Repository navigation
fix: mint a per-deploy HyperDX session secret - #204
Merged
Merged
Conversation
HyperDX signs its session cookie with a key published in upstream's source whenever EXPRESS_SESSION_SECRET is unset, and nothing here set it. So every compose deployment shared one key anyone can read. make init now mints HYPERDX_EXPRESS_SESSION_SECRET with the other generated secrets: 48 alphanumeric chars, topped up into an existing .env that predates it, never overwritten on a re-run. Compose hands it to the hyperdx container as EXPRESS_SESSION_SECRET. Same shape as NEXTAUTH_SECRET, not a :? hard-fail. Compose interpolates every service before profiles filter, so a :? would break make down for anyone not running HyperDX. The sentinel default is what make post fails on instead.
This was referenced Oct 6, 2026
HyperDX stores third-party tokens (Slack bot tokens, OAuth tokens) in plain text unless TOKEN_ENCRYPTION_KEY is set, and nothing here set it. make init now mints HYPERDX_TOKEN_ENCRYPTION_KEY and compose hands it to the hyperdx container. The format is the one the fork parses (packages/api/src/utils/tokenEncryption.ts:150): 64 hex chars, 32 bytes. HyperDX refuses to start on a malformed key, so the compose fallback is empty, which reads as encryption off, never a sentinel. make post fails while it is empty. The README and docs now list both HyperDX keys among the generated secrets.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two HyperDX keys nothing in this repo set.
HyperDX falls back to a session secret published in upstream's source when
EXPRESS_SESSION_SECRETis unset (packages/api/src/config.ts:16in our fork, upstream 2.40.0), so every compose deployment signed HyperDX sessions with the same public key. And withoutTOKEN_ENCRYPTION_KEYit stores third-party tokens (Slack bot tokens, OAuth tokens) in plain text.make initmints both with the other generated secrets, topped up into an existing.envthat predates them, never overwritten on a re-run.HYPERDX_EXPRESS_SESSION_SECRET: 48 alphanumeric chars.HYPERDX_TOKEN_ENCRYPTION_KEY: 64 hex chars (32 bytes), the format the fork parses (packages/api/src/utils/tokenEncryption.ts:150).hyperdxcontainer asEXPRESS_SESSION_SECRETandTOKEN_ENCRYPTION_KEY.${VAR:?}. Compose interpolates every service before profiles filter, so a:?would breakmake downfor anyone not running HyperDX.NEXTAUTH_SECRETuses.tokenEncryption.ts:259->server.ts:92->index.ts:38-44exits), and empty reads as encryption off.make postfails while either is at its fallback (WEAK_SECRET_DEFAULTS, scoped to thehyperdxservice)..env.example, README and docs list both among the generated secrets.Tests:
test_hyperdx.pychecks compose reads each minted key, the fallback compose runs on is exactly whatmake postrefuses, the minted token key is 64 hex chars that decode to 32 bytes, and a.envthat predates either key gets one on re-init and keeps it.The pinned HyperDX image (
v0.2.7) readsEXPRESS_SESSION_SECRETtoday. It predatestokenEncryption.ts, soTOKEN_ENCRYPTION_KEYtakes effect from the first fork release that carries it.The Kubernetes half is hyperi-io/dfe-infra#530. Profile projection here goes green once #205 is in.
Done when CI is green and a fresh
make initleaves both keys live in.env.