feat(ci): Tier-0 smoke — hardened containers can start (#104) #110
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!110
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/104-tier0-container-smoke"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
First increment of the pre-prod validation epic (bitborg-docs#37), targeting the exact failure class that took prod down this week (#81/#94) and that
ansible-playbook --checkcannot catch — it never starts a container.What it does
scripts/smoke-containers.py: for everyroles/*/templates/*.container.j2withNoNewPrivileges=true+DropCapability=ALLand a public image, it resolves the image + declared capabilities and does a realpodman runwith the same--cap-drop/--cap-add/--security-opt=no-new-privileges, then asserts the entrypoint could exec./usr/bin/caddyneedingNET_BIND_SERVICE) is detected viaState.Error/ a 126–127 exit code.Wired into
.forgejo/workflows/ci.yml; runs on the host-backend runner (ADR 0021ci:host→ the job has the VM's own podman). PyYAML comes from the existingpip install ansiblestep.Validated locally (podman 5.8.3), both directions
NET_BIND_SERVICE— makes the smoke FAIL with a non-zero exit and the #94 explanation. A test that can't fail is worthless; this one does.Scope / remaining #104 work (tracked on the issue)
token-audit.prom0600 bug node_exporter rejected).Had this existed, both prod incidents this week (#94 outage, #96 silent metric gap) would have been caught in CI.