0c4e599342
First end-to-end run of the real rotate --execute spine on the host toolchain — real gopass, mandatory backup gate, audit log, INCREDIGO_PASSPHRASE seal flow — against a THROWAWAY scratch app (dummy .env + config.yml, fake SECRET_KEY) in an isolated store. Walks dry-run -> blast -> execute, asserts the in-place cutover (old value gone from both files, one identical new value written, stored blob updated, sealed backup produced) and that the old value is recoverable from the backup. Confirms the safety-relevant asymmetry: only plan/dry-run/blast scan the host (read-only, noop); --execute sources ONLY gopass entries under --prefix, so it can rotate nothing but the scratch entry. appsecret stays LIVE-VM: the scratch secret is fake, so this proves the host flow, not a real credential. Promotion to LIVE-REAL is reserved for a real-cred rotation with explicit per-credential authorization. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
87 lines
4.7 KiB
Markdown
87 lines
4.7 KiB
Markdown
# lab/ — reproduce the rotation proofs (FAKE creds only)
|
|
|
|
These scripts stand up **real** target software in a throwaway VM and drive
|
|
`incredigo rotate --execute` against **fake** credentials in an **isolated** gopass
|
|
store. They are how the `LIVE-VM` proof levels in
|
|
[`../internal/rotate/proofs.go`](../internal/rotate/proofs.go) /
|
|
[`../docs/ROTATION-PROOFS.md`](../docs/ROTATION-PROOFS.md) were earned, and let anyone
|
|
reproduce them from a clean machine.
|
|
|
|
> **Safety:** every script uses `GNUPGHOME=$HOME/.lab-gnupg` + `GOPASS_HOMEDIR=$HOME/.lab-gopass`
|
|
> (a no-protection throwaway key) and fake creds. Nothing here can touch a real gopass
|
|
> store or a real provider. Run them in a disposable VM anyway.
|
|
|
|
## Quick start (Multipass, Ubuntu 24.04)
|
|
|
|
```sh
|
|
multipass launch 24.04 --name incredigo-sbx --disk 15G --memory 4G
|
|
# build a static binary and install it in the VM:
|
|
CGO_ENABLED=0 go build -o /tmp/incredigo ./cmd/incredigo
|
|
multipass transfer /tmp/incredigo incredigo-sbx:/home/ubuntu/incredigo
|
|
multipass exec incredigo-sbx -- sudo install -m755 /home/ubuntu/incredigo /usr/local/bin/incredigo
|
|
# install the real gopass release (NOT Ubuntu's apt 'gopass', which is a pass clone):
|
|
# https://github.com/gopasspw/gopass/releases -> /usr/local/bin/gopass
|
|
|
|
# copy the lab dir in and run a proof, e.g. postgres:
|
|
multipass transfer -r lab incredigo-sbx:/home/ubuntu/lab
|
|
multipass exec incredigo-sbx -- bash -lc 'cd lab && INCREDIGO_BIN=/usr/local/bin/incredigo bash lab-provision-pg.sh'
|
|
multipass exec incredigo-sbx -- bash -lc '
|
|
export GNUPGHOME=$HOME/.lab-gnupg GOPASS_HOMEDIR=$HOME/.lab-gopass
|
|
export INCREDIGO_PASSPHRASE=lab-seal-pass INCREDIGO_ALLOW_EXECUTE=1
|
|
incredigo rotate --execute --prefix imported/'
|
|
```
|
|
|
|
## LIVE-VM provisioners (real target software)
|
|
|
|
| Script | Proves driver | Target |
|
|
|---|---|---|
|
|
| `lab-provision-pg.sh` | `postgres` | real PostgreSQL |
|
|
| `lab-provision-dbclones.sh` | `mysql`, `redis` | real MariaDB + redis-server (self-asserting cutover) |
|
|
| `lab-provision-wg.sh` | `wireguard` | real `wireguard-tools` |
|
|
| `lab-provision-gitea.sh` | `gitea` | real Gitea 1.25 (self-owned PAT) |
|
|
| `lab-provision-appsec.sh` | `appsecret` | real local config files |
|
|
| `lab-provision-mongo.sh` | `mongo` | real mongod/mongosh 8.0 |
|
|
| `lab-provision-k8s.sh` | `k8s` | real k3s v1.35 |
|
|
|
|
## MOCK-ONLY provisioners (emulator / mock — same code path, not the real provider)
|
|
|
|
| Script | Driver | Emulator |
|
|
|---|---|---|
|
|
| `lab-provision-aws.sh` + `lab-verify-aws.sh` + `moto-probe.py` | `aws` | moto (mock AWS) |
|
|
|
|
## Phase-B `passwords` engine POCs
|
|
|
|
| Script | Manager |
|
|
|---|---|
|
|
| `lab-provision-keepass.sh` | KeePassXC (`keepassxc-cli`) |
|
|
| `lab-provision-bitwarden.sh` + `vw-register.py` | Vaultwarden + `bw` CLI |
|
|
| `lab-provision-browsercsv.sh` + `csv-commit-probe.py` | Chrome/Firefox CSV (staging only) |
|
|
| `lab-provision-browserrot.sh` | Phase A-tier-1 site-side rotation engine (`internal/browserrot`) — real headless Chromium against a throwaway local change-password form (fake cred) |
|
|
| `tui-probe.py` | drives the `guide` Bubble Tea TUI under a pty |
|
|
|
|
## Custody / smoke
|
|
|
|
- `lab-rung1-appsecret-host.sh` — **safe-candidate ladder rung 1**, the host dress
|
|
rehearsal: the first end-to-end run of the real `rotate --execute` spine on the host
|
|
toolchain (real gopass, backup gate, audit, seal flow) against a **throwaway scratch
|
|
app** (dummy `.env` + `config.yml`, fake secret). Walks dry-run → blast → execute →
|
|
asserts the in-place cutover (old gone, one new value in both files, stored blob
|
|
updated) → shows the old value is recoverable from the sealed backup. Isolated store,
|
|
zero real-cred risk. `appsecret` stays LIVE-VM — a real-cred rotation is what earns
|
|
LIVE-REAL. (ROADMAP M2 rung 1.)
|
|
- `lab-restore-drill.sh` — proves the sealed `.age` backup is a **real recovery path** on
|
|
the host against real gopass (isolated throwaway store, fake creds): seed → seal →
|
|
destroy every entry → `import` → assert byte-equal restoration + no plaintext in the
|
|
bundle. The safety net for no-op-`RevokeOld` drivers (e.g. `appsecret`), where the
|
|
backup is the only rollback. Prerequisite for the first real rotation (ROADMAP M2).
|
|
- `lab-store.sh` — throwaway key + gopass store + fake `.env`/`.aws`/consumer files.
|
|
- `lab-run.sh` — scan→status→migrate→export→import→`rotate --dry-run --blast`→worklist.
|
|
- `lab-harness.sh`, `incredigo-lab-setup.sh` — older combined harness variants.
|
|
|
|
## Notes carried over
|
|
|
|
- Ubuntu apt `gopass` is the **wrong tool** (a `pass` clone). Install gopasspw/gopass.
|
|
- Multipass snap **cannot read `/tmp`** — stage under `$HOME` before `multipass transfer`.
|
|
- `rotate --prefix` must be the `imported/` **root** (source = first path segment after it).
|
|
- Headless runs need `INCREDIGO_PASSPHRASE` (seal/backup passphrase, separate from GPG).
|