Security & correctness fixes following the audit in REPORT.md.
- setup-hypervisor.sh: fix broken error handling — use curl -fsSL,
check failures properly, return valid exit codes, and fetch
/releases/latest (arch-aware) instead of the possibly-draft .[0]
- entrypoint.sh: quote "$@" and build --net conditionally so empty
NET_INTERFACE/NET_MAC don't yield "tap=,mac="
- image-updater: replace tight 3s retry loop with capped exponential
backoff + periodic pull instead of hammering the registry
- sshd: set PermitRootLogin prohibit-password explicitly (key-only root)
- vm.Dockerfile: copy only host private keys at mode 600 instead of
the whole secret/* glob (drops .gitkeep/.pub from /etc/ssh)
- Makefile: stop generating redundant _pub key files
- build-image.sh: detect failure via alpine-make-vm-image's real exit
status rather than grepping stdout for "ERROR"
- remove orphaned etc/alloy/config.alloy (service not installed)
- README: correct data.raw path
- add REPORT.md audit notes (H1/H2 accepted as out-of-scope)
23 lines
840 B
Bash
Executable File
23 lines
840 B
Bash
Executable File
#!/bin/sh
|
|
# Keep the workspace image fresh. Runs long-lived under supervise-daemon:
|
|
# pulls periodically, with capped exponential backoff on failure instead of a
|
|
# tight retry loop that hammers the registry.
|
|
set -u
|
|
|
|
IMAGE="git.sfclub.cc/cloud/workspace-image:latest"
|
|
INTERVAL="${IMAGE_UPDATER_INTERVAL:-3600}" # seconds between successful pulls
|
|
MIN_DELAY="${IMAGE_UPDATER_MIN_DELAY:-5}" # initial retry delay on failure
|
|
MAX_DELAY="${IMAGE_UPDATER_MAX_DELAY:-300}" # cap on retry delay
|
|
|
|
while true; do
|
|
delay="$MIN_DELAY"
|
|
until docker pull "$IMAGE" >/dev/null 2>&1; do
|
|
echo "image-updater: pull failed, retrying in ${delay}s" >&2
|
|
sleep "$delay"
|
|
delay=$((delay * 2))
|
|
[ "$delay" -gt "$MAX_DELAY" ] && delay="$MAX_DELAY"
|
|
done
|
|
echo "image-updater: pulled $IMAGE"
|
|
sleep "$INTERVAL"
|
|
done
|