Files
incredigo/lab/README.md
T
leetcrypt 681203cca1 lab: host restore drill — prove sealed backup restores (M2 prereq)
The CLI test proves export→import logic against a fake gopass; this proves the
real recovery path end-to-end against real gopass in an isolated throwaway store:
seed → seal → destroy every entry → import → assert byte-equal restoration and no
plaintext in the bundle. It is the safety net for no-op-RevokeOld drivers (e.g.
appsecret), where the sealed .age backup is the only rollback — the prerequisite
for the first real rotation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-07-18 20:19:48 -07:00

79 lines
4.1 KiB
Markdown

# lab/ — reproduce the rotation proofs (FAKE creds only)
These scripts stand up **real** target software in a throwaway VM and drive
`incredigo rotate --execute` against **fake** credentials in an **isolated** gopass
store. They are how the `LIVE-VM` proof levels in
[`../internal/rotate/proofs.go`](../internal/rotate/proofs.go) /
[`../docs/ROTATION-PROOFS.md`](../docs/ROTATION-PROOFS.md) were earned, and let anyone
reproduce them from a clean machine.
> **Safety:** every script uses `GNUPGHOME=$HOME/.lab-gnupg` + `GOPASS_HOMEDIR=$HOME/.lab-gopass`
> (a no-protection throwaway key) and fake creds. Nothing here can touch a real gopass
> store or a real provider. Run them in a disposable VM anyway.
## Quick start (Multipass, Ubuntu 24.04)
```sh
multipass launch 24.04 --name incredigo-sbx --disk 15G --memory 4G
# build a static binary and install it in the VM:
CGO_ENABLED=0 go build -o /tmp/incredigo ./cmd/incredigo
multipass transfer /tmp/incredigo incredigo-sbx:/home/ubuntu/incredigo
multipass exec incredigo-sbx -- sudo install -m755 /home/ubuntu/incredigo /usr/local/bin/incredigo
# install the real gopass release (NOT Ubuntu's apt 'gopass', which is a pass clone):
# https://github.com/gopasspw/gopass/releases -> /usr/local/bin/gopass
# copy the lab dir in and run a proof, e.g. postgres:
multipass transfer -r lab incredigo-sbx:/home/ubuntu/lab
multipass exec incredigo-sbx -- bash -lc 'cd lab && INCREDIGO_BIN=/usr/local/bin/incredigo bash lab-provision-pg.sh'
multipass exec incredigo-sbx -- bash -lc '
export GNUPGHOME=$HOME/.lab-gnupg GOPASS_HOMEDIR=$HOME/.lab-gopass
export INCREDIGO_PASSPHRASE=lab-seal-pass INCREDIGO_ALLOW_EXECUTE=1
incredigo rotate --execute --prefix imported/'
```
## LIVE-VM provisioners (real target software)
| Script | Proves driver | Target |
|---|---|---|
| `lab-provision-pg.sh` | `postgres` | real PostgreSQL |
| `lab-provision-dbclones.sh` | `mysql`, `redis` | real MariaDB + redis-server (self-asserting cutover) |
| `lab-provision-wg.sh` | `wireguard` | real `wireguard-tools` |
| `lab-provision-gitea.sh` | `gitea` | real Gitea 1.25 (self-owned PAT) |
| `lab-provision-appsec.sh` | `appsecret` | real local config files |
| `lab-provision-mongo.sh` | `mongo` | real mongod/mongosh 8.0 |
| `lab-provision-k8s.sh` | `k8s` | real k3s v1.35 |
## MOCK-ONLY provisioners (emulator / mock — same code path, not the real provider)
| Script | Driver | Emulator |
|---|---|---|
| `lab-provision-aws.sh` + `lab-verify-aws.sh` + `moto-probe.py` | `aws` | moto (mock AWS) |
## Phase-B `passwords` engine POCs
| Script | Manager |
|---|---|
| `lab-provision-keepass.sh` | KeePassXC (`keepassxc-cli`) |
| `lab-provision-bitwarden.sh` + `vw-register.py` | Vaultwarden + `bw` CLI |
| `lab-provision-browsercsv.sh` + `csv-commit-probe.py` | Chrome/Firefox CSV (staging only) |
| `lab-provision-browserrot.sh` | Phase A-tier-1 site-side rotation engine (`internal/browserrot`) — real headless Chromium against a throwaway local change-password form (fake cred) |
| `tui-probe.py` | drives the `guide` Bubble Tea TUI under a pty |
## Custody / smoke
- `lab-restore-drill.sh` — proves the sealed `.age` backup is a **real recovery path** on
the host against real gopass (isolated throwaway store, fake creds): seed → seal →
destroy every entry → `import` → assert byte-equal restoration + no plaintext in the
bundle. The safety net for no-op-`RevokeOld` drivers (e.g. `appsecret`), where the
backup is the only rollback. Prerequisite for the first real rotation (ROADMAP M2).
- `lab-store.sh` — throwaway key + gopass store + fake `.env`/`.aws`/consumer files.
- `lab-run.sh` — scan→status→migrate→export→import→`rotate --dry-run --blast`→worklist.
- `lab-harness.sh`, `incredigo-lab-setup.sh` — older combined harness variants.
## Notes carried over
- Ubuntu apt `gopass` is the **wrong tool** (a `pass` clone). Install gopasspw/gopass.
- Multipass snap **cannot read `/tmp`** — stage under `$HOME` before `multipass transfer`.
- `rotate --prefix` must be the `imported/` **root** (source = first path segment after it).
- Headless runs need `INCREDIGO_PASSPHRASE` (seal/backup passphrase, separate from GPG).