Repository navigation
feat: isolate canonical known-host source validation - #72
Merged
Merged
Conversation
Contributor
OpenTofu TestOpenTofu test passed. View run output |
Contributor
OpenTofu PlanOpenTofu plan passed. View run outputOpenTofu will perform the following actions:
# github_workflow_repository_permissions.release_automation will be created
+ resource "github_workflow_repository_permissions" "release_automation" {
+ can_approve_pull_request_reviews = true
+ default_workflow_permissions = "read"
+ id = (known after apply)
+ repository = "terraform-libvirt-domain"
}
Plan: 1 to add, 0 to change, 0 to destroy.
OpenTofu will perform the following actions:
# github_workflow_repository_permissions.release_automation will be created
+ resource "github_workflow_repository_permissions" "release_automation" {
+ can_approve_pull_request_reviews = true
+ default_workflow_permissions = "read"
+ id = (known after apply)
+ repository = "terraform-libvirt-domain"
}
Plan: 1 to add, 0 to change, 0 to destroy. |
Contributor
Author
|
CI completed successfully at head
No source diagnostic, real field extraction, host connection, or apply was dispatched by this change. Successful plan execution is not a claim of a no-op or a reviewed exact infrastructure delta. Merge remains on hold pending explicit owner approval covering the existing main-apply trigger and outstanding unrelated infrastructure scope. After any separately authorized merge, manually dispatch only |
6 of 14 tasks
xnoto
added a commit
that referenced
this pull request
Oct 5, 2026
## Summary Owner-authored SOPS correction to the canonical `ssh_known_hosts` field in `secrets/secrets.yaml`. Owner reports the former entry covered the hostname while the consumer uses an IP destination; intended correction preserves hostname coverage and adds the destination alias for the same trusted key. No key material or destination is reproduced here. Commit `7547dd85872c8eb8e9883914dab01aa11257daf5` changes only `secrets/secrets.yaml` (4 additions, 4 deletions by metadata). The agent has not retrieved ciphertext or decrypted content. Fixes: N/A — follow-up to source diagnostic PR #72. ## Type of change - [x] Bug fix - [ ] Feature / enhancement - [ ] Documentation - [x] Infrastructure (OpenTofu root or module) - [ ] GitOps desired state (manifests, kustomize, charts, SOPS/KSOPS secrets) - [ ] Container image - [ ] CI / reusable workflow - [ ] Refactor / cleanup - [ ] Breaking change ## Validation - [x] Final-head synthetic tests and OpenTofu test/plan passed at `e401c379d4b7265534aa3276ebd08d949c815b95`. Apply and real source diagnostic skipped on PR. - [x] Generated or centrally distributed files were regenerated by their owning automation, not hand-edited — no generated files changed. **Explicit owner waiver, 2026-10-05:** owner approved opening this draft using their SOPS-edit attestation with the encrypted-content review limitation recorded. Adversarial, security, and delivery reviews remain evidence-limited/HOLD rather than code-review-approved; the delivery reviewer rated missing complete-change evidence High. The waiver permits draft creation and CI evaluation only. It does not verify encryption, recipient preservation, plaintext correctness, or absence of other field changes, and does not authorize merge, apply, or dispatch. Do not retrieve protected content to satisfy review. The branch was created before current main `21a0eca21db3525266a4f6cf25f666e73b748243`. The branch was updated via GitHub to head `e401c379d4b7265534aa3276ebd08d949c815b95` before accepting final CI: the reusable plan workflow checks out PR HEAD, not the merge ref. Ignore initial stale-head plans as approval evidence. Expected scope: updates to the two existing known-host Actions secrets, zero additions/deletions and no unrelated changes. This is an expectation, not a verified plan. Record any safe-summary redaction limits; never fetch raw sensitive plans. ## Impact and rollout Canonical producer: tfroot-github `secrets/secrets.yaml` -> `secrets.tf` SOPS lookup `ssh_known_hosts` -> `gh-secrets.tf` `github_actions_secret.secrets`. Existing recipients are `hero-host-config/HERO_HOST_CONFIG_SSH_KNOWN_HOSTS` and `tfroot-libvirt/SSH_KNOWN_HOSTS`. Mapping and resource code are unchanged by this correction. Distribution is not atomic, and successful apply alone does not prove a particular resource changed or successful downstream SSH. Authored/pushed: owner correction complete. PR test/plan and synthetic tests: automatic, passed. Branch update: completed. Merge/main environment-scoped apply: separate confirmation required; merging triggers the existing main workflow. Source diagnostic and fresh Hero check-only dispatch: separate manual confirmation gates. Source matching, distribution, strict host verification, and functional behavior remain distinct. No host/firewall mutation, private-key rotation, libvirt source retirement, image/chart publication, or GitOps change is included. Existing shared-workflow and runner selections are unchanged. Rollback before delivery: close the PR. After delivery: owner restores an approved encrypted source through a reviewed PR and separately approved apply. Do not restore untrusted host keys or disable strict checking. ## Safety and secrets - [ ] Contains no plaintext secrets, decrypted SOPS values, state files, kubeconfigs, tokens, or private endpoints — encrypted source is owner-attested; contents were not independently inspected by the agent. PR prose contains none. - [x] No local OpenTofu init/plan/apply/destroy/import/state operations were run or claimed — plans come from pull-request checks. - [x] Breaking or irreversible effects are described above with rollback notes. Owner authored the encrypted change. AI assistance is limited to metadata/source-contract review, PR preparation, and CI monitoring. No merge or runtime action is authorized by this draft. ### Final-head CI evidence [Synthetic tests](https://github.com/makeitworkcloud/tfroot-github/actions/runs/37247437874) and [OpenTofu test/plan](https://github.com/makeitworkcloud/tfroot-github/actions/runs/37247438632) passed. [Redacted plan summary](#75 (comment)): **0 to add, 2 to change, 0 to destroy**. Counts match the intended scope, but the redacted summary does not expose the two expected resource identities, so exact resource scope is not independently established. No raw plan or encrypted-file contents were retrieved. Owner review of exact non-sensitive resource identities remains a merge gate. No merge, apply, or dispatch performed; draft and review waiver limitations remain in force.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add the owner-approved source-side diagnostic to distinguish an absent canonical known-host entry from a delivery problem. The new
check-known-host-sourceworkflow has credentialless synthetic tests on PRs and a separately confirmed, main-only manual source job. The diagnostic itself runs no OpenTofu/state operation, does not contact Hero, and does not write GitHub secrets.Four new files: a Python-stdlib helper, synthetic tests, workflow, and operator guide. No encrypted source, Terraform resource, recipient mapping, shared workflow, or Hero workflow changes.
Fixes: N/A — owner-approved investigation of the consumer preflight's
missing-host-entryresult.Type of change
Validation
synthetic-testsand existing OpenTofu test/plan.Synthetic tests use temporary generated keys and real Python streaming producers in place of SOPS; they never access KMS or real encrypted data. Coverage includes matching/hashed/missing entries, extraction failures, oversized/infinite streams, timeout termination, mode-restricted temporary files, cleanup, fixed-output assertions, invalid inputs, and workflow main/manual/credential guards.
Adversarial, infrastructure-security, DevOps integration, and QA reviews have no unresolved Critical/High findings. Review fixes replaced unbounded buffered extraction with bounded reads (1 MiB plus one overflow-detection byte), discarded SOPS stderr, and made temporary paths run/attempt-specific. No local tests or decryption ran; CI is the execution authority.
Impact and rollout
Owner/producer: tfroot-github maintainers own this thin orchestration around existing SOPS/OpenSSH tools and its sole manual-workflow consumer. No new package, service, image, or shared-workflow fork is introduced.
Compared path: canonical
ssh_known_hosts-> existingHERO_HOST_CONFIG_SSH_KNOWN_HOSTSresource for hero-host-config -> its runner-local known_hosts file. Both diagnostics use OpenSSHssh-keygen -Fwith the same supplied destination. A source match does not prove byte equality, ED25519 validity, host identity, or successful distribution.Diagnostic selection: PRs run only synthetic tests in this new workflow. A new dispatch from main after separate authorization uses the existing production environment, arc-tf image, and SOPS KMS role. OIDC/KMS access is not proven until that dispatch. The helper extracts the field inside CI, discards tool diagnostics, prints only a fixed result category, and removes its temporary plaintext file. No artifacts/caches retain source material.
IMPORTANT MERGE GATE: the repository's existing OpenTofu workflow remains unchanged. PR creation still triggers its normal test/plan, and merging still triggers its normal main workflow, including its environment-scoped apply. Current main includes unrelated repository-deletion work whose latest apply failed. This PR is NOT authorization to retry or apply those changes. Review the outstanding infrastructure plan and actual environment protection before authorizing merge; environment declaration alone does not establish a required-reviewer gate. No merge or manual dispatch has been performed.
Stages: authored/branch-published and independently reviewed; CI pending. Merge and manual source diagnostic are separate confirmation gates. Consumer comparison and runtime resolution remain pending. No tfroot-libvirt cleanup is included.
Rollback: close before merge or remove the four new files through a reviewed PR. The diagnostic changes no remote secret or host state. Interruption cleanup is best-effort; a host crash cannot guarantee deletion, as documented.
Safety and secrets
AI-assisted implementation and independent reviews. The source check does not expose values, keys, fingerprints, hashes, or subprocess errors. Dispatch destinations can appear as ordinary workflow input metadata; no endpoint is committed.