0c4e599342
First end-to-end run of the real rotate --execute spine on the host toolchain — real gopass, mandatory backup gate, audit log, INCREDIGO_PASSPHRASE seal flow — against a THROWAWAY scratch app (dummy .env + config.yml, fake SECRET_KEY) in an isolated store. Walks dry-run -> blast -> execute, asserts the in-place cutover (old value gone from both files, one identical new value written, stored blob updated, sealed backup produced) and that the old value is recoverable from the backup. Confirms the safety-relevant asymmetry: only plan/dry-run/blast scan the host (read-only, noop); --execute sources ONLY gopass entries under --prefix, so it can rotate nothing but the scratch entry. appsecret stays LIVE-VM: the scratch secret is fake, so this proves the host flow, not a real credential. Promotion to LIVE-REAL is reserved for a real-cred rotation with explicit per-credential authorization. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
4.7 KiB
4.7 KiB
lab/ — reproduce the rotation proofs (FAKE creds only)
These scripts stand up real target software in a throwaway VM and drive
incredigo rotate --execute against fake credentials in an isolated gopass
store. They are how the LIVE-VM proof levels in
../internal/rotate/proofs.go /
../docs/ROTATION-PROOFS.md were earned, and let anyone
reproduce them from a clean machine.
Safety: every script uses
GNUPGHOME=$HOME/.lab-gnupg+GOPASS_HOMEDIR=$HOME/.lab-gopass(a no-protection throwaway key) and fake creds. Nothing here can touch a real gopass store or a real provider. Run them in a disposable VM anyway.
Quick start (Multipass, Ubuntu 24.04)
multipass launch 24.04 --name incredigo-sbx --disk 15G --memory 4G
# build a static binary and install it in the VM:
CGO_ENABLED=0 go build -o /tmp/incredigo ./cmd/incredigo
multipass transfer /tmp/incredigo incredigo-sbx:/home/ubuntu/incredigo
multipass exec incredigo-sbx -- sudo install -m755 /home/ubuntu/incredigo /usr/local/bin/incredigo
# install the real gopass release (NOT Ubuntu's apt 'gopass', which is a pass clone):
# https://github.com/gopasspw/gopass/releases -> /usr/local/bin/gopass
# copy the lab dir in and run a proof, e.g. postgres:
multipass transfer -r lab incredigo-sbx:/home/ubuntu/lab
multipass exec incredigo-sbx -- bash -lc 'cd lab && INCREDIGO_BIN=/usr/local/bin/incredigo bash lab-provision-pg.sh'
multipass exec incredigo-sbx -- bash -lc '
export GNUPGHOME=$HOME/.lab-gnupg GOPASS_HOMEDIR=$HOME/.lab-gopass
export INCREDIGO_PASSPHRASE=lab-seal-pass INCREDIGO_ALLOW_EXECUTE=1
incredigo rotate --execute --prefix imported/'
LIVE-VM provisioners (real target software)
| Script | Proves driver | Target |
|---|---|---|
lab-provision-pg.sh |
postgres |
real PostgreSQL |
lab-provision-dbclones.sh |
mysql, redis |
real MariaDB + redis-server (self-asserting cutover) |
lab-provision-wg.sh |
wireguard |
real wireguard-tools |
lab-provision-gitea.sh |
gitea |
real Gitea 1.25 (self-owned PAT) |
lab-provision-appsec.sh |
appsecret |
real local config files |
lab-provision-mongo.sh |
mongo |
real mongod/mongosh 8.0 |
lab-provision-k8s.sh |
k8s |
real k3s v1.35 |
MOCK-ONLY provisioners (emulator / mock — same code path, not the real provider)
| Script | Driver | Emulator |
|---|---|---|
lab-provision-aws.sh + lab-verify-aws.sh + moto-probe.py |
aws |
moto (mock AWS) |
Phase-B passwords engine POCs
| Script | Manager |
|---|---|
lab-provision-keepass.sh |
KeePassXC (keepassxc-cli) |
lab-provision-bitwarden.sh + vw-register.py |
Vaultwarden + bw CLI |
lab-provision-browsercsv.sh + csv-commit-probe.py |
Chrome/Firefox CSV (staging only) |
lab-provision-browserrot.sh |
Phase A-tier-1 site-side rotation engine (internal/browserrot) — real headless Chromium against a throwaway local change-password form (fake cred) |
tui-probe.py |
drives the guide Bubble Tea TUI under a pty |
Custody / smoke
lab-rung1-appsecret-host.sh— safe-candidate ladder rung 1, the host dress rehearsal: the first end-to-end run of the realrotate --executespine on the host toolchain (real gopass, backup gate, audit, seal flow) against a throwaway scratch app (dummy.env+config.yml, fake secret). Walks dry-run → blast → execute → asserts the in-place cutover (old gone, one new value in both files, stored blob updated) → shows the old value is recoverable from the sealed backup. Isolated store, zero real-cred risk.appsecretstays LIVE-VM — a real-cred rotation is what earns LIVE-REAL. (ROADMAP M2 rung 1.)lab-restore-drill.sh— proves the sealed.agebackup is a real recovery path on the host against real gopass (isolated throwaway store, fake creds): seed → seal → destroy every entry →import→ assert byte-equal restoration + no plaintext in the bundle. The safety net for no-op-RevokeOlddrivers (e.g.appsecret), where the backup is the only rollback. Prerequisite for the first real rotation (ROADMAP M2).lab-store.sh— throwaway key + gopass store + fake.env/.aws/consumer files.lab-run.sh— scan→status→migrate→export→import→rotate --dry-run --blast→worklist.lab-harness.sh,incredigo-lab-setup.sh— older combined harness variants.
Notes carried over
- Ubuntu apt
gopassis the wrong tool (apassclone). Install gopasspw/gopass. - Multipass snap cannot read
/tmp— stage under$HOMEbeforemultipass transfer. rotate --prefixmust be theimported/root (source = first path segment after it).- Headless runs need
INCREDIGO_PASSPHRASE(seal/backup passphrase, separate from GPG).