|
|
build-args: |
|
|
NEXT_PUBLIC_C2_URL=https://api.${{ secrets.DRB_DOMAIN }}
|
|
NEXT_PUBLIC_FIREBASE_API_KEY=${{ secrets.FIREBASE_API_KEY }}
|
|
NEXT_PUBLIC_FIREBASE_AUTH_DOMAIN=${{ secrets.FIREBASE_AUTH_DOMAIN }}
|
|
NEXT_PUBLIC_FIREBASE_PROJECT_ID=${{ secrets.FIREBASE_PROJECT_ID }}
|
|
NEXT_PUBLIC_FIREBASE_STORAGE_BUCKET=${{ secrets.FIREBASE_STORAGE_BUCKET }}
|
|
NEXT_PUBLIC_FIREBASE_MESSAGING_SENDER_ID=${{ secrets.FIREBASE_MESSAGING_SENDER_ID }}
|
|
NEXT_PUBLIC_FIREBASE_APP_ID=${{ secrets.FIREBASE_APP_ID }}
|
|
NEXT_PUBLIC_FIRESTORE_DATABASE=${{ secrets.FIRESTORE_DATABASE }}
|
|
|
|
deploy:
|
|
name: Deploy to VM
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Check runner outbound IP
|
|
run: curl -s ifconfig.me
|
|
|
|
- name: Write SSH key
|
|
run: |
|
|
printf '%s\n' "${{ secrets.SSH_PRIVATE_KEY }}" > /tmp/deploy_key
|
|
chmod 600 /tmp/deploy_key
|
|
ssh-keygen -l -f /tmp/deploy_key
|
|
|
|
- name: Deploy
|
|
run: |
|
|
ssh -o StrictHostKeyChecking=no \
|
|
-o HostKeyAlgorithms=ssh-ed25519,rsa-sha2-256,rsa-sha2-512 \
|
|
-o ConnectTimeout=15 \
|
|
-v \
|
|
-i /tmp/deploy_key \
|
|
drb@${{ secrets.SERVER_IP }} << 'ENDSSH'
|
|
set -e
|
|
cd /opt/drb
|
|
|
|
# Update compose files + mosquitto config
|
|
git pull origin main
|
|
|
|
# Pull pre-built images and restart (no build on the VM)
|
|
docker compose -f docker-compose.yml -f docker-compose.prod.yml pull
|
|
docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d --remove-orphans
|
|
docker image prune -f
|
|
ENDSSH
|
|
|
|
- name: Health check
|
|
run: |
|
|
sleep 20
|
|
curl -f https://api.${{ secrets.DRB_DOMAIN }}/health || \
|
|
(echo "Health check failed" && exit 1)
|