BREAKING CHANGE: PASSWORD is gone and AUTH and CERTRESOLVER are required. The server's compose.yaml and .env must be updated in the same deploy — the new image ignores PASSWORD, and the old one refuses to start without it. Authelia now sits in front of Traefik, so the app was asking for a second password at the same door. Two prompts, and the weaker of the two was the one holding a single shared secret with no sessions, no MFA and no revocation. Deleting it is the whole change: Authelia already does this properly, once, for every service on the host. Gone: auth(), challenge(), the whole of throttle.go and its tests, and golang.org/x/time with them. routes() returns the bare mux, /healthz is an ordinary route on it, and the smoke script drops sixty -u flags. Roughly 230 lines removed and nothing written to replace them. What holds the app up now, both asserted in compose.yaml: - The router names the Authelia middleware through AUTH. Traefik takes a router out of service when its middleware does not resolve, so a typo or an unset variable fails shut rather than serving the app open. - The container still publishes no ports, so the proxy is the only thing that can reach it. Publishing 8080 would now bypass authentication outright, not merely TLS — the comment there says so. certresolver replaces the bare tls=true, parameterised as CERTRESOLVER: the server had been carrying that label by hand since the first deploy. Naming a resolver implies tls=true, so it stays one label. TestAuth and TestHealthzSkipsAuth are replaced by one test asserting every route answers without credentials — a 401 from here would now mean auth had crept back in.
This commit is contained in:
@@ -4,7 +4,7 @@ COMPOSE ?= podman compose
|
||||
BIN := foodster
|
||||
PKG := ./cmd/foodster
|
||||
|
||||
# Shared password and TZ live here. Gitignored.
|
||||
# Registry coordinates, hostname, TZ. Gitignored.
|
||||
ifneq (,$(wildcard .env))
|
||||
include .env
|
||||
export
|
||||
@@ -28,7 +28,7 @@ build: generate ## Build ./foodster
|
||||
-ldflags="-s -w -X main.version=dev" -o $(BIN) $(PKG)
|
||||
|
||||
run: generate ## Run locally on :8080 (database in ./data)
|
||||
PASSWORD=$${PASSWORD:-dev} ENV=dev go run $(PKG)
|
||||
ENV=dev go run $(PKG)
|
||||
|
||||
test: generate ## Run unit tests
|
||||
go test ./...
|
||||
|
||||
Reference in New Issue
Block a user