Files
incredigo/lab/README.md
T
leetcrypt 0c4e599342 lab: rung-1 appsecret host dress rehearsal (M2 ladder)
First end-to-end run of the real rotate --execute spine on the host toolchain —
real gopass, mandatory backup gate, audit log, INCREDIGO_PASSPHRASE seal flow —
against a THROWAWAY scratch app (dummy .env + config.yml, fake SECRET_KEY) in an
isolated store. Walks dry-run -> blast -> execute, asserts the in-place cutover
(old value gone from both files, one identical new value written, stored blob
updated, sealed backup produced) and that the old value is recoverable from the
backup. Confirms the safety-relevant asymmetry: only plan/dry-run/blast scan the
host (read-only, noop); --execute sources ONLY gopass entries under --prefix, so
it can rotate nothing but the scratch entry.

appsecret stays LIVE-VM: the scratch secret is fake, so this proves the host flow,
not a real credential. Promotion to LIVE-REAL is reserved for a real-cred rotation
with explicit per-credential authorization.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-18 20:27:53 -07:00

4.7 KiB

lab/ — reproduce the rotation proofs (FAKE creds only)

These scripts stand up real target software in a throwaway VM and drive incredigo rotate --execute against fake credentials in an isolated gopass store. They are how the LIVE-VM proof levels in ../internal/rotate/proofs.go / ../docs/ROTATION-PROOFS.md were earned, and let anyone reproduce them from a clean machine.

Safety: every script uses GNUPGHOME=$HOME/.lab-gnupg + GOPASS_HOMEDIR=$HOME/.lab-gopass (a no-protection throwaway key) and fake creds. Nothing here can touch a real gopass store or a real provider. Run them in a disposable VM anyway.

Quick start (Multipass, Ubuntu 24.04)

multipass launch 24.04 --name incredigo-sbx --disk 15G --memory 4G
# build a static binary and install it in the VM:
CGO_ENABLED=0 go build -o /tmp/incredigo ./cmd/incredigo
multipass transfer /tmp/incredigo incredigo-sbx:/home/ubuntu/incredigo
multipass exec incredigo-sbx -- sudo install -m755 /home/ubuntu/incredigo /usr/local/bin/incredigo
# install the real gopass release (NOT Ubuntu's apt 'gopass', which is a pass clone):
#   https://github.com/gopasspw/gopass/releases  -> /usr/local/bin/gopass

# copy the lab dir in and run a proof, e.g. postgres:
multipass transfer -r lab incredigo-sbx:/home/ubuntu/lab
multipass exec incredigo-sbx -- bash -lc 'cd lab && INCREDIGO_BIN=/usr/local/bin/incredigo bash lab-provision-pg.sh'
multipass exec incredigo-sbx -- bash -lc '
  export GNUPGHOME=$HOME/.lab-gnupg GOPASS_HOMEDIR=$HOME/.lab-gopass
  export INCREDIGO_PASSPHRASE=lab-seal-pass INCREDIGO_ALLOW_EXECUTE=1
  incredigo rotate --execute --prefix imported/'

LIVE-VM provisioners (real target software)

Script Proves driver Target
lab-provision-pg.sh postgres real PostgreSQL
lab-provision-dbclones.sh mysql, redis real MariaDB + redis-server (self-asserting cutover)
lab-provision-wg.sh wireguard real wireguard-tools
lab-provision-gitea.sh gitea real Gitea 1.25 (self-owned PAT)
lab-provision-appsec.sh appsecret real local config files
lab-provision-mongo.sh mongo real mongod/mongosh 8.0
lab-provision-k8s.sh k8s real k3s v1.35

MOCK-ONLY provisioners (emulator / mock — same code path, not the real provider)

Script Driver Emulator
lab-provision-aws.sh + lab-verify-aws.sh + moto-probe.py aws moto (mock AWS)

Phase-B passwords engine POCs

Script Manager
lab-provision-keepass.sh KeePassXC (keepassxc-cli)
lab-provision-bitwarden.sh + vw-register.py Vaultwarden + bw CLI
lab-provision-browsercsv.sh + csv-commit-probe.py Chrome/Firefox CSV (staging only)
lab-provision-browserrot.sh Phase A-tier-1 site-side rotation engine (internal/browserrot) — real headless Chromium against a throwaway local change-password form (fake cred)
tui-probe.py drives the guide Bubble Tea TUI under a pty

Custody / smoke

  • lab-rung1-appsecret-host.shsafe-candidate ladder rung 1, the host dress rehearsal: the first end-to-end run of the real rotate --execute spine on the host toolchain (real gopass, backup gate, audit, seal flow) against a throwaway scratch app (dummy .env + config.yml, fake secret). Walks dry-run → blast → execute → asserts the in-place cutover (old gone, one new value in both files, stored blob updated) → shows the old value is recoverable from the sealed backup. Isolated store, zero real-cred risk. appsecret stays LIVE-VM — a real-cred rotation is what earns LIVE-REAL. (ROADMAP M2 rung 1.)
  • lab-restore-drill.sh — proves the sealed .age backup is a real recovery path on the host against real gopass (isolated throwaway store, fake creds): seed → seal → destroy every entry → import → assert byte-equal restoration + no plaintext in the bundle. The safety net for no-op-RevokeOld drivers (e.g. appsecret), where the backup is the only rollback. Prerequisite for the first real rotation (ROADMAP M2).
  • lab-store.sh — throwaway key + gopass store + fake .env/.aws/consumer files.
  • lab-run.sh — scan→status→migrate→export→import→rotate --dry-run --blast→worklist.
  • lab-harness.sh, incredigo-lab-setup.sh — older combined harness variants.

Notes carried over

  • Ubuntu apt gopass is the wrong tool (a pass clone). Install gopasspw/gopass.
  • Multipass snap cannot read /tmp — stage under $HOME before multipass transfer.
  • rotate --prefix must be the imported/ root (source = first path segment after it).
  • Headless runs need INCREDIGO_PASSPHRASE (seal/backup passphrase, separate from GPG).