CB-633: constrain a member's environment with a real allow-list (memberCredentials.policy) #147
Reference in New Issue
Block a user
Delete Branch "worker/cb-633-env-allowlist-31c312-8"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What changed
A herdr pane runs a login shell that re-sources the operator's secret store, so every credential in it reaches members. CB-596's control was an env overlay applied BEFORE that shell runs — any sourced file could (and did) re-export over it. This moves the control into a file the daemon owns.
Tests
mvn clean install: BUILD SUCCESS — 896 tests, 0 failures, 0 errors, 0 skipped (totals summed from target/surefire-reports/*.xml).
The key test starts a real login zsh from a clean parent twice (baseline and scrubbed) and asserts surviving non-empty exports EQUAL baseline ∩ derived allow-list — equality, not blocked-name spot checks. Skips cleanly via assumeTrue when /bin/zsh or $HOME/.zshrc is absent. It caught two real things during development: zsh evaluates special-assoc subscripts arithmetically ('bad math expression', fixed by enumerating exports via env itself), and blanked variables stay exported-empty (survival must mean non-empty value).
Closes gitea fleet/fleetd#144.