update
This commit is contained in:
@@ -63,7 +63,7 @@ def _bool(name: str, default: bool) -> bool:
|
||||
def get_settings() -> Settings:
|
||||
robot_package_base_url = os.getenv("ROBOT_PACKAGE_BASE_URL", "https://package.pnkr.cloud").rstrip("/")
|
||||
return Settings(
|
||||
agent_version=os.getenv("AGENT_VERSION", "1.0.3"),
|
||||
agent_version=os.getenv("AGENT_VERSION", "1.0.4"),
|
||||
host=os.getenv("AGENT_HOST", "0.0.0.0"),
|
||||
port=int(os.getenv("AGENT_PORT", "5010")),
|
||||
robot_package_base_url=robot_package_base_url,
|
||||
@@ -86,7 +86,7 @@ def get_settings() -> Settings:
|
||||
),
|
||||
allowed_apt_packages=_csv(
|
||||
os.getenv("ALLOWED_APT_PACKAGES"),
|
||||
["postgresql"],
|
||||
["*"],
|
||||
),
|
||||
allowed_docker_registries=_csv_with_defaults(
|
||||
os.getenv("ALLOWED_DOCKER_REGISTRIES"),
|
||||
|
||||
@@ -128,8 +128,8 @@ class AptInstaller(DebInstaller):
|
||||
def discover_service_units(self, package_name: str) -> list[str]:
|
||||
"""Return concrete systemd service units shipped by an installed package.
|
||||
|
||||
The package name is already constrained by the Agent APT allowlist. It is
|
||||
still passed as a single argv item and no shell expansion is performed.
|
||||
The package name is already syntax-validated by the manifest validator. It
|
||||
is passed as a single argv item and no shell expansion is performed.
|
||||
Template units are omitted because they cannot be meaningfully checked
|
||||
without an instance name.
|
||||
"""
|
||||
|
||||
@@ -18,7 +18,7 @@ class ManifestValidator:
|
||||
elif component_type == "apt":
|
||||
component = AptComponent.model_validate(raw_component).model_dump(by_alias=True)
|
||||
allowed_packages = set(settings.allowed_apt_packages)
|
||||
if component["packageName"] not in allowed_packages:
|
||||
if "*" not in allowed_packages and component["packageName"] not in allowed_packages:
|
||||
raise ValueError(
|
||||
f"APT package is not allowed: {component['packageName']}"
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user