mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
Add Case -> Clone Repo could only reach public repositories in the Docker deployment. This lets a deployment opt in to the GitHub CLI and the Azure CLI (+ azure-devops extension) as git credential helpers. Codeman itself still collects no credentials. - server.Dockerfile / agent.Dockerfile: CODEMAN_INSTALL_GH / CODEMAN_INSTALL_AZ build args (0 or 1, default 0; anything else stops the build). Off leaves no apt repository, package, extension, helper script or credential entry, so a default build is unchanged. On installs from the vendors' apt repositories and configures system gitconfig helpers: github.com / gist.github.com -> `gh auth git-credential`, dev.azure.com / *.visualstudio.com -> new docker/git-credential-azure-cli (an Entra ID token from `az account get-access-token`, or AZURE_DEVOPS_EXT_PAT). A helper whose CLI is not signed in prints nothing, so a private clone still fails fast. - The extension lives in AZURE_EXTENSION_DIR outside HOME (/opt/codeman-az-extensions, runtime-owned; /opt/az-extensions, gid-0 group-writable in the agent image). - Hosts turn them on in docker-compose.override.yml: `build: args:` for the server image, `environment:` CODEMAN_AGENT_IMAGE_INSTALL_GH / _AZ for the agent image. build-agent-image.mjs and the in-app auto-build share one env -> ARG table (pinned by the parity test) and pass nothing when unset. docker-compose.yaml is untouched; .env.example only gains a comment, so the self-updater's environment gate sees no new keys. - Docker cases seed the gh sign-in (~/.config/gh/hosts.yml, config.yml) and the az sign-in files from ~/.azure per file, read-only, like pi/grok. - The Clone Repo AUTH_REQUIRED message says how to sign the server's git in instead of claiming private repositories cannot be cloned. - Docs: docker/README.md "Private repositories", docker-compose.md, docker-cases.md, the Quick-Start / Core-Concepts / Docker-Cases wiki pages, security-architecture.md, architecture-invariants.md, changeset. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0167CiuzLrmjYWxwKp3rMWjw
35 lines
1.5 KiB
Bash
Executable File
35 lines
1.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# Git credential helper for Azure DevOps, backed by the signed-in Azure CLI.
|
|
#
|
|
# Configured in the image's system gitconfig for https://dev.azure.com and
|
|
# https://*.visualstudio.com (see server.Dockerfile). On `get` it answers with
|
|
# an Entra ID access token for the Azure DevOps resource as the password, the
|
|
# same token type Git Credential Manager uses for Azure Repos. It never prompts:
|
|
# when `az` is not signed in it prints nothing, so git fails fast with its own
|
|
# authentication error instead of hanging a request that has no terminal.
|
|
#
|
|
# AZURE_DEVOPS_EXT_PAT, the azure-devops extension's own PAT variable, is used
|
|
# instead when it is set, for accounts that authenticate with a PAT.
|
|
|
|
# `store` and `erase` are no-ops: the token belongs to az, which refreshes it.
|
|
[ "$1" = "get" ] || exit 0
|
|
|
|
# Drain the request git writes on stdin; the host scoping is in gitconfig.
|
|
cat >/dev/null
|
|
|
|
if [ -n "${AZURE_DEVOPS_EXT_PAT:-}" ]; then
|
|
printf 'username=pat\npassword=%s\n' "$AZURE_DEVOPS_EXT_PAT"
|
|
exit 0
|
|
fi
|
|
|
|
command -v az >/dev/null 2>&1 || exit 0
|
|
|
|
# 499b84ac-1321-427f-aa17-267ca6975798 is the fixed application ID of Azure
|
|
# DevOps: https://learn.microsoft.com/azure/devops/integrate/get-started/authentication/service-principal-managed-identity
|
|
token="$(az account get-access-token \
|
|
--resource 499b84ac-1321-427f-aa17-267ca6975798 \
|
|
--query accessToken --output tsv 2>/dev/null)" || exit 0
|
|
[ -n "$token" ] || exit 0
|
|
|
|
printf 'username=azure-cli\npassword=%s\n' "$token"
|