Skip to content

Enable user and password update - #149

Open
alicefr wants to merge 2 commits into
bootc-dev:mainfrom
alicefr:update-password
Open

alicefr wants to merge 2 commits into
bootc-dev:mainfrom
alicefr:update-password

Conversation

@alicefr

@alicefr alicefr commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

Add a new command to the registry update-credentials to update the user and password authentication for the registry.

Fixes: #148

Allow updating auth registry credentials on a running container
by overwriting the htpasswd file via exec.

Assisted-by: AI
Signed-off-by: Alice Frosi <afrosi@redhat.com>
Extend the auth registry integration test to verify password
rotation with both user and password change, and add a
CreateAuthPod helper to reduce duplication.

Assisted-by: AI
Signed-off-by: Alice Frosi <afrosi@redhat.com>
}

cmd.Flags().StringVar(&registryUser, "registry-user", "", "Username for the authenticated registry")
cmd.Flags().StringVar(&registryPassword, "registry-password", "", "Password for the authenticated registry")

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will show the password in the terminal right? We should probably use a hidden field for passwords


escaped := strings.ReplaceAll(htpasswdEntry, "'", "'\\''")
_, err = m.podman.ContainerExec(ctx, config.AuthRegistryContainerName, []string{
"/bin/sh", "-c", fmt.Sprintf("printf '%%s\\n' '%s' > /auth/htpasswd", escaped),

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we can use backticks in Sprintf which should also help with escaping quotes


escaped := strings.ReplaceAll(htpasswdEntry, "'", "'\\''")
_, err = m.podman.ContainerExec(ctx, config.AuthRegistryContainerName, []string{
"/bin/sh", "-c", fmt.Sprintf("printf '%%s\\n' '%s' > /auth/htpasswd", escaped),

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

when restart the container entrypoint re-executes this leading to file being overwritten with initial credentials

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enable password update for the registry authentication

3 participants