Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[Bug] Docker entrypoint auth bootstrap is unsafe for mounted and upgraded configs

Đang mở
#3,133 5 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
45/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
docker, github-actions, java, shell

Hướng nghiên cứu

Bắt đầu với docker-entrypoint.sh và bin/enable-auth.sh để theo dõi quy trình bootstrap xác thực hiện tại và các đường dẫn viết lại thuộc tính. Sau đó kiểm tra phạm vi config CLI được đề xuất, bộ kiểm thử entrypoint và các bộ lọc đường dẫn trong docker-build-ci.yml. Được xem là hoàn tất khi các cấu hình được mount và được nâng cấp được xử lý nhất quán, các secret không bị lộ dưới dạng đối số tiến trình, và các bài kiểm thử shell được liệt kê bao phủ contract của entrypoint.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug improvement

Problem

The Docker entrypoint bootstraps authentication with grep/sed against
conf/rest-server.properties. That works for the shipped defaults it was
written for, but not for mounted configs, upgraded volumes, or any value whose
encoding differs between shell and HugeConfig.

Concrete cases, most of them raised during review of #3119:

  • Gremlin and REST can end up on different auth providers. The check is a
    presence-only grep for auth.authenticator, so a config that already has
    the REST property but not the Gremlin side is treated as fully configured.
  • A pre-existing authenticated volume can fail its first startup after
    upgrade.
    A legacy volume can carry docker/init_complete while the
    bootstrap state the entrypoint now expects is absent.
  • PASSWORD is observable. It is currently handed to Java as a command-line
    argument, which puts it in ps output for every process in the container.
  • sed rewriting does not implement the Java properties grammar. Escaped
    keys, : and whitespace separators, continuations, and duplicate logical
    definitions are all read differently by HugeConfig than by the entrypoint.
    Concretely, set_prop detects only key=, so a mounted config using :
    gets a second logical definition appended and HugeConfig then rejects the
    file as a list. This affects backend and pd.peers as well as
    init_store.enabled, so the fix should cover all of them together.
  • PASSWORD silently does nothing when init-store is skipped. init-store
    reads it from stdin, and the disabled path returns before that, so the admin
    is created on the PD startup path from auth.admin_pa — public default pa.
    #3119 documents this and warns at runtime; it does not fix it.

The first case, as it stands on master 98477f0f5: the entrypoint no longer
greps for auth.authenticator itself, it calls bin/enable-auth.sh whenever
PASSWORD is set, and that script gates only on whether conf-bak/ exists.
On a config it did not write, it appends a second definition to both files,
and the two parsers disagree about which one wins.

A mounted authenticator plus the one enable-auth.sh appends: REST resolves to the first, Gremlin to the last

Proposal

Move property reading and writing off grep/sed and onto the same
Commons Configuration path HugeConfig uses, so both sides agree on encoding,
and let the entrypoint delegate auth classification to it.

Rough shape:

  • a small ConfigTool CLI for typed get/set against a properties file,
    preserving comments, file mode, and inode for mounted configs;
  • entrypoint uses it instead of grep/sed, and stops passing secrets as
    process arguments;
  • auth bootstrap becomes explicit about mounted, upgraded, and custom
    authenticator cases rather than inferring from one key's presence;
  • a shell test suite covering the entrypoint contract, wired into
    docker-build-ci.yml.

Scope

In scope: docker-entrypoint.sh, the new config CLI and its wrapper, the
entrypoint test suite, and the workflow path filters that run it.

Out of scope: the init_store.enabled option and its gate (#3118 / #3119),
Helm chart structure, and GraphManager behavior.

Context

This work originally shared a branch with #3119. That made a ~2,900-line diff
covering two unrelated ideas, so it was split out to keep each reviewable on
its own. #3119 now carries only the option, the gate, the env mapping, and the
init-flag guard.

Visual summary

Docker auth bootstrap

Ngôn ngữ chính
Java
Star
3.2k
Fork
637
Merge trung bình
3 ngày 17 giờ
Pull request đã merge (30 ngày)
22

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của apache/hugegraph

Tất cả issue của apache/hugegraph

Issue tương tự

Thêm issue về Java

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.