P6: S3 blob store, Helm chart, air-gapped installer verify loop
- S3BlobStore (object_store, path-style) behind the same BlobStore trait, tested against a REAL MinIO container (round trip, overwrite, NotFound on get and delete, nested keys); [storage] backend=local|s3 config with validation + server-side selection (S3 creds via env overlay) - Helm chart: server pod with the secret broker as a SIDECAR sharing a private emptyDir unix socket (no network hop carries credentials), frontend, optional local PVC vs S3, OIDC/oauth values, unbuffered-SSE ingress annotations, NetworkPolicies (frontend->server only), hardened securityContexts; ci/check-helm.sh lints AND asserts the rendered topology properties - deploy/airgapped/install.sh: offline signature+checksum verification via the bundled teamclaw-bundler BEFORE any docker load; --verify-only mode; ci/test-install.sh rehearses clean/tampered/wrong-key paths with the real binary - CI: helm gate + installer rehearsal wired in 149 Rust tests; helm lint + rendered assertions green; installer verify-path rehearsal green. Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
co-authored by
Claude Fable 5
parent
ccf96053e6
commit
70ec39f696
@@ -8,10 +8,12 @@ publish.workspace = true
|
||||
|
||||
[dependencies]
|
||||
async-trait = "0.1"
|
||||
object_store = { version = "0.12", features = ["aws"] }
|
||||
thiserror = { workspace = true }
|
||||
tokio = { workspace = true }
|
||||
|
||||
[dev-dependencies]
|
||||
testcontainers-modules = { workspace = true }
|
||||
uuid = { workspace = true }
|
||||
|
||||
[lints]
|
||||
|
||||
@@ -2,6 +2,10 @@
|
||||
//! filesystem implementation serves dev and the air-gapped target; an
|
||||
//! S3-compatible implementation slots in behind the same trait for cloud.
|
||||
|
||||
mod s3;
|
||||
|
||||
pub use s3::S3BlobStore;
|
||||
|
||||
use std::path::{Component, Path, PathBuf};
|
||||
|
||||
#[derive(Debug, thiserror::Error)]
|
||||
|
||||
@@ -0,0 +1,84 @@
|
||||
//! S3-compatible blob store (cloud target). The same `BlobStore` contract
|
||||
//! as the local filesystem implementation; MinIO serves it in tests and
|
||||
//! self-hosted installs, AWS S3 in managed clouds.
|
||||
|
||||
use object_store::aws::AmazonS3;
|
||||
use object_store::path::Path as ObjectPath;
|
||||
use object_store::{ObjectStore, PutPayload};
|
||||
|
||||
use crate::{BlobError, BlobStore};
|
||||
|
||||
pub struct S3BlobStore {
|
||||
store: AmazonS3,
|
||||
}
|
||||
|
||||
impl S3BlobStore {
|
||||
/// `endpoint` is the S3 API base (http allowed for in-cluster MinIO);
|
||||
/// credentials come from deployment secrets.
|
||||
pub fn connect(
|
||||
endpoint: &str,
|
||||
bucket: &str,
|
||||
access_key: &str,
|
||||
secret_key: &str,
|
||||
) -> Result<S3BlobStore, BlobError> {
|
||||
let store = object_store::aws::AmazonS3Builder::new()
|
||||
.with_endpoint(endpoint)
|
||||
.with_allow_http(true)
|
||||
.with_bucket_name(bucket)
|
||||
.with_access_key_id(access_key)
|
||||
.with_secret_access_key(secret_key)
|
||||
.with_region("us-east-1")
|
||||
// MinIO and most self-hosted S3s require path-style addressing.
|
||||
.with_virtual_hosted_style_request(false)
|
||||
.build()
|
||||
.map_err(|e| BlobError::Io(e.to_string()))?;
|
||||
Ok(S3BlobStore { store })
|
||||
}
|
||||
|
||||
fn key(key: &str) -> Result<ObjectPath, BlobError> {
|
||||
if key.is_empty() || key.split('/').any(|part| part.is_empty() || part == "..") {
|
||||
return Err(BlobError::InvalidKey(key.to_owned()));
|
||||
}
|
||||
ObjectPath::parse(key).map_err(|e| BlobError::InvalidKey(e.to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
#[async_trait::async_trait]
|
||||
impl BlobStore for S3BlobStore {
|
||||
async fn put(&self, key: &str, bytes: &[u8]) -> Result<(), BlobError> {
|
||||
let path = Self::key(key)?;
|
||||
self.store
|
||||
.put(&path, PutPayload::from_bytes(bytes.to_vec().into()))
|
||||
.await
|
||||
.map_err(|e| BlobError::Io(e.to_string()))?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
async fn get(&self, key: &str) -> Result<Vec<u8>, BlobError> {
|
||||
let path = Self::key(key)?;
|
||||
match self.store.get(&path).await {
|
||||
Ok(result) => Ok(result
|
||||
.bytes()
|
||||
.await
|
||||
.map_err(|e| BlobError::Io(e.to_string()))?
|
||||
.to_vec()),
|
||||
Err(object_store::Error::NotFound { .. }) => Err(BlobError::NotFound),
|
||||
Err(e) => Err(BlobError::Io(e.to_string())),
|
||||
}
|
||||
}
|
||||
|
||||
async fn delete(&self, key: &str) -> Result<(), BlobError> {
|
||||
let path = Self::key(key)?;
|
||||
// object_store's S3 delete is idempotent; the drive UX wants an
|
||||
// honest NotFound, so probe first (head).
|
||||
match self.store.head(&path).await {
|
||||
Ok(_) => {}
|
||||
Err(object_store::Error::NotFound { .. }) => return Err(BlobError::NotFound),
|
||||
Err(e) => return Err(BlobError::Io(e.to_string())),
|
||||
}
|
||||
self.store
|
||||
.delete(&path)
|
||||
.await
|
||||
.map_err(|e| BlobError::Io(e.to_string()))
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,91 @@
|
||||
//! The cloud-target blob store against a REAL S3-compatible server
|
||||
//! (MinIO in a container) — same contract the local store satisfies.
|
||||
|
||||
use testcontainers_modules::testcontainers::core::{ExecCommand, IntoContainerPort, WaitFor};
|
||||
use testcontainers_modules::testcontainers::runners::AsyncRunner;
|
||||
use testcontainers_modules::testcontainers::{GenericImage, ImageExt};
|
||||
|
||||
use tc_files::{BlobError, BlobStore, S3BlobStore};
|
||||
|
||||
async fn minio_store() -> (
|
||||
S3BlobStore,
|
||||
testcontainers_modules::testcontainers::ContainerAsync<GenericImage>,
|
||||
) {
|
||||
let container = GenericImage::new("minio/minio", "latest")
|
||||
.with_exposed_port(9000.tcp())
|
||||
.with_wait_for(WaitFor::message_on_either_std("API:"))
|
||||
.with_env_var("MINIO_ROOT_USER", "tc-access")
|
||||
.with_env_var("MINIO_ROOT_PASSWORD", "tc-secret-key")
|
||||
.with_cmd(["server", "/data"])
|
||||
.start()
|
||||
.await
|
||||
.expect("minio starts");
|
||||
// Create the bucket with the bundled mc client.
|
||||
container
|
||||
.exec(ExecCommand::new([
|
||||
"sh",
|
||||
"-c",
|
||||
"mc alias set local http://127.0.0.1:9000 tc-access tc-secret-key && mc mb local/teamclaw",
|
||||
]))
|
||||
.await
|
||||
.expect("bucket created");
|
||||
let port = container.get_host_port_ipv4(9000).await.unwrap();
|
||||
// The bucket is created asynchronously after boot; retry connect+probe.
|
||||
let store = S3BlobStore::connect(
|
||||
&format!("http://127.0.0.1:{port}"),
|
||||
"teamclaw",
|
||||
"tc-access",
|
||||
"tc-secret-key",
|
||||
)
|
||||
.expect("client builds");
|
||||
for _ in 0..50 {
|
||||
if store.put("probe", b"x").await.is_ok() {
|
||||
store.delete("probe").await.ok();
|
||||
return (store, container);
|
||||
}
|
||||
tokio::time::sleep(std::time::Duration::from_millis(200)).await;
|
||||
}
|
||||
panic!("minio bucket never became writable");
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn s3_round_trip_overwrite_and_missing_keys() {
|
||||
let (store, _container) = minio_store().await;
|
||||
|
||||
store
|
||||
.put("ws1/documents/agent1/report.md", b"# Q2 Report")
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
store.get("ws1/documents/agent1/report.md").await.unwrap(),
|
||||
b"# Q2 Report"
|
||||
);
|
||||
|
||||
// Overwrite replaces.
|
||||
store
|
||||
.put("ws1/documents/agent1/report.md", b"# Q3 Report")
|
||||
.await
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
store.get("ws1/documents/agent1/report.md").await.unwrap(),
|
||||
b"# Q3 Report"
|
||||
);
|
||||
|
||||
// Delete then NotFound on both get and delete.
|
||||
store
|
||||
.delete("ws1/documents/agent1/report.md")
|
||||
.await
|
||||
.unwrap();
|
||||
assert!(matches!(
|
||||
store.get("ws1/documents/agent1/report.md").await,
|
||||
Err(BlobError::NotFound)
|
||||
));
|
||||
assert!(matches!(
|
||||
store.delete("ws1/documents/agent1/report.md").await,
|
||||
Err(BlobError::NotFound)
|
||||
));
|
||||
|
||||
// Nested keys work without directory semantics.
|
||||
store.put("a/b/c/deep.txt", b"deep").await.unwrap();
|
||||
assert_eq!(store.get("a/b/c/deep.txt").await.unwrap(), b"deep");
|
||||
}
|
||||
Reference in New Issue
Block a user