harden build scripts and fix correctness issues from audit
Security & correctness fixes following the audit in REPORT.md.
- setup-hypervisor.sh: fix broken error handling — use curl -fsSL,
check failures properly, return valid exit codes, and fetch
/releases/latest (arch-aware) instead of the possibly-draft .[0]
- entrypoint.sh: quote "$@" and build --net conditionally so empty
NET_INTERFACE/NET_MAC don't yield "tap=,mac="
- image-updater: replace tight 3s retry loop with capped exponential
backoff + periodic pull instead of hammering the registry
- sshd: set PermitRootLogin prohibit-password explicitly (key-only root)
- vm.Dockerfile: copy only host private keys at mode 600 instead of
the whole secret/* glob (drops .gitkeep/.pub from /etc/ssh)
- Makefile: stop generating redundant _pub key files
- build-image.sh: detect failure via alpine-make-vm-image's real exit
status rather than grepping stdout for "ERROR"
- remove orphaned etc/alloy/config.alloy (service not installed)
- README: correct data.raw path
- add REPORT.md audit notes (H1/H2 accepted as out-of-scope)
This commit is contained in:
@@ -1,88 +0,0 @@
|
||||
discovery.docker "local" {
|
||||
host = "unix:///var/run/docker.sock"
|
||||
refresh_interval = "5s"
|
||||
}
|
||||
|
||||
discovery.relabel "docker" {
|
||||
targets = discovery.docker.local.targets
|
||||
|
||||
//
|
||||
// Container Name
|
||||
//
|
||||
rule {
|
||||
source_labels = ["__meta_docker_container_name"]
|
||||
regex = "/(.*)"
|
||||
replacement = "$1"
|
||||
target_label = "container"
|
||||
}
|
||||
|
||||
//
|
||||
// Docker Compose
|
||||
//
|
||||
rule {
|
||||
source_labels = ["__meta_docker_container_label_com_docker_compose_service"]
|
||||
target_label = "service"
|
||||
}
|
||||
|
||||
rule {
|
||||
source_labels = ["__meta_docker_container_label_com_docker_compose_project"]
|
||||
target_label = "compose_project"
|
||||
}
|
||||
|
||||
//
|
||||
// Image
|
||||
//
|
||||
rule {
|
||||
source_labels = ["__meta_docker_container_image"]
|
||||
target_label = "image"
|
||||
}
|
||||
|
||||
//
|
||||
// stdout / stderr
|
||||
//
|
||||
rule {
|
||||
source_labels = ["__meta_docker_container_log_stream"]
|
||||
target_label = "stream"
|
||||
}
|
||||
|
||||
//
|
||||
// Query 用
|
||||
//
|
||||
rule {
|
||||
source_labels = ["__meta_docker_container_label_com_docker_compose_service"]
|
||||
target_label = "job"
|
||||
}
|
||||
}
|
||||
|
||||
loki.process "docker" {
|
||||
|
||||
stage.static_labels {
|
||||
values = {
|
||||
node = env("NODE_NAME"),
|
||||
environment = env("ENVIRONMENT"),
|
||||
platform = "docker",
|
||||
}
|
||||
}
|
||||
|
||||
forward_to = [loki.write.default.receiver]
|
||||
}
|
||||
|
||||
loki.source.docker "local" {
|
||||
host = "unix:///var/run/docker.sock"
|
||||
|
||||
targets = discovery.relabel.docker.output
|
||||
|
||||
refresh_interval = "5s"
|
||||
|
||||
forward_to = [
|
||||
loki.process.docker.receiver,
|
||||
]
|
||||
}
|
||||
|
||||
loki.write "default" {
|
||||
|
||||
endpoint {
|
||||
url = env("LOKI_URL")
|
||||
tenant_id = env("LOKI_TENANT")
|
||||
}
|
||||
}
|
||||
@@ -1,4 +1,8 @@
|
||||
KbdInteractiveAuthentication no
|
||||
PasswordAuthentication no
|
||||
PubkeyAuthentication yes
|
||||
# Root is the only account with an authorized_keys; allow key-based root login
|
||||
# only (never password), and make the policy explicit rather than relying on
|
||||
# the compile-time default.
|
||||
PermitRootLogin prohibit-password
|
||||
|
||||
|
||||
Reference in New Issue
Block a user