mirror of
https://github.com/dredx/prole.git
synced 2026-09-23 12:03:59 +00:00
Itemized changes:
1. knoe-auth: New cluster-internal KDC and SSO gateway service
- Created etc/init_knoe_auth.sh based on init_kdc.sh with knoe-auth naming
- Namespace defaults to SERVICE_NAMESPACE (knoe-system)
- ConfigMap: knoe-auth-kdc-config, Secret: knoe-auth-secrets
- Legacy cleanup removes old auth/dog/authority deployments
2. Orchestration: knoe-auth initializes before CloudNativePG
- Updated prole.sh to insert init_knoe_auth.sh as step 2 (before CNPG)
- Renumbered all subsequent initialization steps
3. Kong routing: Updated init_kong.sh to route to knoe-auth in SERVICE_NAMESPACE
4. Comment/reference updates for knoe-auth
- Updated init_common_services.sh, init_service_layer.sh, init_kerberos.sh
5. prole-db renamed to knoe-db across the entire codebase
- Renamed prole-db/ directory to knoe-db/
- Renamed all prole-db Kubernetes manifests (deploy/opentofu, k8s/)
- Renamed scripts: docker-root-knoe-db.sh, docker-run-knoe-db.sh, test-cnpg-knoe-db.sh
- Renamed etc/init_prole-db-reset.sh to etc/init_knoe-db-reset.sh
- Renamed etc/prole-db-passwwd.sh to etc/knoe-db-passwwd.sh
- Renamed mock_val counterparts accordingly
- Renamed tests/etc/test_init_prole-db-reset.sh to test_init_knoe-db-reset.sh
- Renamed docs/prole-db-documentation-mcp-architecture.md to knoe-db variant
- Renamed modes/k3d/prole-db/ to modes/k3d/knoe-db/
- Renamed prole-db.iml to knoe-db.iml
6. Configuration updates
- Updated conf/dev, conf/prod, conf/test, conf/service prole.cfg files
- Updated conf/port-mapping.cfg
- Updated etc/prole_cfg.sh and mock_val/prole_cfg.sh
- Updated service/prole.cfg
7. Kubernetes manifests and deploy configuration
- Updated deploy/opentofu/k3s ArgoCD application YAMLs
- Updated kong-configmap.yaml and kustomization.yaml
- Updated k3s/kong-config.yml and prole-resources.yaml
- Updated prole-mssql-db deployment YAMLs
- Updated supabase helm render and deploy scripts
8. Infrastructure and GCP Terraform
- Updated deploy/gcp/terraform: folders, groups, IAM, service-projects
9. Python/installer code updates
- Updated knoe/core: actions, build_context, controller, env, milestones
- Updated knoe/milestone.py
- Updated knoe/ui/screens: cfg, database, database_options, deploy, docker,
navigation, security, services, validate
- Updated knoe.spec, status.py
10. Shell script updates
- Updated etc/: build_db, init_cloudnative_pg, init_cnpg_backup,
init_db_manager, init_forgejo, init_gitlab, init_monitoring, init_openbao,
init_port_forwards, init_postgrest, init_supabase_ports, status
- Updated mock_val/ counterparts for all above scripts
- Updated prole-net/init-prole-dns.sh
- Updated bin/prole-kpf.sh, gitea/deploy.sh, supabase/deploy.sh
11. Test updates
- Updated tests/etc/: test_init_cloudnative_pg*, test_init_cnpg_backup*,
test_init_kdc*, test_init_kerberos*, test_init_kong*, test_prole_cfg*
- Updated tests/installer/: test_actions_helpers, test_cfg_save_kubecontext,
test_controller, test_core_classes, test_milestones, test_milestones_extended,
test_namespace_propagation
- Updated tests/: test_database_options, test_navigation,
test_render_supabase_hostname, test_docker_build_fix,
test_all_prole_home_fixes, silent_install_test, final_test
12. Documentation updates
- Updated docs/: DOCKER-BUILD-FIX, PROLE-CFG-SECRETS, PROLE-HOME-DIRECTORY,
build-system, patent
- Updated scan/network_description.txt
- Updated pom.xml
13. Miscellaneous script updates
- Updated root-level: _adopt_replica_pvcs, _fix_replica_merlin, _import_pi,
_patch_cluster, _prebind_pvcs, _rebind_d002, _rebind_d002b, test_resolve
- Updated scripts/generate_spec.py
Co-authored-by: Junie <junie@jetbrains.com>
1.8 KiB
1.8 KiB
prole.cfg Secrets
This document describes how secrets are handled in prole.cfg and where they are stored in OpenBao.
Temporary encrypted values
During installation, secrets are written to prole.cfg as temporary encrypted values so an interrupted run can resume:
- Format:
${PROLE_SECRET:v1:<nonce_b64>:<ciphertext_b64>} - Encryption: AES‑256‑GCM
- Key storage:
- macOS: login Keychain (service
prole-installer) - Other platforms:
~/.prole/secrets/installer.key(0600)
- macOS: login Keychain (service
These encrypted values are removed at Post‑Install by running etc/build-a-bao.sh.
OpenBao placeholders
After Post‑Install, secrets in prole.cfg are replaced with OpenBao placeholders that point to a namespace‑scoped KV path:
- Format:
${OPENBAO:kv/prole/<namespace>/<leaf>#<key>}
The namespace comes from NAMESPACE in prole.cfg and makes the file 1:1 with a single knoe-db deployment.
Secrets recorded in prole.cfg
The following keys are treated as secrets and stored in OpenBao:
| prole.cfg key | OpenBao KV path |
|---|---|
Inputs.init_password.db_password |
kv/prole/<namespace>/db#password |
Inputs.init_password.db_password_confirm |
kv/prole/<namespace>/db#password |
Global.DB_PASSWORD |
kv/prole/<namespace>/db#password |
Inputs.kerberos_config.password |
kv/prole/<namespace>/kerberos#password |
Kerberos Authentication.PASSWORD |
kv/prole/<namespace>/kerberos#password |
Monitoring.GRAFANA_ADMIN_PASSWORD |
kv/prole/<namespace>/monitoring#grafana_admin_password |
Post‑Install step
Run the Build‑A‑Bao step on the Post‑Install screen (or etc/build-a-bao.sh) to:
- Decrypt temporary secrets from
prole.cfg - Write them to OpenBao under the namespace path
- Replace
prole.cfgsecrets with OpenBao placeholders