feat(deployment): add secure Linux runtime (#17)
This commit is contained in:
@@ -88,3 +88,60 @@ jobs:
|
||||
else
|
||||
echo "Network namespaces/NAT tooling unavailable; deterministic loopback topology remains the required gate."
|
||||
fi
|
||||
|
||||
container:
|
||||
needs: quality
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
- name: Check out repository
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install .NET SDK
|
||||
uses: actions/setup-dotnet@v4
|
||||
with:
|
||||
dotnet-version: 10.0.301
|
||||
|
||||
- name: Build deployment diagnostic
|
||||
run: |
|
||||
dotnet restore src/FinalFactory.Rendezvous.TestClient/FinalFactory.Rendezvous.TestClient.csproj --locked-mode
|
||||
dotnet build src/FinalFactory.Rendezvous.TestClient/FinalFactory.Rendezvous.TestClient.csproj --configuration Release --no-restore
|
||||
|
||||
- name: Build and exercise hardened container
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
compose_file="deploy/compose/compose.yaml"
|
||||
secret="deploy/compose/secrets/signing-key"
|
||||
cleanup() {
|
||||
RENDEZVOUS_UID=1654 RENDEZVOUS_GID=1654 \
|
||||
docker compose -f "$compose_file" down --volumes >/dev/null 2>&1 || true
|
||||
rm -f "$secret"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
install -d -m 0700 deploy/compose/secrets
|
||||
openssl rand -out "$secret" 32
|
||||
chmod 0444 "$secret"
|
||||
export RENDEZVOUS_UID=1654
|
||||
export RENDEZVOUS_GID=1654
|
||||
docker compose -f "$compose_file" up --build --detach
|
||||
container_id="$(docker compose -f "$compose_file" ps -q rendezvous)"
|
||||
test -n "$container_id"
|
||||
test "$(docker inspect --format '{{.Config.User}}' "$container_id")" = "1654:1654"
|
||||
test "$(docker inspect --format '{{.HostConfig.ReadonlyRootfs}}' "$container_id")" = "true"
|
||||
test "$(docker inspect --format '{{range .Mounts}}{{if eq .Destination \"/app/appsettings.Production.json\"}}{{.RW}}{{end}}{{end}}' "$container_id")" = "false"
|
||||
test "$(docker inspect --format '{{range .Mounts}}{{if eq .Destination \"/run/secrets/rendezvous-signing-key\"}}{{.RW}}{{end}}{{end}}' "$container_id")" = "false"
|
||||
for attempt in {1..100}; do
|
||||
if curl --fail --silent http://127.0.0.1:8080/health/ready >/dev/null 2>&1; then
|
||||
break
|
||||
fi
|
||||
if (( attempt == 100 )); then
|
||||
docker compose -f "$compose_file" logs rendezvous
|
||||
exit 1
|
||||
fi
|
||||
sleep 0.1
|
||||
done
|
||||
./scripts/smoke-deployment.sh
|
||||
docker compose -f "$compose_file" stop --timeout 40 rendezvous
|
||||
test "$(docker inspect --format '{{.State.Running}}' "$container_id")" = "false"
|
||||
test "$(docker inspect --format '{{.State.ExitCode}}' "$container_id")" = "0"
|
||||
|
||||
Reference in New Issue
Block a user