Inline OAuth2 signing key in config

The OAuth2/OIDC server accepted its signing key via a file path
(key-file), while every other PEM key in the probod config (SAML
private key, ACME account key) is embedded inline. Switch the
field to a private-key string so the convention is uniform.

The signing key is operator-supplied material that must outlive
any process restart, so the bootstrap builder now treats
OAUTH2_SERVER_SIGNING_KEY as required and refuses to start
without one; silently minting a fresh key per boot would break
token validation across rollouts. The OAUTH2_SERVER_* env vars
otherwise flow through builder.Build like the existing SAML
block so the new OAuth2Server section is populated end-to-end.

Rework the e2e harness to render its config via bootstrap at
test setup, which removes the static
e2e/console/testdata/config.yaml and the previously generated
test-only PEM file. A per-run RSA key is minted via
bootstrap.GenerateOAuth2SigningKey (kept public for test
tooling) and injected through the builder env map. CI now
passes ACME_ROOT_CA inline instead of mutating a YAML on disk.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2026-04-21 17:56:00 +02:00
parent a622c610d7
commit c4e81ed092
12 changed files with 288 additions and 170 deletions

View File

@@ -32,9 +32,10 @@ func mockEnv(env map[string]string) EnvGetter {
func requiredEnv() map[string]string {
return map[string]string{
"PROBOD_ENCRYPTION_KEY": "test-encryption-key-32-bytes-long",
"AUTH_COOKIE_SECRET": "test-cookie-secret-32-bytes-long!",
"AUTH_PASSWORD_PEPPER": "test-password-pepper-32-bytes-lo",
"PROBOD_ENCRYPTION_KEY": "test-encryption-key-32-bytes-long",
"AUTH_COOKIE_SECRET": "test-cookie-secret-32-bytes-long!",
"AUTH_PASSWORD_PEPPER": "test-password-pepper-32-bytes-lo",
"OAUTH2_SERVER_SIGNING_KEY": "test-oauth2-signing-key",
}
}
@@ -47,7 +48,16 @@ func TestBuilder_Build_MissingRequiredEnvVars(t *testing.T) {
{
name: "all missing",
env: map[string]string{},
wantMissing: []string{"PROBOD_ENCRYPTION_KEY", "AUTH_COOKIE_SECRET", "AUTH_PASSWORD_PEPPER"},
wantMissing: []string{"PROBOD_ENCRYPTION_KEY", "AUTH_COOKIE_SECRET", "AUTH_PASSWORD_PEPPER", "OAUTH2_SERVER_SIGNING_KEY"},
},
{
name: "missing oauth2 signing key",
env: map[string]string{
"PROBOD_ENCRYPTION_KEY": "key",
"AUTH_COOKIE_SECRET": "secret",
"AUTH_PASSWORD_PEPPER": "pepper",
},
wantMissing: []string{"OAUTH2_SERVER_SIGNING_KEY"},
},
{
name: "missing encryption key",
@@ -415,6 +425,64 @@ func TestBuilder_Build_SAMLPreset(t *testing.T) {
assert.Equal(t, "preset-key", cfg.Probod.Auth.SAML.PrivateKey)
}
func TestBuilder_Build_OAuth2Defaults(t *testing.T) {
b := NewBuilder(mockEnv(requiredEnv()))
cfg, err := b.Build()
require.NoError(t, err)
require.Len(t, cfg.Probod.Auth.OAuth2Server.SigningKeys, 1)
sk := cfg.Probod.Auth.OAuth2Server.SigningKeys[0]
assert.Equal(t, "test-oauth2-signing-key", sk.PrivateKey)
assert.Equal(t, "default", sk.KID)
assert.True(t, sk.Active)
assert.Equal(t, 3600, cfg.Probod.Auth.OAuth2Server.AccessTokenDuration)
assert.Equal(t, 2592000, cfg.Probod.Auth.OAuth2Server.RefreshTokenDuration)
assert.Equal(t, 600, cfg.Probod.Auth.OAuth2Server.AuthorizationCodeDuration)
assert.Equal(t, 600, cfg.Probod.Auth.OAuth2Server.DeviceCodeDuration)
}
func TestBuilder_Build_OAuth2FromEnv(t *testing.T) {
env := requiredEnv()
env["OAUTH2_SERVER_SIGNING_KEY"] = "env-signing-key"
env["OAUTH2_SERVER_SIGNING_KEY_KID"] = "env-kid"
env["OAUTH2_SERVER_ACCESS_TOKEN_DURATION"] = "10"
env["OAUTH2_SERVER_REFRESH_TOKEN_DURATION"] = "20"
env["OAUTH2_SERVER_AUTHORIZATION_CODE_DURATION"] = "30"
env["OAUTH2_SERVER_DEVICE_CODE_DURATION"] = "40"
b := NewBuilder(mockEnv(env))
cfg, err := b.Build()
require.NoError(t, err)
require.Len(t, cfg.Probod.Auth.OAuth2Server.SigningKeys, 1)
sk := cfg.Probod.Auth.OAuth2Server.SigningKeys[0]
assert.Equal(t, "env-signing-key", sk.PrivateKey)
assert.Equal(t, "env-kid", sk.KID)
assert.True(t, sk.Active)
assert.Equal(t, 10, cfg.Probod.Auth.OAuth2Server.AccessTokenDuration)
assert.Equal(t, 20, cfg.Probod.Auth.OAuth2Server.RefreshTokenDuration)
assert.Equal(t, 30, cfg.Probod.Auth.OAuth2Server.AuthorizationCodeDuration)
assert.Equal(t, 40, cfg.Probod.Auth.OAuth2Server.DeviceCodeDuration)
}
func TestBuilder_Build_OAuth2Preset(t *testing.T) {
env := requiredEnv()
delete(env, "OAUTH2_SERVER_SIGNING_KEY")
b := NewBuilder(mockEnv(env))
b.oauth2SigningKey = "preset-signing-key"
cfg, err := b.Build()
require.NoError(t, err)
require.Len(t, cfg.Probod.Auth.OAuth2Server.SigningKeys, 1)
assert.Equal(t, "preset-signing-key", cfg.Probod.Auth.OAuth2Server.SigningKeys[0].PrivateKey)
}
func TestBuilder_Build_PgCABundleFromEnv(t *testing.T) {
env := requiredEnv()
env["PG_CA_BUNDLE"] = "test-ca-bundle-content"