Harden admin deployment and local acceptance

Enforce mTLS and least-privilege runtime boundaries while adding repeatable MySQL 8.4 and Docker smoke checks that require no production secrets.
This commit is contained in:
Rocky
2026-08-17 15:20:46 +08:00
parent 1a9c518f96
commit 405a2cfc0f
17 changed files with 1480 additions and 37 deletions
+70
View File
@@ -0,0 +1,70 @@
#!/usr/bin/env bash
set -euo pipefail
BASE_URL="${BASE_URL:-https://account.osglab.com}"
ADMIN_CLIENT_CERT="${ADMIN_CLIENT_CERT:-}"
ADMIN_CLIENT_KEY="${ADMIN_CLIENT_KEY:-}"
if [[ -z "$ADMIN_CLIENT_CERT" || -z "$ADMIN_CLIENT_KEY" ]]; then
echo "Set ADMIN_CLIENT_CERT and ADMIN_CLIENT_KEY to local PEM paths." >&2
exit 2
fi
work_directory="$(mktemp -d)"
trap 'rm -rf "$work_directory"' EXIT
request_status() {
local name="$1"
local expected="$2"
shift 2
local status
status="$(curl --silent --show-error \
--output "$work_directory/$name.body" \
--dump-header "$work_directory/$name.headers" \
--write-out '%{http_code}' \
"$@")"
if [[ "$status" != "$expected" ]]; then
echo "$name expected HTTP $expected but received $status" >&2
exit 1
fi
}
request_status "health" "200" "$BASE_URL/health"
request_status "admin-without-certificate" "404" "$BASE_URL/admin/"
request_status "forged-edge-header" "404" \
--header "X-OSG-mTLS-Verified: SUCCESS" \
"$BASE_URL/v1/admin/auth/session"
request_status "admin-with-certificate" "200" \
--cert "$ADMIN_CLIENT_CERT" \
--key "$ADMIN_CLIENT_KEY" \
"$BASE_URL/admin/"
request_status "session-with-certificate" "200" \
--cert "$ADMIN_CLIENT_CERT" \
--key "$ADMIN_CLIENT_KEY" \
"$BASE_URL/v1/admin/auth/session"
if ! grep -Fq "OSG 运营后台" "$work_directory/admin-with-certificate.body"; then
echo "Admin HTML marker was not found." >&2
exit 1
fi
if ! grep -Eiq '^strict-transport-security: .*max-age=31536000' \
"$work_directory/admin-with-certificate.headers"; then
echo "Strict-Transport-Security header is missing." >&2
exit 1
fi
if ! grep -Eiq "^content-security-policy: .*script-src 'self'; style-src 'self'" \
"$work_directory/admin-with-certificate.headers"; then
echo "The expected strict Content-Security-Policy header is missing." >&2
exit 1
fi
if grep -Fiq "unsafe-inline" "$work_directory/admin-with-certificate.headers"; then
echo "Content-Security-Policy unexpectedly permits unsafe-inline." >&2
exit 1
fi
echo "Admin edge acceptance checks passed."