Skip to content

fix: the hunt runner gets its own ClickHouse user - #197

Open
catinspace-au wants to merge 1 commit into
mainfrom
fix/ch-least-privilege
Open

catinspace-au wants to merge 1 commit into
mainfrom
fix/ch-least-privilege

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

HOLD: merges in the GA lane after the dfe-schemas and engine releases. Merged before them, the runner dials dfe_hunt_runner, a user that only exists once a released dfe-schemas (role catalogue 1.1.0, dfe-schemas#54) and a released engine that adopts the provided password (dfe-engine#737) are on the stack.

The hunt runner ran INSERT ... SELECT built from rule text as default, which can reach url(), s3(), remote() and file(). It now dials dfe_hunt_runner, which holds SELECT and INSERT on the data database and nothing else.

  • make init mints DFE_HUNT_RUNNER_CLICKHOUSE_PASSWORD into .env like the other generated secrets, and tops up an existing .env that predates it.
  • Compose hands it to the engine as DFE_CLICKHOUSE_HUNT_RUNNER_PASSWORD, so the engine creates the user on that password, and to the runner as its own password, with the username fixed at dfe_hunt_runner. The engine and everything else stay on default.
  • make post fails while it is empty on a stack that runs the runner.
  • docs/operating.md stops counting the generated secrets (it said three; there are eight) and points at GENERATED_SECRETS.

Proof, run locally: make check-python, check-tests (771 passed), check-docs, check-hardfail, check-compose (every path resolves) and check-profiles against the matching dfe-infra branch all pass. check-dockerfile not run here: the Dockerfile is untouched.

Not proven here: a full stack run with the runner on dfe_hunt_runner. It needs the released engine and dfe-schemas; until then the POST hunt claim is the check to run once both are pinned.

Done when the dfe-schemas and engine releases are on the stack and this merges in the GA lane.

The hunt runner ran INSERT ... SELECT built from rule text as `default`, which can reach url(), s3(), remote() and file(). It now dials dfe_hunt_runner, which holds SELECT and INSERT on the data database and nothing else.

- `make init` mints DFE_HUNT_RUNNER_CLICKHOUSE_PASSWORD into .env like the other generated secrets, topping up an existing .env.
- Compose hands it to the engine as DFE_CLICKHOUSE_HUNT_RUNNER_PASSWORD, so the engine creates the user on that password, and to the runner as its own password, with the username fixed at dfe_hunt_runner.
- `make post` fails while it is empty on a stack that runs the runner.

Needs a dfe-engine that adopts the provided password and a dfe-schemas that mints hunt_runner. On an older pair the user never exists and the runner cannot connect.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant