Repository navigation
feat(service): Share one write token across repository tenants - #4
Merged
Merged
Conversation
Replace the per-tenant token map with one shared write token. A run names its tenant as owner/repo, such as GITHUB_REPOSITORY, so a new project needs no service or Terraform change. The tenant is a namespace label, not proof of identity: a holder of the token can write any tenant's recordings. Tenant names must be exactly two safe path parts, so no tenant's prefix sits inside another's. The cap on runs without a token is now global, because a per-tenant cap could be bypassed by picking a new name. Terraform makes one write_token output instead of tenant_tokens, and the tenants variable is gone. Co-Authored-By: David Cramer <david@sentry.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adding a project to Roach used to mean adding it to
tenantsin Terraform, runningapply, and copying a new token from thetenant_tokensoutput into the project's CI secrets. With this change, a project needs no service or Terraform change. Its CI job reads one shared organization secret,ROACH_TOKEN, and names its tenant asowner/repo, usuallyGITHUB_REPOSITORY.What changed
RoachServiceConfig.tenants(one token hash per tenant) is nowwriteTokenHash, one SHA-256 for all tenants. The service has no list of tenants.RunConfig.tenantmust beowner/repo. Each part must start with a letter, a digit or_, and there must be exactly two parts. The tenant becomes the storage prefix, so this blocks..and keeps one tenant's prefix from sitting inside another's (for examplejuniorandjunior/model).random_password.write_tokenand a sensitivewrite_tokenoutput. Thetenantsvariable and thetenant_tokensoutput are removed.Trust tradeoff: the tenant name is a namespace label, not proof of identity. Any job that has
ROACH_TOKENcan write the recordings of any tenant. Give the secret only to trusted repositories and workflows, never to a workflow that runs code from a fork. Reads stay public as before, and runs without a token still can't write or go live.No compatibility path: a config with
tenantsfails at startup. Nothing is deployed yet, so this is a hard cutover.Tests:
tests/service.test.tsnow covers these cases:junior,acme/..,../acme,a/b/candacme/are refusedWith the old per-tenant cap, that last check fails.
tests/deployed.test.tsruns the production path withgetsentry/junioras the tenant.pnpm checkpasses with 16/16 tests, andterraform validatepasses.via David Cramer.
--
View Junior Session [Sentry]