Repository navigation
fix(ansible): close grafana_alloy privilege and env-file review findings - #60
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
Environment parsing, root-alias identity validation, and nested secret-path handling remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Hardens Grafana Alloy credential handling and teardown, updates environment-file validation, and expands Molecule coverage.
Changes:
- Moves credentials to
/etc/grafana-alloy.envwith stronger path and ownership checks. - Replaces shell sourcing and fixes
--checkELF probing. - Updates documentation, templates, changelog, and regression tests.
File summaries
| File | Description |
|---|---|
ansible/roles/grafana_alloy/vars/main.yml |
Updates the ownership marker. |
ansible/roles/grafana_alloy/tasks/validate-paths.yml |
Rejects dot path segments. |
ansible/roles/grafana_alloy/tasks/preflight.yml |
Validates credential-parent security. |
ansible/roles/grafana_alloy/tasks/main.yml |
Adds identity validation and safer teardown. |
ansible/roles/grafana_alloy/README.md |
Documents the new credential path. |
ansible/roles/grafana_alloy/files/grafana-alloy.env.example |
Updates credential provisioning guidance. |
ansible/roles/grafana_alloy/defaults/main.yml |
Changes the default secret location. |
ansible/roles/decdn_node/tasks/main.yml |
Adds check-mode probing and Python environment parsing. |
ansible/roles/decdn_node/README.md |
Documents updated environment parsing. |
ansible/roles/decdn_node/files/decdn.env.example |
Updates environment-file guidance. |
ansible/README.md |
Updates credential provisioning instructions. |
ansible/molecule/validation/converge.yml |
Adds validation regression cases. |
ansible/molecule/slow-readiness/verify.yml |
Verifies disabled OTLP omission. |
ansible/molecule/grafana-cloud/verify.yml |
Updates path and teardown tests. |
ansible/molecule/grafana-cloud/prepare.yml |
Stages credentials at the new path. |
ansible/molecule/default/verify.yml |
Verifies literal RPC URL handling. |
ansible/molecule/default/converge.yml |
Adds shell-metacharacter test input. |
ansible/galaxy/CHANGELOG.md |
Records the fixes and behavior changes. |
Review details
- Files reviewed: 18/18 changed files
- Comments generated: 5
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
d64071b to
71d3f89
Compare
71d3f89 to
72d8bb2
Compare
|
Addressed the valid Copilot findings: UID/GID-0 aliases are now resolved and rejected; the EnvironmentFile loader implements only an exact, tested systemd-compatible subset; nested Alloy secret paths are explicitly rejected/documented; stale source/diagnostic wording is fixed. The json.loads and “could not be sourced” comments targeted the obsolete d64071b revision. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The secret-file containment check moved out of the stat-based parent audit and into the path-shape loop, so the ga-nested-secret-path rescue guard no longer matched and the case recorded no rejection tag. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Review (post-merge, head
|
Bug Description
Review findings from the internal sync at
7a6d744(decdn/internal-devops#15), filed as #59 — plus the--checkELF-probe miss in comment 7.Fixes #59
Root Cause
/etc/decdn, which the node user owns, so a compromiseddecdnprocess can replace the root-readEnvironmentFile.decdn config validatebash-sourced ato_json(double-quoted) env file, so$VAR/$(...)in an RPC URL expanded at validate time even though systemd would pass them through literally...but not..otlp_endpointwas untested.file -bwas skipped under--check, so the ELF assert saw empty stdout.Fix
/etc/grafana-alloy.env; require it to be a direct child of root-controlled/etc. Existing/etc/decdn/grafana-alloy.envfiles must be moved — nested overrides are intentionally rejected because a writable ancestor can replace the file.to_jsonrendering; replace bashsourcewith a non-expanding host parser restricted to one-line EnvironmentFile forms whose semantics it implements exactly..and..path segments.check_mode: falseto the read-only ELF probe.$HOME$(touch …), UID/GID-0 aliases, nested secret paths, disabled-path dot segments, and the OTLP omission branch.How to Verify
make molecule(needs Docker) — default / grafana-cloud / validation / slow-readiness.make checkagainst a dir-mode manual install should no longer fail the ELF assert./etc/grafana-alloy.envis provisioned asroot:root 0600directly under/etc.Test Plan
make lint-ansible— production profile, 0 failures / 0 warningsmake lint-alloy— Grafana Alloy 1.19.2 accepts all rendered variantsmake moleculelocally — Docker daemon unavailable on this runner; CI owns the containerized runRisk Assessment
Medium — the env-file load path for
decdn config validatechanged. Host-provisioned files remain supported in the documented one-line unquoted, complete single-quoted, and systemd double-quoted forms. The Alloy secret-path default is intentionally breaking for existing opt-in deployments: move/etc/decdn/grafana-alloy.envto/etc/grafana-alloy.env; overriding back to a nested path is rejected.