Make the Vault gitea creds path selectable
agentpr always read gitea/creds/unkin-agent from a bare const, so a service like repospawner could not run it as its own Gitea identity. - Replace the GiteaCredsPath const with a function: GITEA_CREDS_PATH when set, otherwise gitea/creds/<AGENT_LOGIN>. Unset env still resolves to gitea/creds/unkin-agent, so existing callers are unchanged. - Thread the creds path through fetchGiteaToken/readGiteaCreds instead of reading a package-level const, and report it in the error messages. - Make agentpr's help text login-agnostic and document both variables.
This commit is contained in:
@@ -49,9 +49,10 @@ func approleLogin(vaultAddr, roleID string) (string, error) {
|
||||
return out.Auth.ClientToken, nil
|
||||
}
|
||||
|
||||
// readGiteaCreds reads the Gitea creds secret and returns the token field.
|
||||
func readGiteaCreds(vaultAddr, clientToken string) (string, error) {
|
||||
url := strings.TrimRight(vaultAddr, "/") + "/v1/" + GiteaCredsPath
|
||||
// readGiteaCreds reads the Gitea creds secret at credsPath and returns the
|
||||
// token field.
|
||||
func readGiteaCreds(vaultAddr, clientToken, credsPath string) (string, error) {
|
||||
url := strings.TrimRight(vaultAddr, "/") + "/v1/" + credsPath
|
||||
req, err := http.NewRequest(http.MethodGet, url, nil)
|
||||
if err != nil {
|
||||
return "", err
|
||||
@@ -60,12 +61,12 @@ func readGiteaCreds(vaultAddr, clientToken string) (string, error) {
|
||||
|
||||
resp, err := httpClient.Do(req)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("vault read %s: %w", GiteaCredsPath, err)
|
||||
return "", fmt.Errorf("vault read %s: %w", credsPath, err)
|
||||
}
|
||||
defer func() { _ = resp.Body.Close() }()
|
||||
data, _ := io.ReadAll(resp.Body)
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
return "", fmt.Errorf("vault read %s: HTTP %d: %s", GiteaCredsPath, resp.StatusCode, strings.TrimSpace(string(data)))
|
||||
return "", fmt.Errorf("vault read %s: HTTP %d: %s", credsPath, resp.StatusCode, strings.TrimSpace(string(data)))
|
||||
}
|
||||
|
||||
var out struct {
|
||||
@@ -74,10 +75,10 @@ func readGiteaCreds(vaultAddr, clientToken string) (string, error) {
|
||||
} `json:"data"`
|
||||
}
|
||||
if err := json.Unmarshal(data, &out); err != nil {
|
||||
return "", fmt.Errorf("vault read %s: decoding response: %w", GiteaCredsPath, err)
|
||||
return "", fmt.Errorf("vault read %s: decoding response: %w", credsPath, err)
|
||||
}
|
||||
if out.Data.Token == "" {
|
||||
return "", fmt.Errorf("vault read %s: no token field in secret", GiteaCredsPath)
|
||||
return "", fmt.Errorf("vault read %s: no token field in secret", credsPath)
|
||||
}
|
||||
return out.Data.Token, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user