cloudfoundry / cloudfoundry/capi-release
db_encryption_key is not yaml escaped
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 24
- Forks
- 110
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 8
Description
Issue
db_encryption_key is incorrectly parsed if it has a leading #. This is because hashes are interpreted as comments if not escaped/quoted
We need to yaml_escape it (and potentially review other password/key fields) before rendering it to cloud_controller.yml
Context
with the following password:
egrep db_encryption_key /var/vcap/jobs/cloud_controller_ng/config/cloud_controller_ng.yml
db_encryption_key: #mypassword
bosh deployment prestart fails on cloud_controller_ng job with prestart logs reporting the following
Running migrations
[2022-01-06 14:29:08+0000] Running migration try number 1 of 3
[2022-01-06 14:31:43+0000] VCAP::CloudController::ValidateDatabaseKeys::DatabaseEncryptionKeyMissingError
[2022-01-06 14:31:43+0000] No database encryption keys are specified
[2022-01-06 15:16:55+0000] Waiting for bosh_dns
Steps to Reproduce
- Set
cc.db_encryption_keyto something like#mypasswordin the bosh manifest - Deploy
Expected result
The key is set correctly and the deploy succeeds
Current result
prestart fails with DatabaseEncryptionKeyMissingError
Possible Fix
Use https://github.com/cloudfoundry/capi-release/blob/e0582bc93edde2851764ce42e2dbebe18baa4218/jobs/cloud_controller_ng/templates/cloud_controller_ng.yml.erb#L11-L19
We should probably also do a review and see if there are other fields that should be escaped
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading jobs/cloud_controller_ng/templates/cloud_controller_ng.yml.erb around lines 11–19, then reproduce the issue with a db_encryption_key beginning with # and inspect the generated cloud_controller_ng.yml. Done means the key is preserved in the rendered configuration and the cloud_controller_ng prestart and database migration succeed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- yaml
- Domain
- cloud, infrastructure
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100