The image cannot be built: the Dockerfile passes a key #111 refuses #121
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#121
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What happened
Building the image fails at
collectstatic:Found while deploying the test instance. The container already running is untouched — the
build never produced an image — but no instance can be rebuilt or upgraded until this
is fixed.
Why it was not caught
#111 made the production settings refuse a key shorter than 50 characters. Two places pass
a key that is not a real one:
.forgejo/workflows/ci.ymlpasses a long literal, with a comment saying it is longenough for
security.W009. It still passes.docker/Dockerfile:99passesbuild-time-only-not-a-secret— 28 characters. It does not.CI does not build the image, because building one needs a runner advertising the
dockerlabel and none is registered (#81). So the one check that would have caught this is the one
that has never run, and the refusal landed green.
The fix
The build step needs a key for the length of one command, and it never reaches the image.
A longer literal would satisfy the rule while remaining exactly what its own name says it is
— and would be copied by somebody. Generating a random key for that single command satisfies
the rule for the right reason and cannot be copied anywhere.
Worth stating in the Dockerfile beside it:
collectstaticneeds a key only because thesettings module insists on one, not because anything it writes is signed with it.
Worth being careful about
The real hole is that the image build is not exercised anywhere. The fix above unblocks
today; #81 is what stops the next version of this happening.
The Dockerfile now generates its build-time key inline —
POSTULO_SECRET_KEY="$(python -c 'import secrets; print(secrets.token_urlsafe(64))')"— instead of carrying a 28-character literal that #111 correctly refuses. A generated key also cannot be the one an instance ends up running, which the literal could have been.tests/test_image_build.pyreads the Dockerfile rather than building it, so the same mistake fails in the ordinary suite in milliseconds instead of on a runner ten minutes in. Proved by a successful rebuild on ragnar.Shipped in
d0cc4c8on0.3.0, withmainkept level.