DiamondLightSource / DiamondLightSource/smartem-devtools

Agent: require TLS for backend communication in production, with a development override

Aperta
#236 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
security
Lingua principale
TypeScript
Stelle
0
Fork
0
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Split out of #85, which bundled it with the Keycloak authentication work. The authentication
half is delivered; this half is untouched and is independent of it.

## Requirement

The agent should refuse to talk to the backend over an unencrypted connection when running in
production mode, and this should be the default. Development needs an explicit override, since
the local k3s setup and test runs use plain HTTP.

## Current state

There is no transport enforcement in the agent at all:

- No scheme validation on the configured backend URL.
- No production/development distinction governing transport.
- The default is `api_url: str = "http://127.0.0.1:8000"`
(`src/smartem_agent/__main__.py`), which is correct for local development but means nothing
prevents that shape of URL in a deployed agent.

Certificate verification behaviour is likewise unspecified rather than deliberately configured.

## Scope

- Reject non-HTTPS backend URLs by default, with a clear startup error rather than a late
runtime failure - the agent runs unattended on EPU workstations, so failing fast at start is
much better than failing on first write.
- Provide an explicit development override (environment variable or CLI flag). It should be
obvious in the logs when the override is active.
- Decide and document certificate verification: whether a custom CA bundle needs supporting for
DLS-internal certificates, and whether verification may ever be relaxed.
- Confirm what the backend actually terminates TLS with in each environment - this likely
interacts with the ingress and service-exposure work in #181.

## Notes

Agents run on Windows EPU workstations near the microscopes, so certificate trust needs to work
on Windows as well as on Linux development machines.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Direzione di ricerca

Inizia da src/smartem_agent/__main__.py e segui come vengono configurati api_url, la modalità production/development e gli errori di avvio. Esamina il lavoro su ingress ed esposizione dei servizi in #181, quindi determina i requisiti per la verifica dei certificati e per le CA personalizzate su Windows e Linux. Il lavoro è completato quando production rifiuta HTTP all'avvio, development richiede un override esplicito registrato nei log e la policy TLS è documentata.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
python
Ambito
backend, security
Tipo di issue
Funzionalità
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
48/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.