Repository navigation
fix(opencode): use supported ssl field for HSTS matching - #48
Merged
Merged
Conversation
Contributor
OpenTofu TestOpenTofu test passed. View run output |
Contributor
OpenTofu PlanOpenTofu plan passed. View run outputOpenTofu will perform the following actions:
# cloudflare_ruleset.response_headers will be created
+ resource "cloudflare_ruleset" "response_headers" {
+ description = "Hostname-scoped response security headers"
+ id = (known after apply)
+ kind = "zone"
+ last_updated = (known after apply)
+ name = "Response header transforms"
+ phase = "http_response_headers_transform"
+ rules = [
+ {
+ action = "rewrite"
+ action_parameters = {
+ headers = {
+ "strict-transport-security" = {
+ operation = "set"
+ value = "max-age=86400"
},
}
}
+ description = "One-day HSTS for the OpenCode HTTPS hostname only"
+ enabled = true
+ expression = "(http.host eq \"opencode.makeitwork.cloud\" and ssl)"
+ id = (known after apply)
+ logging = (known after apply)
+ ref = "opencode_hsts"
},
]
+ version = (known after apply)
+ zone_id = (sensitive value)
}
Plan: 1 to add, 0 to change, 0 to destroy.
OpenTofu will perform the following actions:
# cloudflare_ruleset.response_headers will be created
+ resource "cloudflare_ruleset" "response_headers" {
+ description = "Hostname-scoped response security headers"
+ id = (known after apply)
+ kind = "zone"
+ last_updated = (known after apply)
+ name = "Response header transforms"
+ phase = "http_response_headers_transform"
+ rules = [
+ {
+ action = "rewrite"
+ action_parameters = {
+ headers = {
+ "strict-transport-security" = {
+ operation = "set"
+ value = "max-age=86400"
},
}
}
+ description = "One-day HSTS for the OpenCode HTTPS hostname only"
+ enabled = true
+ expression = "(http.host eq \"opencode.makeitwork.cloud\" and ssl)"
+ id = (known after apply)
+ logging = (known after apply)
+ ref = "opencode_hsts"
},
]
+ version = (known after apply)
+ zone_id = (sensitive value)
}
Plan: 1 to add, 0 to change, 0 to destroy. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Correct the invalid HTTPS predicate introduced in #47. The owner requested this fix after apply attempt 2 failed with Cloudflare HTTP400/code20127:
http.request.schemeis an unknown identifier.One-line change in
cf-opencode-hsts.tf: replacehttp.request.scheme eq "https"withssl, retaining the exact hostname match. Cloudflare documentssslas a Boolean that is true when the HTTP connection to the client is encrypted.Type of change
Validation
6c5e8d7536b27c9b981d4d6f7a0be4c64f568909: run 37247544593. Apply correctly skipped. Sanitized plan: 1 add, 0 change, 0 destroy, only the HSTS ruleset, with the correctedsslpredicate. No DNS updates proposed.Independent adversarial and infrastructure-security reviews of complete commit
6c5e8d7536b27c9b981d4d6f7a0be4c64f568909found no Critical/High findings. QA review found the README/runbook remains consistent and needs no change; it explicitly identifies Cloudflare API acceptance and post-apply HTTPS/HTTP/sibling/phone behavior as uncovered by PR CI, not as completed tests. Those gates remain pending. The current Code Mode HTTP client follows redirects even with manual mode, so it cannot establish first-hop HTTP headers. Prior apply attempt 2 planned 1 add, 0 change, 0 destroy; DNS timestamp errors did not recur. This is historical evidence, not validation of this revision.Important limit: the previous invalid expression passed OpenTofu planning. Passing new PR checks will not prove Cloudflare API acceptance or deployed HSTS. No local OpenTofu execution, live mutation, or authenticated test is part of this fix.
Impact and rollout
Producer: tfroot-cloudflare edge configuration. Sole consumer is the existing Cloudflare zone response-header phase. Native auth, existing HTTPS redirection, one-day max-age, no includeSubDomains/preload, Access deferral and sibling hostname scope are unchanged. No DNS/tunnel/AWX/provider pin change.
Shared workflow at
a03d6b9and images/tfroot-runner hook ownership at2ac081dare unchanged. PR test/plan runs automatically; main merge triggers a fresh environment-associated apply, not a saved PR plan. Owner explicitly approved merge and automatic apply. Merged as0b5b5517e94c43f4414060e986ded777f141c85b; main run 37247903691 completed successfully: main test and apply passed, plan job skipped as designed. Apply reported 1 added, 0 changed, 0 destroyed. No chart/image publication, GitOps selection/reconciliation, or workload restart is involved.After approved apply, separately verify Cloudflare acceptance and HSTS on HTTPS UI and unauthenticated API responses, preserved API auth rejection, unchanged HTTP redirection and sibling-host behavior. Owner phone login/session continuity remains a separate functional check. Existing README rollback remains: serve max-age=0 over HTTPS before removing the rule; deleting a header alone does not clear cached policies. Reverting this correction would restore an invalid expression and is not a deployment rollback.
Safety and secrets
AI-authored correction and independent source reviews. The earlier field-name error was agent-authored; this correction uses the vendor field reference rather than inferring a field name.
Post-apply verification — 2026-10-05
Credentialless public checks confirmed
Strict-Transport-Security: max-age=86400on the OpenCode HTTPS UI (200) and/api/info(401 with the native Basic challenge). The HTTP probe followed a redirect to the HTTPS UI; first-hop HTTP headers are not observable with this client and are not claimed. Checked sibling hosts retained their prior statuses and no HSTS header. This establishes API acceptance and the checked public response behavior, not exhaustive sibling coverage or authenticated phone/session functionality. No credentials or cookies were retrieved. Phone login and existing-session continuity remain owner verification. No GitOps/workload rollout was required.