Jon Chery
1b7aac71f6
feat(P5): proxmox native ingress mode — LXC + podman traefik (REQ-175)
...
Add --ingress-mode flag (native default, floating-ip) + --floating-ip,
--gateway, --mac, --net-prefix flags to 'orca node join'.
Native mode (default): provision an unprivileged LXC with
--features nesting=1,keyctl=1,fuse=1 (research Topic 3), install
podman inside it, run orca-traefik container. nft on PVE host DNATs
to the LXC bridge IP (DNATTarget parameterization, C-55: discover
LXC IP before first nft apply, no downtime window).
LXC provisioning: deterministic VMID 200, hostname orca-traefik,
--onboot 1, 2GB RAM. Idempotent (C-53: command -v podman check).
podman-restart.service enabled inside LXC (research Topic 6).
step-ca root CA pushed into LXC via pct exec heredoc.
traefik static config rendered + written into LXC.
nft ruleset rendered with DNATTarget=LXC-IP + applied on PVE host.
Migration 0009_ingress_mode.sql (C-59: NOT 0007 — already taken by
certs_serial_unique). ALTER TABLE nodes ADD COLUMN ingress_mode.
IngressMode field added to model.Node + set on proxmox node record.
---ci---
project: orca
phase: 5
milestone: v0.14
status: execute
---/ci---
2026-08-10 20:16:40 +00:00
Jon Chery
dea472f443
feat(P2): podman traefik reconciler + TLS model fix (REQ-172)
...
Replace internal/traefik/install.go binary+systemd installer with a
podman-container reconciler (R-024). The reconciler is idempotent:
inspect → start-if-stopped → pull+run-if-absent.
Container run flags (research-validated):
--restart=unless-stopped (not always; research Topic 6)
--network host (binds 127.0.0.1:8080/8443 on host/LXC loopback)
-v /etc/traefik/traefik.yml:ro (overrides baked default; C-58)
-v /etc/traefik/dynamic:ro (orca writes atomically via SSH-push)
-v /etc/orca/step-ca-root.crt:ro (future mTLS; v0.14 uses tls:{})
No :Z SELinux flag (research Topic 7)
C-50: ensurePodmanLocal/Remote installs podman if absent.
C-57: removeLegacySystemdUnitLocal/Remote stops+disables+removes
the v0.13 orca-traefik.service + /usr/local/bin/traefik before
starting the podman container (upgrade path).
upgrade.go cutover rewritten to use the reconciler.
TLS model fix (research Topic 4): drop certResolver: orca from
dynamic config (traefik v3.3 only supports acme/tailscale resolvers,
not CA-file-based). Emit tls: {} instead. Real mTLS via dynamic
tls.certificates + clientAuth.caFiles deferred to v0.15 (grill
G-003, confidence 0.55 < 0.60).
Callsites updated:
init.go: installTraefikLocal → ensureTraefikContainerLocal
linux/bootstrap.go: traefik.InstallRemote → EnsureTraefikContainerRemote
proxmox/bootstrap.go: same
traefik_install.go: wrapper updated
Tests: internal/traefik/install_test.go (new) — ImageRef, podmanRunArgs,
container-running/stopped/absent paths, legacy systemd removal (C-57).
---ci---
project: orca
phase: 2
milestone: v0.14
status: execute
---/ci---
2026-08-10 20:04:20 +00:00
Jon Chery
d324939699
fix: PVE role/user idempotency + init pre-staging instructions
...
- createPVERole: use grep -qF + fallback to pveum role mod (was broken
by single-quote-in-grep pattern: grep -q '^'OrcaOperator'')
- createPVEUser: same idempotency fix (grep -qF + fallback to mod)
- orca init: prints ssh-copy-id instructions with the orca public key
path after generating the SSH keypair
- docs/uat.md: removed manual pre-staging (ssh-keygen, ssh-copy-id
with operator key, host-key fingerprint pinning). orca init handles
key generation; node join uses the orca key by default; TOFU is
automatic. Updated node join examples to not pass --ssh-key or
--host-key-fingerprint.
---ci---
project: orca
status: fix
---/ci---
2026-08-10 17:07:30 +00:00
Jon Chery
16440a89f2
feat(B): Traefik deployment to all nodes during init/join (REQ-165, REQ-167)
...
- internal/traefik/install.go: shared Traefik installer (download +
systemd unit + dynamic dir). Default v3.3.0, configurable.
- orca init: installs Traefik on localhost (idempotent, non-fatal
if offline)
- proxmox bootstrap: installs Traefik on PVE host + downloads LXC
template (default ubuntu-24.04, --lxc-template flag)
- linux bootstrap: installs Traefik on worker
- emitter/traefik.go: directory provider (was single file);
register pve-ct/pve-vm in RegisterTraefik
- --lxc-template flag on node join (default ubuntu-24.04)
---ci---
project: orca
milestone: v0.12.18
phase: B
status: complete
requirements:
covered: [165, 167]
---/ci---
2026-08-10 16:09:48 +00:00
Jon Chery
a6ceb13491
fix(A): bootstrap plumbing — init creates SSH key + known_hosts + master key (REQ-164)
...
Fixes UAT issues 1, 8, 9, 12C, 13:
- orca init: generates SSH keypair (GenerateOrLoadSSHKey), creates
empty known_hosts (0600), generates master key (GenerateMasterKey +
SaveMasterKey). All were missing from runInit — every downstream
SSH/secrets/cluster operation failed on a fresh init.
- TOFUHostKeyCallbackPath: creates known_hosts file if it doesn't exist
(defense-in-depth alongside init)
- Linux bootstrap: replaces buggy inline TOFU with
proxmox.TOFUHostKeyCallbackPath (first-connect key capture works)
- --type flag help: includes "linux" (was "localhost or proxmox")
- doctor network: SSH exec probe (was HTTP /healthz to :8443 — no
daemon in SSH-push model R-001)
---ci---
project: orca
milestone: v0.12.18
phase: A
status: complete
requirements:
covered: [164]
---/ci---
2026-08-10 16:02:19 +00:00
Jon Chery
b6dd86fdf3
docs(P11): doc drift round 2 — README, cli.md, CHANGELOG, verify-reqs (REQ-160)
...
- README: status banner v0.12+v0.13, latest tag v0.12.10, subcommand
table expanded (auth/nft/peer-setup/secrets rotate-master), "mTLS by
default" corrected to "SSH-push canonical", docs table updated
- docs/cli.md: complete rewrite (521->1465 lines), all ~40 subcommands
- CHANGELOG: regenerated from git log (v0.11.29..HEAD)
- help text: job run HCL->markdown, job stop daemon->SSH-push
- docs/security-runbook.md: expanded to match P05 reality (seal/unseal,
doctor audit/modes/oidc, incident response)
- docs/webauthn.md: added auth register (P06)
- docs/namespace.md: added inherit + set-constraint
- internal/proxmox/bootstrap.go: comments password->key auth
- internal/cli/status.go: deprecation warning
- scripts/verify-docs.sh + make verify-docs: cli.md <-> orca --help
- cmd/verify-reqs/main.go: fix bold-format regex (was bypassing v0.12)
+ case-insensitive status matching
- .ciagent/REQUIREMENTS.md: v0.12 REQs marked complete
- .ciagent/ROADMAP.md: v0.12 bolded COMPLETE
---ci---
project: orca
phase: 11
milestone: v0.13
status: complete
requirements:
covered: [160]
---/ci---
2026-08-10 14:18:27 +00:00
Jon Chery
3a3ea74d76
fix(P08): transport + SSH safety — typed errors, IPv6, timeouts, signal (REQ-157)
...
- transport.IsTransient: typed sentinels (ErrTransient/ErrPermanent) +
standard net.Error/io errors.Is; substring matching removed
- sshpush.isTransient: same typed-error classification
- rotateSSHKeys: 2-phase atomic swap (stage peers -> swap local ->
verify -> cleanup old); no more partial-result window
- known_hosts: dial() reads stored field (was reading v0.8 path directly)
- IPv6: net.JoinHostPort in proxmox SSH dial + drain splitHostPort
- SSH timeouts: context.WithTimeout on peer-setup, drift, txn rollback,
job restart (default 2m)
- verifyCutover: orca CA pool TLS config (was default http.Client)
- OIDC callback: ReadHeaderTimeout 5s (slowloris defense)
- root Execute: signal.NotifyContext for SIGINT/SIGTERM (clean exit
for non-watch commands)
Tests: typed-error classification table, IPv6 JoinHostPort, signal
handler context cancellation.
---ci---
project: orca
phase: 8
milestone: v0.13
status: complete
requirements:
covered: [157]
---/ci---
2026-08-10 13:11:07 +00:00
Jon Chery
4b70e31cf4
fix(P02): input validation + injection hardening — 11 vectors (REQ-150)
...
Critical fixes:
- logs --job: validate ^[A-Za-z0-9_-]+$ + shellQuote (was %q backtick RCE)
- pprof: isLoopback treats empty host as bind-all (was :6060 bypass)
- backup restore: filepath.Rel containment check (was tar-slip via a/../..)
- WebAuthn reg auth deferred to P04 (requires session infra)
High fixes:
- txn rollback/show/apply: validate ^T-[0-9a-f]{16}$ + shellQuote
- nft diff --against: validate txn ID before filepath.Join
- drain stopAlloc: validate allocID ^[A-Za-z0-9_-]+$
- cluster_compat: shellQuote peer dir name
- podman image: shellQuote (was %q backtick injection)
- nft TrustedProbes: net.ParseIP/CIDR validation + split v4/v6 sets
- sudoers: validate --proxmox-user/--proxmox-role ^[a-zA-Z_][a-zA-Z0-9_-]{0,31}$
fixed path /etc/sudoers.d/orca; shellQuote pveum/useradd; validateSudoers
checks actual file
- nft country block: validate ^[A-Z]{2}$ (was len==2 only)
New file: internal/cli/validate.go (shared validators + shellQuote)
All 38 Go test packages pass. go vet + gofmt clean.
---ci---
project: orca
phase: 2
milestone: v0.13
status: complete
requirements:
covered: [150]
---/ci---
2026-08-07 19:28:01 +00:00
Jon Chery
ced2182322
fix(P20): system user consistency (REQ-135, F23)
...
---ci---
project: orca
phase: 20
milestone: v0.12
status: execute
---/ci---
Proxmox bootstrap now creates a nologin system user (-r -s
/usr/sbin/nologin), matching peer-setup. Previously it created a
login user (-m -s /bin/bash) with more privilege. Build + tests green.
2026-08-07 11:29:56 +00:00
Jon Chery
da682f1017
fix(P19): sudoers hardening — remove apt-get/dpkg (REQ-134, F22)
...
---ci---
project: orca
phase: 19
milestone: v0.12
status: execute
---/ci---
apt-get/dpkg removed from sudoers entirely (NOEXEC breaks maintainer
scripts; operator runs apt-get/dpkg out-of-band). Only pct + qm remain
(both NOEXEC). Tests updated. Build green.
2026-08-07 11:29:26 +00:00
Jon Chery
3269e1cb1d
fix(P19): sudoers hardening — NOEXEC on apt-get/dpkg (REQ-134, F22)
...
---ci---
project: orca
phase: 19
milestone: v0.12
status: execute
---/ci---
All sudoers commands now have NOEXEC (pct, qm, apt-get, dpkg) to
block shell escapes (REQ-134, F22). Previously apt-get/dpkg lacked
NOEXEC. Tests pass. Build green.
2026-08-07 11:28:24 +00:00
Jon Chery
20523ac045
fix(P07): remove all password/token paths (REQ-146, R-021, C-34) -- BREAKING
...
---ci---
project: orca
phase: 7
milestone: v0.12
status: execute
---/ci---
R-021 invariant: no passwords, no Orca-issued tokens, no CA-key
passphrases anywhere in the system.
Removed:
- proxmox/bootstrap.go: ssh.Password auth -> ssh.PublicKeys (key-based).
--password/ removed from node join; replaced
with --ssh-key (default: orca SSH key). Pre-staged key required.
- stepca/stepca.go: --password-file /dev/stdin removed from Init and
issueCert. Provisioner changed to 'orca-oidc' (OIDC provisioner).
- identity/spiffe.go: --password-file removed from MintSVID. Provisioner
changed to 'orca-oidc'.
Tests: all proxmox, stepca, identity, cli tests updated + pass. 3 new
password-rejection regression tests. Fake SSH server gains
PublicKeyCallback. go vet clean. Full build green.
2026-08-07 11:12:18 +00:00
Jon Chery
437aab39b4
feat(P0a1): multi-namespace path resolver + config demotion + known_hosts flock + CA migration spec (v0.9 P0a1)
...
P0a1 — Re-architecture Foundation (path resolver + config demotion).
Path resolver (REQ-070, R-002):
- internal/paths/paths.go: 23 functions for the multi-namespace layout
(Root/ClusterDir/NamespaceDir/NS*/DefaultNamespace/CA/MasterKey/CacheDB/
Txn/Peers/KnownHosts/SSH/Server/Config). Honors $ORCA_HOME. 100% coverage.
- internal/certpaths/certpaths.go: refactored as thin shim delegating to
paths, preserving the v0.8 flat-layout API for backward compat during
the dual-write window (REQ-090). Package doc explains the v0.10-P14
migration plan. certpaths deleted after v0.10-P14. 100% coverage.
Config demotion (REQ-069, R-014):
- internal/config/markdown.go: minimal hand-rolled YAML frontmatter parser
(no new dep — yaml.v3 not in go.mod). Returns same *Config struct as HCL.
- internal/config/config.go: renamed Load body to LoadHCL (// Deprecated
per R-013), added dispatcher Load() routing on extension (.hcl->HCL,
.md->Markdown, .yaml->Markdown). Signature preserved so root.go unchanged.
- dispatch_test.go + markdown_test.go: 89.8% coverage on config package.
Known_hosts flock (REQ-063, deferred P1 from REVIEW_v0.8 A2):
- internal/security/flock.go: stdlib syscall.Flock advisory lock helper.
- internal/proxmox/bootstrap.go: TOFUHostKeyCallback capture + ResetHostKey
both acquire the flock before read-modify-write on known_hosts. Prevents
concurrent writers under v0.9 parallel SSH fan-out. 3 flock tests.
CA migration spec (grill C-07):
- .ciagent/CA_MIGRATION_SPEC_v0.9.md: Option A (preserve trust root,
RECOMMENDED) vs Option B (forced re-bootstrap). Pre-flight checks,
migration steps, rollback, post-migration invariants, spike plan.
Verification: build pass, 17/17 Go packages pass, 20/20 bats pass, gofmt
clean, go vet clean, verify-reqs 90 consistent. Coverage: paths 100%,
certpaths 100%, config 89.8%, emit covered.
---ci---
project: orca
phase: P0a1
milestone: v0.9
status: execute
---/ci---
2026-08-05 16:38:26 +00:00
Jon Chery
2dcb14377a
fix(doctor): TOFU capture-fix parity with bootstrap — v0.6 ship-defect (T02.9)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:56:45 +00:00
Jon Chery
13e6762f0f
feat(cli): orca node key-reset <node> — local known_hosts reset (T02.8, REQ-059)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:51:47 +00:00
Jon Chery
325a5662f4
feat(proxmox): populate Result.HostKeyFingerprint (T02.7, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:48:00 +00:00
Jon Chery
8b0cbe10ae
fix(proxmox): TOFU capture bug — v0.6 ship-defect first-connect join always failed (T02.6)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:46:38 +00:00
Jon Chery
bd17e6e114
feat(proxmox): pinnedHostKeyCallback for --host-key-fingerprint (T02.5, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:45:53 +00:00
Jon Chery
7cb12c52ce
feat(proxmox): HostKeyFingerprint field on Options (T02.4, REQ-058)
...
---ci---
project: orca
phase: 2
milestone: v0.8
status: execute
---/ci---
2026-08-04 11:38:39 +00:00
Jon Chery
2786de166d
refactor(proxmox): extract sessionRunner seam for testability (T01.1, REQ-057)
...
---ci---
project: orca
phase: 1
milestone: v0.8
status: execute
---/ci---
2026-08-04 00:51:15 +00:00
Jon Chery
797bc2f412
feat(P02): Proxmox SSH join + OrcaOperator role + sudoers
...
orca node join --type proxmox bootstraps a remote Proxmox VE 8/9 host
via SSH (REQ-050, REQ-051). The password is used only for initial auth;
subsequent access uses the deployed orca SSH key (D-031).
Changes:
- go.mod: add golang.org/x/crypto v0.54.0 (ssh + ssh/knownhosts + ed25519)
bump x/sys to v0.47.0, add x/term (indirect)
- internal/certpaths: SSHKeyPath, SSHPubPath, KnownHostsPath (D-037)
- internal/security/sshkey.go: GenerateOrLoadSSHKey (Ed25519, PKCS8 PEM,
0600/0644 modes, idempotent load per D-036)
- internal/proxmox/bootstrap.go: BootstrapProxmox SSH dance:
1. Generate/load SSH key
2. SSH dial (password + knownhosts.New TOFU per D-035)
3. Deploy pubkey to ~orca/.ssh/authorized_keys (idempotent)
4. useradd -m orca (idempotent)
5. pveum role add OrcaOperator --privs 'VM.Audit Datastore.AllocateSpace SDN.Use'
6. pveum user add orca@pam (AD-019: PAM realm, not @pve)
7. pveum acl modify / -user orca@pam -role OrcaOperator
8. Write /etc/sudoers.d/orca (AD-020: NOEXEC on pct/qm, no NOEXEC on
apt-get/dpkg, pvesh EXCLUDED — API execute bypasses NOEXEC)
9. visudo -cf validation (abort on failure)
All steps idempotent; audit-logged.
- internal/cli/node.go: --type/--host/--ssh-user/--password/--ssh-port/
--proxmox-user/--proxmox-role flags; joinProxmox() wires to
proxmox.BootstrapProxmox + registers node with kind=proxmox, os=pve.
Password zeroed after use (D-031).
- tests: sshkey generate/load round-trip, idempotency, file modes;
proxmox sudoers content (NOEXEC/NOPASSWD/pvesh-excluded),
privilege set, validation; node join flag wiring
---ci---
project: orca
phase: 2
milestone: v0.6
status: execute
---/ci---
2026-08-03 19:55:14 +00:00