build: bake gitleaks into the runner image #247

Sammanfogat
supernaut sammanfogade 1 incheckning från build/add-gitleaks in i main 2026-07-29 21:08:22 +00:00
Ägare

Adds gitleaks to the runner image recipe, so the CI secret scan (#62) has a binary to run.

This PR alone changes no CI behaviour — it only changes what the next bake installs. The
gating gitleaks step comes in a follow-up, after the image is re-baked, for the same reason the
ruff check step was held back: adding a step that calls a binary the current image lacks would
fail every PR until the re-bake, which is precisely the lockout bitborg-reconcile-trigger just
went through.

Changes

  • GITLEAKS_VERSION (default 8.30.1) as the single source of truth, alongside TOFU_VERSION and
    NODE_VERSION, documented in the usage header and passed into the remote sudo env.
  • Pinned release tarball → /usr/local/bin, mirroring the OpenTofu install. It cannot ride the
    pip install line next to ansible-lint/ruff, being a Go binary.
  • gitleaks version added to the bake's sanity check, so a broken download fails the bake rather
    than surfacing later as a mysterious CI failure.

Note the asset name is gitleaks_${VERSION}_linux_x64.tar.gz — x64, not amd64. The OpenTofu
line directly above uses amd64, so copying that convention 404s. Verified both:
x64 → HTTP 200, amd64 → HTTP 404.

History scan result (the gate for #62)

Ran ahead of this, locally, across all six repos with --redact:

Repo Findings
bitborg-payment, bitborg-auth-reconciler, bitborg-reconcile-trigger, bitborg-web, bitborg-infra 0
bitborg-internal 2 → reviewed, allowlisted

bitborg-infra's history is clean, including through the period of the Glesys credential
incident — those values were evidently never committed, which is a materially better outcome than
assumed when #62 was written.

The two bitborg-internal findings are the same line in a research document: a UUID-shaped
unscheduledToken in a fenced code block illustrating a Swedbank Pay request payload, surrounded by
obvious placeholders. Swedbank Pay was never adopted (Mollie was chosen), so no such credential ever
existed. Allowlisted per-fingerprint in .gitleaksignore — which fails safe, since a genuinely new
secret in that file yields a different fingerprint and still trips.

After you re-bake

SSH_KEY=~/.ssh/gitborg-prod NETWORK=gitborg-prod-net SSH_SG=<sg> \
  scripts/bake-runner-image.sh --replace

Then one follow-up PR can add both deferred gating steps: gitleaks and ruff check.

Verified: shellcheck scripts/bake-runner-image.sh passes.

Refs #61, #62

Adds `gitleaks` to the runner image recipe, so the CI secret scan (#62) has a binary to run. **This PR alone changes no CI behaviour** — it only changes what the *next* bake installs. The gating `gitleaks` step comes in a follow-up, after the image is re-baked, for the same reason the `ruff check` step was held back: adding a step that calls a binary the current image lacks would fail every PR until the re-bake, which is precisely the lockout `bitborg-reconcile-trigger` just went through. ## Changes - `GITLEAKS_VERSION` (default `8.30.1`) as the single source of truth, alongside `TOFU_VERSION` and `NODE_VERSION`, documented in the usage header and passed into the remote sudo env. - Pinned release tarball → `/usr/local/bin`, mirroring the OpenTofu install. It cannot ride the `pip install` line next to `ansible-lint`/`ruff`, being a Go binary. - `gitleaks version` added to the bake's sanity check, so a broken download fails the bake rather than surfacing later as a mysterious CI failure. Note the asset name is `gitleaks_${VERSION}_linux_x64.tar.gz` — **`x64`, not `amd64`**. The OpenTofu line directly above uses `amd64`, so copying that convention 404s. Verified both: `x64` → HTTP 200, `amd64` → HTTP 404. ## History scan result (the gate for #62) Ran ahead of this, locally, across all six repos with `--redact`: | Repo | Findings | | --- | --- | | bitborg-payment, bitborg-auth-reconciler, bitborg-reconcile-trigger, bitborg-web, **bitborg-infra** | **0** | | bitborg-internal | 2 → reviewed, allowlisted | **bitborg-infra's history is clean**, including through the period of the Glesys credential incident — those values were evidently never committed, which is a materially better outcome than assumed when #62 was written. The two bitborg-internal findings are the same line in a research document: a UUID-shaped `unscheduledToken` in a fenced code block illustrating a Swedbank Pay request payload, surrounded by obvious placeholders. Swedbank Pay was never adopted (Mollie was chosen), so no such credential ever existed. Allowlisted per-fingerprint in `.gitleaksignore` — which fails safe, since a genuinely new secret in that file yields a different fingerprint and still trips. ## After you re-bake ``` SSH_KEY=~/.ssh/gitborg-prod NETWORK=gitborg-prod-net SSH_SG=<sg> \ scripts/bake-runner-image.sh --replace ``` Then one follow-up PR can add both deferred gating steps: `gitleaks` and `ruff check`. Verified: `shellcheck scripts/bake-runner-image.sh` passes. Refs #61, #62
supernaut lade till 1 incheckning 2026-07-29 20:58:13 +00:00
build: bake gitleaks into the runner image
Alla kontroller lyckades
ci / ci (pull_request) Successful in 56s
2e042cbb4b
supernaut sammanfogade incheckning d755794bde till main 2026-07-29 21:08:22 +00:00
supernaut tog bort grenen build/add-gitleaks 2026-07-29 21:08:22 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-07-29 21:08:22 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-08-03 09:41:34 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!247
Ingen beskrivning angiven.