build: bake gitleaks into the runner image #247
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!247
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "build/add-gitleaks"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Adds
gitleaksto the runner image recipe, so the CI secret scan (#62) has a binary to run.This PR alone changes no CI behaviour — it only changes what the next bake installs. The
gating
gitleaksstep comes in a follow-up, after the image is re-baked, for the same reason theruff checkstep was held back: adding a step that calls a binary the current image lacks wouldfail every PR until the re-bake, which is precisely the lockout
bitborg-reconcile-triggerjustwent through.
Changes
GITLEAKS_VERSION(default8.30.1) as the single source of truth, alongsideTOFU_VERSIONandNODE_VERSION, documented in the usage header and passed into the remote sudo env./usr/local/bin, mirroring the OpenTofu install. It cannot ride thepip installline next toansible-lint/ruff, being a Go binary.gitleaks versionadded to the bake's sanity check, so a broken download fails the bake ratherthan surfacing later as a mysterious CI failure.
Note the asset name is
gitleaks_${VERSION}_linux_x64.tar.gz—x64, notamd64. The OpenTofuline directly above uses
amd64, so copying that convention 404s. Verified both:x64→ HTTP 200,amd64→ HTTP 404.History scan result (the gate for #62)
Ran ahead of this, locally, across all six repos with
--redact:bitborg-infra's history is clean, including through the period of the Glesys credential
incident — those values were evidently never committed, which is a materially better outcome than
assumed when #62 was written.
The two bitborg-internal findings are the same line in a research document: a UUID-shaped
unscheduledTokenin a fenced code block illustrating a Swedbank Pay request payload, surrounded byobvious placeholders. Swedbank Pay was never adopted (Mollie was chosen), so no such credential ever
existed. Allowlisted per-fingerprint in
.gitleaksignore— which fails safe, since a genuinely newsecret in that file yields a different fingerprint and still trips.
After you re-bake
Then one follow-up PR can add both deferred gating steps:
gitleaksandruff check.Verified:
shellcheck scripts/bake-runner-image.shpasses.Refs #61, #62