mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-25 14:53:34 +00:00
* fix(deploy): harden production container and bootstrap security - Replace --network=host with explicit port mapping (-p 3000:3000) to restore Docker network isolation. The prior config gave the container full access to the host network namespace including the Cloud SQL Auth Proxy on localhost:5432. (CWE-668) - Support pinned image versions via IRONCLAW_VERSION env var instead of always pulling :latest. Mutable tags allow uncontrolled deployments if the registry is compromised or a broken image is pushed. Falls back to :latest when unset for backwards compatibility. (CWE-829) - Add SHA256 checksum verification after downloading the Cloud SQL Auth Proxy binary. The prior script executed an unverified binary downloaded over the network with direct access to the production database. (CWE-494) Co-Authored-By: Claude Opus 4.6 <[email protected]> * chore(ci): rerun regression gate [skip-regression-check] --------- Co-authored-by: Rafael Martinez <[email protected]> Co-authored-by: Claude Opus 4.6 <[email protected]>
76 lines
2.4 KiB
Bash
Executable File
76 lines
2.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# VM bootstrap script for IronClaw on GCP Compute Engine.
|
|
#
|
|
# Run on a fresh Debian 12 VM after SSH:
|
|
# sudo bash setup.sh
|
|
#
|
|
# Prerequisites:
|
|
# - VM has the ironclaw-vm service account attached
|
|
# - Cloud SQL Auth Proxy accessible via IAM
|
|
# - Artifact Registry image pushed
|
|
|
|
set -euo pipefail
|
|
|
|
# Must run as root
|
|
if [ "$(id -u)" -ne 0 ]; then
|
|
echo "ERROR: This script must be run as root (sudo bash setup.sh)"
|
|
exit 1
|
|
fi
|
|
|
|
echo "==> Installing Docker"
|
|
apt-get update
|
|
apt-get install -y docker.io
|
|
systemctl enable docker
|
|
systemctl start docker
|
|
|
|
echo "==> Installing Cloud SQL Auth Proxy"
|
|
CLOUD_SQL_PROXY_VERSION="v2.14.3"
|
|
CLOUD_SQL_PROXY_SHA256="75e7cc1f158ab6f97b7810e9d8419c55735cff40bc56d4f19673adfdf2406a59"
|
|
curl -fsSL -o /usr/local/bin/cloud-sql-proxy \
|
|
"https://storage.googleapis.com/cloud-sql-connectors/cloud-sql-proxy/${CLOUD_SQL_PROXY_VERSION}/cloud-sql-proxy.linux.amd64"
|
|
echo "${CLOUD_SQL_PROXY_SHA256} /usr/local/bin/cloud-sql-proxy" | sha256sum -c - || {
|
|
echo "ERROR: Cloud SQL Auth Proxy checksum verification failed -- aborting"
|
|
rm -f /usr/local/bin/cloud-sql-proxy
|
|
exit 1
|
|
}
|
|
chmod +x /usr/local/bin/cloud-sql-proxy
|
|
|
|
echo "==> Installing systemd services"
|
|
cp /tmp/deploy/cloud-sql-proxy.service /etc/systemd/system/
|
|
cp /tmp/deploy/ironclaw.service /etc/systemd/system/
|
|
systemctl daemon-reload
|
|
|
|
echo "==> Starting Cloud SQL Auth Proxy"
|
|
systemctl enable cloud-sql-proxy
|
|
systemctl start cloud-sql-proxy
|
|
|
|
echo "==> Configuring Docker registry auth"
|
|
# The VM service account provides Artifact Registry access
|
|
gcloud auth configure-docker us-central1-docker.pkg.dev --quiet
|
|
|
|
echo "==> Creating config directory"
|
|
# Owned by root, readable only by root. Docker reads --env-file as root
|
|
# before dropping to uid 1000 (ironclaw) inside the container.
|
|
mkdir -p /opt/ironclaw
|
|
chmod 700 /opt/ironclaw
|
|
|
|
if [ ! -f /opt/ironclaw/.env ]; then
|
|
echo "WARNING: /opt/ironclaw/.env does not exist."
|
|
echo "Create it with your configuration before starting IronClaw."
|
|
echo "See deploy/env.example for the required variables."
|
|
echo ""
|
|
echo "Then run: systemctl enable ironclaw && systemctl start ironclaw"
|
|
else
|
|
chmod 600 /opt/ironclaw/.env
|
|
echo "==> Starting IronClaw"
|
|
systemctl enable ironclaw
|
|
systemctl start ironclaw
|
|
fi
|
|
|
|
echo "==> Setup complete"
|
|
echo ""
|
|
echo "Verify with:"
|
|
echo " systemctl status cloud-sql-proxy"
|
|
echo " systemctl status ironclaw"
|
|
echo " docker logs ironclaw"
|