arrproxy: bump images to v0.5.0 (per-token method scoping)
arrproxy v0.5.0 adds per-token HTTP method scoping for machine tokens, so a minted token can be limited to e.g. GET only. Existing tokens keep an empty methods list and stay unrestricted. - Bump arrproxy-api and arrproxy-ui pins to v0.5.0 - Mirror migrations 0002_tier_tokens.sql and 0003_token_methods.sql into the migrations ConfigMap, which had drifted at 0001 while v0.4.0 already queried tier/read_only and v0.5.0 queries methods - Have the wave-1 migrate Job apply all three files in order (every statement is idempotent, so a resync over a migrated database is a no-op)
This commit is contained in:
@@ -34,7 +34,7 @@ spec:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: api
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.4.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.5.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
|
||||
@@ -64,6 +64,10 @@ spec:
|
||||
- ON_ERROR_STOP=1
|
||||
- -f
|
||||
- /migrations/0001_init.sql
|
||||
- -f
|
||||
- /migrations/0002_tier_tokens.sql
|
||||
- -f
|
||||
- /migrations/0003_token_methods.sql
|
||||
volumeMounts:
|
||||
- name: migrations
|
||||
mountPath: /migrations
|
||||
|
||||
@@ -1,7 +1,9 @@
|
||||
---
|
||||
# arrproxy schema, mirrored from the arrproxy repo migrations/0001_init.sql
|
||||
# (v0.1.0). arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies
|
||||
# this once per sync as the app user. Keep in sync with the repo on schema bumps.
|
||||
# arrproxy schema, mirrored from the arrproxy repo migrations/ (v0.5.0).
|
||||
# arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies these in
|
||||
# order once per sync as the app user. Every statement is idempotent, so a resync
|
||||
# over an already-migrated database is a no-op. Keep in sync with the repo on
|
||||
# schema bumps.
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
@@ -27,3 +29,14 @@ data:
|
||||
|
||||
CREATE INDEX IF NOT EXISTS tokens_subject_idx ON tokens (subject);
|
||||
CREATE INDEX IF NOT EXISTS tokens_token_hash_idx ON tokens (token_hash);
|
||||
0002_tier_tokens.sql: |
|
||||
-- Tier-scoped virtual API keys. Existing rows (tier '') remain legacy per-app
|
||||
-- tokens validated on the unprefixed routes; tier keys carry a tier name and,
|
||||
-- for read-only tiers (kids), read_only=true so writes are rejected.
|
||||
ALTER TABLE tokens ADD COLUMN IF NOT EXISTS tier TEXT NOT NULL DEFAULT '';
|
||||
ALTER TABLE tokens ADD COLUMN IF NOT EXISTS read_only BOOLEAN NOT NULL DEFAULT false;
|
||||
0003_token_methods.sql: |
|
||||
-- Per-token HTTP method scoping. An empty list (the default every existing row
|
||||
-- gets) means unrestricted, so tokens minted before this column behave exactly
|
||||
-- as before; a non-empty list limits the token to those methods.
|
||||
ALTER TABLE tokens ADD COLUMN IF NOT EXISTS methods TEXT[] NOT NULL DEFAULT '{}';
|
||||
|
||||
@@ -31,7 +31,7 @@ spec:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: ui
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.4.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.5.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
|
||||
Reference in New Issue
Block a user