fix(bridge): qualify beta enrollment and curated Dex runtime - #570
Draft
Pal Lakatos-Toth (pallakatos) wants to merge 13 commits into
Draft
Pal Lakatos-Toth (pallakatos) wants to merge 13 commits into
Pal Lakatos-Toth (pallakatos) wants to merge 13 commits into
Conversation
Retain enforcement and original failures; report only fixed annotation booleans and UID-fenced retirement phase comparisons. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Dependency ReviewThe following issues were found:
|
Read retained audit rotations, fence request barriers by Audit-Id, preserve exact CREATE counts, and disallow RBAC or transport failures as private-audience denial proof. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve the production policy default and classify its exact Invalid response. Treat only a missing active audit file during rotation as a bounded retry. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Expose only the non-secret fixture review failure; preserve private TokenRequest and Secret redaction and all admission requirements. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Avoid kubectl CRD discovery under the intentionally restricted fixture identity. Keep server validation, exact impersonation, and all private-audience denial checks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Pin stable upstream source, verified Go-generated dependency locks and disclosed compatibility patches. Require real OIDC/SQLite, signing continuity, native linkage, preserved attribution and full final-image vulnerability checks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ication Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
There was a problem hiding this comment.
Trivy found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.
Keep all final-image gates mandatory while using RUNNER_TEMP only after a runner exists. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…links Keep active dependency manifests scanned, preserve archived baseline bytes and checksums, require nonroot replay, and resolve the real base-provided ELF interpreter before executing it. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Match the pinned upstream login contract exactly, retain error-form and no-callback requirements, and reject misleading successful or unrelated error responses. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Pal Lakatos-Toth (pallakatos)
marked this pull request as ready for review
September 16, 2026 19:38
Pal Lakatos-Toth (pallakatos)
requested review from
Johnson Shi (johnsonshi) and
Lachlan Evenson (lachie83)
as code owners
September 16, 2026 19:38
Promote the verified single-module Go resolver update to go-ntlmssp v0.1.1, require its overflow regression, and retain the actual compiled package inventory with a fatal OpenPGP import guard. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Pal Lakatos-Toth (pallakatos)
marked this pull request as draft
September 16, 2026 20:13
Record bounded process state, fixed current/previous startup markers and exact-router kubelet probe categories after native observer failure. Preserve UID/RV provenance and keep readiness, network intervention and acceptance gates unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reject UID or resourceVersion drift when multiple Pods share one ReplicaSet. The two-Pod regression reproduces the previous revision false acceptance and verifies stable shared anchors remain supported. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current combined candidate
Current head 7ae918c adds failure-only observer startup/rollout evidence and its tests/documentation. Production code, dependencies, image recipes, readiness assertions, policies and deadlines are unchanged from the security-qualified component candidate below. The native failure is not claimed fixed.
The new collector retains bounded container state/restarts/previous exits, separate current/previous fixed startup markers, and exact-Pod/exact-router kubelet probe categories. It preserves the first UID/resourceVersion snapshot when multiple Pods share a ReplicaSet and discards changed snapshots. The original review found that repeated reads could overwrite that first anchor; a two-Pod regression reproduced the old resourceVersion false acceptance, and the correction's re-review closed the finding. All212 native Python diagnostic contracts passed. No raw logs, probe URLs/bodies, container IDs, secret values or arbitrary errors are retained.
Current-head Bridge CI35154265976 passed all12 jobs, including actual Dex runtime qualification and image scans. Native run35154266163 passed all18 runtime cases and all3 cold-install API lanes. Runtime artifact10471406371 was verified against ZIP SHA256
89c5c29477a2a585f94f0a58d4d961c75623363a45adfbd30385bc704447d404, exact7ae source and all18 passed outcomes; real network-policy enforcement is qualified for the no-active-SRE lane. Core CI35154266055 still awaits its final E2E/benchmark jobs.The earlier unready-router failure did not recur; its cause is still unestablished. This passing execution is not a claim that diagnostics fixed production behavior. No failed result was relabeled, approval refreshed, current-observer provenance relaxed or intervention enabled on an unready process.
Security follow-up and preceding qualification
Security follow-up 0f47f36 patches the real Medium CVE-2026-32952 dependency to
github.com/Azure/go-ntlmssp v0.1.1using a verified hosted Go resolver artifact. It is the only changed module selection; existing API locks, source pins and archival baseline bytes are preserved. The build also retains the actual compiled Go package inventory and fails if unsafex/crypto/openpgppackages are present. There is no scanner exclusion or advisory waiver.The guarded merge of the previously green candidate stopped on those unresolved security discussions before any branch-protection mutation. The NTLM regression and actual compiled-package guard subsequently executed successfully at this head. Both discussions were resolved with evidence; the NTLM instance is fixed and OpenPGP was not dismissed or claimed fixed.
Preceding 0f47 outcomes: all 12 Bridge jobs, including the complete NTLM-fixed Dex runtime, passed in run35145255990. Full core CI35145255952 passed, including E2E and benchmarks. Dex artifact10466986564 was verified against its server digest
2dfd144658b2db7fa695e3bcc5fb28d1a4d66e52538acb2ca3b4e990bd76f5bdand exact checkout/tree.Native acceptance remains failed. Run35145255231 attempt1 completed its runtime step but failed artifact finalization with HTTP403; no finalized runtime artifact existed. One same-source failed-jobs retry was performed without source or permission changes. Attempt2 successfully uploaded its evidence and cleaned up its disposable cluster, but actual runtime execution failed 14 passed / 1 failed / 3 blocked. Verified artifact10469104605 has ZIP SHA256
874858843c4566f426edf6ad07a6feac52880541c96c8c94a2646fc9c4cff87c.The failed case is
private-bff-observer-and-fresh-privacy-rpc: deadline waiting for the current observer capability. Its Pod was Running with OpenClaw ready but the inference-router not ready; controller diagnostics reportedconsumer_rollout_pending. Private scope/writer checks were qualified. The network experiment refused its baseline before any policy creation. Missing startup/probe evidence does not prove a CNI, authentication or application cause. The bounded source-reviewed diagnostic follow-up above is not a production fix or a waived retry.Previously qualified candidate (not merged)
Historical candidate 369aa86 passed all12 Bridge jobs, including actual final Dex Azure Linux native linkage, preserved base/CA/RPM inventory, real memory OIDC, SQLite OIDC plus old-key/refresh continuity after restart, and a fresh OS/Go High/Critical scan with zero findings. Artifact10462758755's server digest and the synthetic checkout's tree equivalence were verified. All18 same-head native cases also passed with verified artifact10463719508; its complete core checks subsequently passed too. Those historical results do not override the later dependency update or current native failure.
No Dex image has been published to the operator registry or deployed. Independent rebuild/payload comparison and the configured live beta journey remain separate requirements. This PR is still draft, not deployment approval.
Retained source and qualification history
Head
d3778aa2b75d836bfc7fdaf1e5c4a3e41e25684cadds the complete curated Dex source/dependency recipe and mandatory final-runtime CI job. Source commitf7cc7df8ef1cdfce9d4d92159a4e0ade5153bc1fhas independent packaging, compatibility, key-continuity and CI review closure; the new audit records scope and execution limits.The latest official stable Dex image failed its actual High/Critical scan and was not deployed. This rebuild uses pinned stable application source, real Go-generated and verified dependency locks, a pinned Go security patch release and Microsoft Azure Linux distroless. Two disclosed literal-format fixes keep vet enabled; a historical test clock does not change production certificate validation. Real CGO/SQLite and upstream features remain implemented.
Earlier no-push ACR execution passed compatibility tests, upstream root/API race-suite commands, nine signing-key-continuity cases and probe compilation. Twenty pinned-source/tamper tests also ran successfully. Later GHA final-runtime outcomes are recorded above. An independent ACR rebuild/payload comparison, final-runtime requalification and fresh scan before guarded publication remain required—not inferred from source, compiler or a different image's success.
The new IdP job is part of the existing mandatory Bridge aggregate; failures remain fatal. Attribution rules require normal Go headers and narrowly enumerate legal/generated/upstream integrity data without modifying those bytes or exempting source directories.
The fixture-only predecessor
a2712056af3f8b402149466b60ee29a634aa20a1passed its actual budget admission gate and all18 native cases on the same head. The permission-review blocker was proven to be kubectl's client-side CRD discovery; direct built-in API transport fixed it without additional privileges or disabling server validation. Fresh combined-head checks remain required.Retained fixture evidence changes
The earlier fixture-only head8512b50b4d5b565673e8d7c64eebcc92cbbf93f7 added native evidence corrections, not production policy changes. The public578 run is retained: late observer/TLS/CNI/rotation passed there, but bootstrap's exclusive audited CREATE check failed (16passed/1failed/1blocked). Its actual CREATE count was not retained; a duplicate production CREATE is not established.
The fixture previously read only active audit.log despite configured rotation and called a fixed one-second sleep a barrier. It now reads bounded retained logs, rechecks rotation inventory, preserves distinct requests while deduplicating identical AuditIDs, waits for the actual server-issued audit marker, and rejects intervals missing their starting marker. Exact CREATE count1 remains required; observed counts are now reported without secret data.
The budget fixture now proves the principal's TokenRequest RBAC and an ordinary-audience positive before requiring the precise private-audience policy rejection. Generic RBAC/network errors cannot count as admission proof. An independent review corrected the classifier to Kubernetes1.31's actual default Invalid response, exact policy/binding and validation message, and closed the audit rename/recreate retry gap. Production admission expressions and reasons are unchanged.
That fixture checkpoint passed201native Python and11Node wrapper regressions locally; subsequent a271 added the actual raw-transport proof and passed the native gates described above. Dex packaging was deliberately excluded from those earlier heads.
Retained annotation investigation
Failure-only native fixture diagnostics for the post-merge enrollment refusal in run35102511778, exact public b413f34.
The post-merge run passed14 cases, failed late observer enrollment with consumer-template-drift, and blocked3 dependent TLS/CNI/rotation cases. The runtime Deployment retained its UID and changed only template annotations; the root controller and BFF templates remained unchanged. The existing data does not identify the annotation or establish a production cause. Two pre-merge heads passed, but those passes do not waive this failure.
This change adds only fixed boolean groups for known private-epoch, services-credential, credential-projection and inference-provider annotations, plus an other-annotations boolean. No annotation values, names supplied by a cluster, template hashes or secret material are published.
An additional UID/resourceVersion-fenced namespace read reports only a whitelisted late-retirement phase and whether the current template matches its recorded template. It explicitly does not verify authority. Unavailable optional receipt diagnostics do not erase independently valid Deployment comparisons.
Validation and limits
13 focused annotation redaction/provenance tests are included in the current Python results. This is not a production fix, successful current-head native retry, merge approval or deployment qualification. No enforcement condition, authority, image, Helm default or customer object changes. The audit barrier has a bounded evidence-availability wait; runtime/private-retirement deadlines and denial expectations are not relaxed.
The installation remains held while the actual failure is diagnosed. The previously successful distroless image builds/scans remain valid component evidence, not full installation acceptance.