harden build scripts and fix correctness issues from audit

Security & correctness fixes following the audit in REPORT.md.

  - setup-hypervisor.sh: fix broken error handling — use curl -fsSL,
    check failures properly, return valid exit codes, and fetch
    /releases/latest (arch-aware) instead of the possibly-draft .[0]
  - entrypoint.sh: quote "$@" and build --net conditionally so empty
    NET_INTERFACE/NET_MAC don't yield "tap=,mac="
  - image-updater: replace tight 3s retry loop with capped exponential
    backoff + periodic pull instead of hammering the registry
  - sshd: set PermitRootLogin prohibit-password explicitly (key-only root)
  - vm.Dockerfile: copy only host private keys at mode 600 instead of
    the whole secret/* glob (drops .gitkeep/.pub from /etc/ssh)
  - Makefile: stop generating redundant _pub key files
  - build-image.sh: detect failure via alpine-make-vm-image's real exit
    status rather than grepping stdout for "ERROR"
  - remove orphaned etc/alloy/config.alloy (service not installed)
  - README: correct data.raw path
  - add REPORT.md audit notes (H1/H2 accepted as out-of-scope)
This commit is contained in:
iceBear67
2026-07-14 17:52:24 +08:00
parent 43cd7c1d22
commit c7afb86ebc
9 changed files with 114 additions and 118 deletions
+7 -1
View File
@@ -17,7 +17,13 @@ COPY .env /kitchen/.env
RUN sh /kitchen/substitution.sh < /kitchen/.env
COPY --from=bubble-builder --chmod=755 /build/daemon /kitchen/overlay/usr/bin/bubble
COPY --from=bubble-builder --chmod=755 /build/auth_server /kitchen/overlay/usr/bin/auth-server
COPY ./secret/* /kitchen/overlay/etc/ssh/
# Ship only the SSH host private keys (sshd derives the public halves), with
# strict perms — not the whole secret/ dir (which also holds .pub/.gitkeep).
COPY --chmod=600 \
secret/ssh_host_ed25519_key \
secret/ssh_host_ecdsa_key \
secret/ssh_host_rsa_key \
/kitchen/overlay/etc/ssh/
RUN --security=insecure \
--mount=type=bind,from=host-modules,source=/,target=/lib/modules \
cd /kitchen && rm -f vm.raw && ALPINE_BRANCH="3.24" ./build-image.sh