Repository navigation
fix(deploy): build the CUBRID-profile image with the auth extra - #1033
Merged
Merged
Conversation
A build argument replaces the Dockerfile's default EXTRAS, so the cubrid variant lost pyjwt and could not start with OIDC configured (#992). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
3 tasks
Collaborator
Author
|
owner 가 이 변경을 확인하고 승인했습니다 (GitHub 리뷰가 아니라 직접 — 작성 계정이 owner 계정이라 리뷰로 남길 수 없습니다). CI 는 CLEAN 입니다. 머지합니다. |
2 of 3 tasks
yeongseon
pushed a commit
that referenced
this pull request
Oct 6, 2026
…1057) ## 무엇을 #992 의 남은 항목 가운데 "OIDC 설정으로 `serve` 기동 → `/healthz` 200" 스모크를 더합니다. 테스트 파일 하나와 CHANGELOG 뿐이고, 서비스 코드는 바꾸지 않았습니다. ## 어떻게 `tests/unit/test_oidc_start_smoke.py` 가 실제 `serve` 명령을 별도 프로세스로 띄웁니다. 환경은 다중 사용자 프로필입니다. ``` OIDC_ISSUER, OIDC_AUDIENCE, KPUBDATA_BUILDER_ADMIN_SUBJECTS=<issuer>|<sub>, KPUBDATA_BUILDER_REQUIRE_OWN_PROVIDER_CREDENTIAL=true ``` `DEV_MODE`, `API_KEY`, `CREDENTIAL_MASTER_KEY` 는 테스트 실행 환경에 있더라도 빼고 띄웁니다. - 프로세스가 뜨고 `GET /healthz` → 200 `{"status": "ok"}` - 토큰 없이 `/providers`, `/builds`, `/version` → 401 `unauthorized` - 검증할 수 없는 토큰 → 401 또는 503 `auth_unavailable` (통과시키지 않음) - 부정: `OIDC_AUDIENCE` 가 없거나 `ADMIN_SUBJECTS` 가 없으면 "refusing to start" 로 종료 kpubdata 0.9.0 pin(#1050) 덕에 가능해졌습니다 — `REQUIRE_OWN_PROVIDER_CREDENTIAL` 이 켜져 있으면 `serve` 는 `env_keys` 를 모르는 kpubdata 에서 기동을 거부합니다(#990). ## 한계 - IdP 에 닿지 않습니다(`idp.invalid`). **서비스가 뜨고 닫혀 있다**는 것만 보이고, 로그인이 된다는 것은 보이지 않습니다. 수용 기준의 "실 Keycloak 토큰으로 `GET /providers` 200" 은 실제 realm 이 정해진 뒤의 일입니다. - 컨테이너나 compose 를 띄우지 않습니다. 이미지·compose 의 변수 전달은 `test_prod_oidc_plumbing.py` 가 파일로 확인합니다. - 손으로 띄웠을 때 본 것: 토큰이 없을 때의 401 문구가 OIDC 배포에서도 `api key not configured` 입니다. 동작은 맞고 문구만 어색합니다. 이 PR 에서는 건드리지 않았습니다. ## #992 수용 기준 대조 - [x] 배포 이미지에서 `import jwt` — #1020, #1033 - [x] OIDC 변수가 있는 프로필이 CI 에서 기동 스모크를 통과 — **이 PR** (프로세스 기동 기준. 컨테이너 기동은 아님) - [ ] 실 Keycloak 토큰으로 `GET /providers` 200 — 배포 대상·realm 결정 필요 ## 검증 - 새 파일 5건 통과 (약 5초), `ruff`, `mypy` 통과 - 전체 단위 스위트는 로컬에서 돌리지 않았습니다(테스트 추가만). CI 에 맡깁니다. Refs #992 (닫지 않습니다) 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Eomdahyeon <213566566+Eomdahyeon@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #992
문제
#1020 이 기본 이미지의
EXTRAS를publish auth로 바꿨지만,docker.yml의 CUBRID 변형은EXTRAS=publish cubrid로 빌드한다. build-arg 는 Dockerfile 의 기본값에 더해지는 것이 아니라 통째로 덮어쓰므로,:cubrid이미지에는pyjwt가 없고OIDC_ISSUER를 설정하면 기동을 거부한다. #1020 본문이 남긴 항목이고, 워크플로 파일이라 작성자 계정으로는 고칠 수 없었다.변경
docker.yml:EXTRAS=publish auth cubrid, 그리고 왜 기본 extra 를 다시 적어야 하는지 주석.tests/unit/test_prod_oidc_plumbing.py: 워크플로의 모든EXTRAS=변형이 Dockerfile 기본값의 extra 를 전부 포함하는지. 기본값에 extra 가 추가되면 변형도 따라가야 한다.[Unreleased]Fixed.하지 않은 것 — 그래서
Refsdeploy.yml이 OIDC 변수를.env로 렌더하는 부분은 손대지 않았다. 배포 대상이 정해지지 않았다.검증
python3로 직접 호출: 통과.docker.yml변경을 되돌리면AssertionError로 실패한다 (확인함).ruff check,ruff format --check,check_english_comments.py통과.:cubrid이미지는mainpush 에서만 빌드되므로 이 PR 의 CI 는import jwt를 확인하지 못한다.🤖 Generated with Claude Code