fix: the hunt runner gets its own ClickHouse user - #197
Open
catinspace-au wants to merge 1 commit into
Open
catinspace-au wants to merge 1 commit into
catinspace-au wants to merge 1 commit into
Conversation
The hunt runner ran INSERT ... SELECT built from rule text as `default`, which can reach url(), s3(), remote() and file(). It now dials dfe_hunt_runner, which holds SELECT and INSERT on the data database and nothing else. - `make init` mints DFE_HUNT_RUNNER_CLICKHOUSE_PASSWORD into .env like the other generated secrets, topping up an existing .env. - Compose hands it to the engine as DFE_CLICKHOUSE_HUNT_RUNNER_PASSWORD, so the engine creates the user on that password, and to the runner as its own password, with the username fixed at dfe_hunt_runner. - `make post` fails while it is empty on a stack that runs the runner. Needs a dfe-engine that adopts the provided password and a dfe-schemas that mints hunt_runner. On an older pair the user never exists and the runner cannot connect.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
HOLD: merges in the GA lane after the dfe-schemas and engine releases. Merged before them, the runner dials
dfe_hunt_runner, a user that only exists once a released dfe-schemas (role catalogue 1.1.0, dfe-schemas#54) and a released engine that adopts the provided password (dfe-engine#737) are on the stack.The hunt runner ran
INSERT ... SELECTbuilt from rule text asdefault, which can reachurl(),s3(),remote()andfile(). It now dialsdfe_hunt_runner, which holdsSELECTandINSERTon the data database and nothing else.make initmintsDFE_HUNT_RUNNER_CLICKHOUSE_PASSWORDinto.envlike the other generated secrets, and tops up an existing.envthat predates it.DFE_CLICKHOUSE_HUNT_RUNNER_PASSWORD, so the engine creates the user on that password, and to the runner as its own password, with the username fixed atdfe_hunt_runner. The engine and everything else stay ondefault.make postfails while it is empty on a stack that runs the runner.docs/operating.mdstops counting the generated secrets (it said three; there are eight) and points atGENERATED_SECRETS.Proof, run locally:
make check-python,check-tests(771 passed),check-docs,check-hardfail,check-compose(every path resolves) andcheck-profilesagainst the matching dfe-infra branch all pass.check-dockerfilenot run here: the Dockerfile is untouched.Not proven here: a full stack run with the runner on
dfe_hunt_runner. It needs the released engine and dfe-schemas; until then the POST hunt claim is the check to run once both are pinned.Done when the dfe-schemas and engine releases are on the stack and this merges in the GA lane.