Skip to content

Reassert secrets.json permissions on daemon startup - #2288

Open
mikemikimike wants to merge 1 commit into
netclaw-dev:devfrom
mikemikimike:netclaw-2075-codex
Open

mikemikimike wants to merge 1 commit into
netclaw-dev:devfrom
mikemikimike:netclaw-2075-codex

Conversation

@mikemikimike

Copy link
Copy Markdown

Summary

Reassert owner-only permissions on an existing secrets.json before the daemon loads it, covering deployments where a volume mount relaxes the file mode. Add a regression test that restores a group-readable file to 0600.

Fixes #2075

Issue: #2075

Validation

  • dotnet build Netclaw.slnx -c Release --no-restore
  • dotnet test src/Netclaw.Configuration.Tests/Netclaw.Configuration.Tests.csproj -c Release --no-build --filter FullyQualifiedName~SecretsFileWriterTests
  • dotnet slopwatch analyze

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

secrets.json left group-readable under Kubernetes fsGroup (0600 not re-asserted on load)

1 participant