fix(harnesses): migrate to ESO secrets_required form, mirror agent-runtimes

The CRS-served harnesses still carried `secrets_files: [{encrypted: true}]`
which now hard-fails on H-SECRET-1 ("SOPS-encrypted secrets_files entries
are no longer permitted") in the dispatcher's harness validator. Sync the
8 provider harnesses with the agent-runtimes copies: same `secrets_required`
shape, same `init.sh` (ESO-mounted file paths), same `bin/` wrappers.

Use bare `account_ref: "<provider>"` (not `<provider>.cp:cp` — that
scope-kind isn't valid per SR-DISP-1-FIELD).

Provider key names follow the per-provider schema as emitted by the CP
provisioner: minimax/airouter/z-ai → api_key; gitea-https/gitea-admin →
{token,base_url,username}; gitea-ssh* → {host,private_key}.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Paul O'Reilly
2026-05-07 07:26:19 +12:00
parent 8bbf6cbb2f
commit 5f85d895c1
20 changed files with 288 additions and 117 deletions

View File

@@ -18,7 +18,8 @@ ssh_hosts:
scripts:
init: "./init.sh"
secrets_files:
- source: ./ssh-key.sops.env
target: /opt/harness/secrets/gitea-ssh/ssh-key.sops.env
encrypted: true
secrets_required:
- name: gitea-ssh
account_ref: "gitea-ssh"
mount_path: /run/agent/secrets/gitea-ssh
mode: "0400"

View File

@@ -1,32 +1,27 @@
#!/bin/bash
# gitea-ssh init: copy the ESO-mounted SSH key to the path the harness-init
# `~/.ssh/config` expects.
#
# The harness-init dispatcher writes `~/.ssh/config` with
# IdentityFile /home/agent/.ssh/gitea-oreillyit-nz-ai-enablement
# so the key must end up at that path with mode 0600 owned by agent.
#
# The ESO mount at /run/agent/secrets/gitea-ssh/private_key is read-only
# (V1VolumeMount(read_only=True)), so chmod against it would fail with EROFS.
# install(1) handles permissions/ownership atomically against the destination.
#
# Per M22 Phase 9 file-only delivery (H-SECRET-4): no credential value enters
# an env var.
set -euo pipefail
# Extract SSH private key from decrypted env file and write to the per-host
# identity file path. The meta-init script generates ~/.ssh/config with
# IdentityFile /home/agent/.ssh/gitea-oreillyit-nz-ai-enablement
# matching the ssh_hosts alias in harness.yaml.
SSH_KEY_SRC="/run/agent/secrets/gitea-ssh/private_key"
SSH_KEY_DST="/home/agent/.ssh/gitea-oreillyit-nz-ai-enablement"
SSH_KEY_FILE="/home/agent/.ssh/gitea-oreillyit-nz-ai-enablement"
# Find the decrypted env file (dispatcher decrypts SOPS at dispatch time for K8s,
# or the meta-init script decrypts for Docker)
for env_file in /opt/harness/secrets/gitea-ssh/*.decrypted.env /opt/harness/secrets/gitea-ssh/*.env; do
[ -f "$env_file" ] || continue
while IFS='=' read -r key value; do
# Skip comments and blank lines
[[ "$key" =~ ^[[:space:]]*# ]] && continue
[[ -z "$key" ]] && continue
if [ "$key" = "GITEA_SSH_KEY" ]; then
mkdir -p /home/agent/.ssh
echo "$value" | base64 -d > "$SSH_KEY_FILE"
chmod 600 "$SSH_KEY_FILE"
chown agent:agent "$SSH_KEY_FILE"
echo "SSH key written to $SSH_KEY_FILE"
break 2
fi
done < "$env_file"
done
if [ ! -f "$SSH_KEY_FILE" ]; then
echo "WARNING: GITEA_SSH_KEY not found in any env file under /opt/harness/secrets/gitea-ssh/"
if [ ! -r "$SSH_KEY_SRC" ]; then
echo "ERROR: SSH key not found at $SSH_KEY_SRC — ESO ExternalSecret not Ready?" >&2
exit 1
fi
mkdir -p /home/agent/.ssh
install -m 0600 -o agent -g agent "$SSH_KEY_SRC" "$SSH_KEY_DST"
echo "gitea-ssh: SSH key staged at $SSH_KEY_DST (0600 agent:agent)"