Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Private key security updates/fixes #2108

Merged
merged 5 commits into from
Nov 20, 2023
Merged

Conversation

angrybayblade
Copy link
Contributor

@angrybayblade angrybayblade commented Nov 15, 2023

Proposed changes

This PR

  • Fixes the start.sh script to use password if provided when issuing certificates
  • Updates the documentation on private key security in deployments

Fixes

fixes #2088
fixes #2089

If it fixes a bug or resolves a feature request, be sure to link to that issue.

Types of changes

What types of changes does your code introduce? (A breaking change is a fix or feature that would cause existing functionality and APIs to not work as expected.)
Put an x in the box that applies

  • Non-breaking fix (non-breaking change which fixes an issue)
  • Breaking fix (breaking change which fixes an issue)
  • Non-breaking feature (non-breaking change which adds functionality)
  • Breaking feature (breaking change which adds functionality)
  • Refactor (non-breaking change which changes implementation)
  • Messy (mixture of the above - requires explanation!)

Checklist

Put an x in the boxes that apply.

  • I have read the CONTRIBUTING doc
  • I am making a pull request against the main branch (left side). Also you should start your branch off our main.
  • Lint and unit tests pass locally with my changes
  • I have added tests that prove my fix is effective or that my feature works
  • I have locally run services that could be impacted and they do not present failures derived from my changes
  • Public-facing documentation has been updated with the changes affected by this PR. Even if the provided contents are not in their final form, all significant information must be included.
  • Any backwards-incompatible/breaking change has been clearly documented in the upgrading document.

Copy link

codecov bot commented Nov 15, 2023

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (7dab1ca) 94.13% compared to head (73037ec) 94.13%.
Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2108   +/-   ##
=======================================
  Coverage   94.13%   94.13%           
=======================================
  Files         255      255           
  Lines       15810    15810           
=======================================
  Hits        14883    14883           
  Misses        927      927           
Flag Coverage Δ
unittests 94.13% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Comment on lines 56 to 62
if [[ "$AEA_PASSWORD" != "" ]]; then
aea add-key cosmos --connection --password $AEA_PASSWORD
aea issue-certificates --password $AEA_PASSWORD
else
aea add-key cosmos --connection
aea issue-certificates
fi
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixes #2088

Copy link
Collaborator

@jmoreira-valory jmoreira-valory left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

trader-quickstart related PR valory-xyz/trader-quickstart#55 has been updated to latest branch (now on develop branch):

Copy link
Collaborator

@jmoreira-valory jmoreira-valory left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Steps to test this PR:

Build the agent image according to this PR:

cd open-autonomy/deployments/Dockerfiles/autonomy
docker build . -t valory/open-autonomy:rc0

Edit file open-autonomy/autonomy/data/Dockerfiles/agent/Dockerfile
Change
FROM ${AUTONOMY_IMAGE_NAME}:${AUTONOMY_IMAGE_VERSION}
by
FROM ${AUTONOMY_IMAGE_NAME}:rc0

Reinstall framework from local directory:

pip3 install -e ../../open-autonomy

@angrybayblade you can now mark issues #2108 and #2088 as completed.

@angrybayblade angrybayblade merged commit 777973d into main Nov 20, 2023
24 checks passed
@DavidMinarsch DavidMinarsch deleted the docs/pwd-security-kubernetes branch November 25, 2023 23:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Password stored in clear in deployment files Framework fails when running with password-protected keys
2 participants