fix(run-api): authenticate every caller, and bound every harness run #45

Closed
ryangr0 wants to merge 1 commit from fix/sweep-hardening into development
Owner
No description provided.
fix(run-api): authenticate every caller, and bound every harness run
All checks were successful
On Pull Request / checks (pull_request) Successful in 1m18s
603c0f7b15
The claim endpoint authenticated nothing. Anything that could reach ploegd
could POST /api/v1/claim and be handed a live Run: its lease, its authorized
spending ceiling, the prior Rounds' findings, and -- for a writing Role -- a
forge push credential, which on a deployment with no forge admin token is the
shared org-wide PAT. The 48-hex run token in the path authorizes ONE run; it
never answered whether the caller is an executor at all. Those are two
questions and only one had a credential. ADR-0023 records the decision.

Every /api/v1 route now requires `Authorization: Bearer <token>`. ploegd
refuses to start when PLOEG_RUN_API_TOKEN is unset, so an operator cannot
arrive at "no auth" by omission; PLOEG_RUN_API_AUTH=off is the deliberate,
logged way out for the local compose demo and the bench, never for a cluster.

Also bounds every harness run with a prompt-timeout hard wall and an idle
timeout, spawn-and-wait included. Lease renewal runs on its own goroutine and
proves only that the WORKER is alive, so a wedged agent previously burned the
pod's whole activeDeadlineSeconds while holding its branch and its budget.

Operators must create the ploeg-run-api-secret Secret before upgrading: a
chart upgrade without it leaves ploegd in CrashLoopBackOff by design.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Author
Owner

Closing: most of this is in Glide or replaced (worker auth with per-run capabilities in pkg/httpapi/worker_auth.go; the harness watchdog in 76494d1). The two remaining fixes were ported: 0dc8c1a (only a minted forge token in a claim response) and 9ee3ce4 (record why a Run that opened a PR then failed). Metered-spend gating for legacy mode was not ported. Ploeg now lives in https://forgejo.webgrip.dev/webgrip/glide under apps/ploeg; this repository is being frozen.

Closing: most of this is in Glide or replaced (worker auth with per-run capabilities in pkg/httpapi/worker_auth.go; the harness watchdog in 76494d1). The two remaining fixes were ported: 0dc8c1a (only a minted forge token in a claim response) and 9ee3ce4 (record why a Run that opened a PR then failed). Metered-spend gating for legacy mode was not ported. Ploeg now lives in https://forgejo.webgrip.dev/webgrip/glide under apps/ploeg; this repository is being frozen.
ryangr0 closed this pull request 2026-09-23 12:06:43 +00:00
Commenting is not possible because the repository is archived.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/ploeg!45
No description provided.