mirror of
https://github.com/whyour/qinglong.git
synced 2026-09-20 16:07:11 +08:00
feat(ql3): add optional console run drilldown
This commit is contained in:
@@ -425,7 +425,7 @@ const { statSync, writeFileSync } = require('node:fs');
|
||||
const { rootCertificates } = require('node:tls');
|
||||
const facade = '/opt/qinglong/node_modules/@qinglong/cluster-admin/dist/product-cli/cli.js';
|
||||
const share = '/opt/qinglong/share/ql3-copilot-console';
|
||||
for (const [file, mode] of [['docker-loopback.sh', 0o555], ['verify-release.sh', 0o555], ['README.md', 0o444], ['client-config.example.json', 0o444], ['host-environment.example.json', 0o444]]) {
|
||||
for (const [file, mode] of [['docker-loopback.sh', 0o555], ['verify-release.sh', 0o555], ['README.md', 0o444], ['client-config.example.json', 0o444], ['run-management-client-config.example.json', 0o444], ['host-environment.example.json', 0o444]]) {
|
||||
if ((statSync(share + '/' + file).mode & 0o777) !== mode) process.exit(51);
|
||||
}
|
||||
writeFileSync('/tmp/ca.pem', rootCertificates[0], { mode: 0o600 });
|
||||
|
||||
@@ -14,6 +14,7 @@ const REQUIRED_FILES = Object.freeze([
|
||||
CONSOLE_ROOT + '/evidenceVerifier.ts',
|
||||
CONSOLE_ROOT + '/evidenceVerifierCli.ts',
|
||||
CONSOLE_ROOT + '/server.ts',
|
||||
'packages/ql3-cluster-admin/src/run-management/runCancellationInspection.ts',
|
||||
CLIENT_FILE,
|
||||
ASSET_ROOT + '/index.html',
|
||||
ASSET_ROOT + '/app.css',
|
||||
@@ -21,6 +22,7 @@ const REQUIRED_FILES = Object.freeze([
|
||||
ASSET_ROOT + '/app.js',
|
||||
DEPLOYMENT_ROOT + '/README.md',
|
||||
DEPLOYMENT_ROOT + '/client-config.example.json',
|
||||
DEPLOYMENT_ROOT + '/run-management-client-config.example.json',
|
||||
'deploy/containers/ql3-cluster-admin/Dockerfile',
|
||||
'scripts/ql3-cluster-admin-product-live-contract.cjs',
|
||||
]);
|
||||
@@ -103,6 +105,9 @@ function auditClusterCopilotConsole(options = {}) {
|
||||
'clusterCopilotConsoleClientCommand',
|
||||
'clusterCopilotConsoleProjectReadPath',
|
||||
"'run_event_list'",
|
||||
"'run_cancellation_status'",
|
||||
"'run_cancellation_blocked_list'",
|
||||
"'run_cancellation_inspect'",
|
||||
"'task_read'",
|
||||
"'workflow_step_list'",
|
||||
]);
|
||||
@@ -130,6 +135,7 @@ function auditClusterCopilotConsole(options = {}) {
|
||||
"request.headers.host !== expectedOrigin.slice('http://'.length)",
|
||||
'maximumConcurrentRequests: 2',
|
||||
"'/api/v1/copilot/inspect': 'inspect'",
|
||||
"'/api/v1/run-management/cancellation-status': 'run_cancellation_status'",
|
||||
"'/api/v1/observe/run-list': 'run_list'",
|
||||
"'/api/v1/observe/task-list': 'task_list'",
|
||||
"'/api/v1/observe/workflow-list': 'workflow_list'",
|
||||
@@ -144,27 +150,29 @@ function auditClusterCopilotConsole(options = {}) {
|
||||
'WebSocket',
|
||||
'set-cookie',
|
||||
'diagnose',
|
||||
'cancel',
|
||||
'run.cancellation.rearm',
|
||||
'child_process',
|
||||
'node:fs',
|
||||
'node:net',
|
||||
]);
|
||||
expectFragments(CONSOLE_ROOT + '/cli.ts', [
|
||||
'--session /absolute/session',
|
||||
'--run-management-config /absolute/run-client.json',
|
||||
'--run-management-assertion /absolute/assertion.jwt',
|
||||
'readCanonicalFile(',
|
||||
"'private'",
|
||||
'validateClusterCopilotClientCredentialFile',
|
||||
"clusterCredential: 'server_only'",
|
||||
'networkBoundary: parsed.networkBoundary',
|
||||
"publishedHostAddress: '127.0.0.1'",
|
||||
'operations: CLUSTER_COPILOT_CONSOLE_READ_OPERATIONS',
|
||||
'runManagementAuthority: runManagementAuthority',
|
||||
'mutation: false',
|
||||
]);
|
||||
rejectFragments(CONSOLE_ROOT + '/cli.ts', [
|
||||
'process.env',
|
||||
'0.0.0.0',
|
||||
'diagnose',
|
||||
'cancel',
|
||||
"operation: 'run.cancellation.rearm'",
|
||||
]);
|
||||
expectFragments(CONSOLE_ROOT + '/evidenceVerifier.ts', [
|
||||
'qinglong/cluster-console-evidence-verification@v1',
|
||||
@@ -214,6 +222,9 @@ function auditClusterCopilotConsole(options = {}) {
|
||||
'读取 Run 列表',
|
||||
'读取 Workflow Runs',
|
||||
'显式读取诊断内容',
|
||||
'读取取消可用性',
|
||||
'读取首屏 Blocked Runs',
|
||||
'该只读面没有 rearm',
|
||||
'模型文本是不可信内容',
|
||||
'导出脱敏包',
|
||||
'/evidence-bundle.js',
|
||||
@@ -237,7 +248,7 @@ function auditClusterCopilotConsole(options = {}) {
|
||||
'WebSocket',
|
||||
'EventSource',
|
||||
'diagnose',
|
||||
'cancel',
|
||||
'run.cancellation.rearm',
|
||||
'http://',
|
||||
'https://',
|
||||
'navigator.',
|
||||
@@ -280,6 +291,8 @@ function auditClusterCopilotConsole(options = {}) {
|
||||
'Do not deploy it as a Kubernetes workload',
|
||||
'Run, Task, Workflow',
|
||||
'thirteen exact operations',
|
||||
'available vocabulary to sixteen',
|
||||
'QL3_COPILOT_CONSOLE_RUN_MANAGEMENT=enabled',
|
||||
'--port=0',
|
||||
'TLS 1.3 `GET /readyz`',
|
||||
'excluded from small router Edge/Standalone artifacts',
|
||||
@@ -423,6 +436,9 @@ function auditClusterCopilotConsole(options = {}) {
|
||||
operations: Object.freeze([
|
||||
'inspect',
|
||||
'output',
|
||||
'run_cancellation_status',
|
||||
'run_cancellation_blocked_list',
|
||||
'run_cancellation_inspect',
|
||||
'run_list',
|
||||
'run_read',
|
||||
'run_event_list',
|
||||
@@ -456,7 +472,7 @@ function auditClusterCopilotConsole(options = {}) {
|
||||
networkAccess: false,
|
||||
fileWrites: false,
|
||||
}),
|
||||
sourceFileCount: 6,
|
||||
sourceFileCount: 7,
|
||||
findings: Object.freeze(findings),
|
||||
compatible: findings.length === 0,
|
||||
});
|
||||
|
||||
@@ -11,6 +11,8 @@ const FILES = Object.freeze({
|
||||
'scripts/ql3-cluster-admin-release-workstation-ceremony-audit.cjs',
|
||||
environment:
|
||||
'deploy/console/ql3-cluster-copilot/host-environment.example.json',
|
||||
runManagementExample:
|
||||
'deploy/console/ql3-cluster-copilot/run-management-client-config.example.json',
|
||||
image: 'deploy/containers/ql3-cluster-admin/Dockerfile',
|
||||
workflow: '.github/workflows/ql3-image-release.yml',
|
||||
candidate: 'scripts/ql3-release-candidate-contract.cjs',
|
||||
@@ -82,6 +84,9 @@ function auditClusterCopilotConsoleDistribution(options = {}) {
|
||||
'memory=192m',
|
||||
'standard)',
|
||||
'memory=512m',
|
||||
'QL3_COPILOT_CONSOLE_RUN_MANAGEMENT-disabled',
|
||||
'--run-management-config /var/run/secrets/qinglong3/copilot-console/run-management-client.json',
|
||||
'--run-management-assertion /var/run/secrets/qinglong3/copilot-console/run-management-assertion.jwt',
|
||||
],
|
||||
'QL3_COPILOT_CONSOLE_LAUNCHER_CONTRACT_DRIFT',
|
||||
);
|
||||
@@ -200,6 +205,7 @@ function auditClusterCopilotConsoleDistribution(options = {}) {
|
||||
QL3_COPILOT_CONSOLE_NETWORK: 'qinglong3-copilot-console-egress',
|
||||
QL3_COPILOT_CONSOLE_PORT: '5701',
|
||||
QL3_COPILOT_CONSOLE_RESOURCE_CLASS: 'compact',
|
||||
QL3_COPILOT_CONSOLE_RUN_MANAGEMENT: 'disabled',
|
||||
};
|
||||
if (
|
||||
environment &&
|
||||
@@ -223,6 +229,8 @@ function auditClusterCopilotConsoleDistribution(options = {}) {
|
||||
'share/ql3-copilot-console/verify-release.sh',
|
||||
'COPY --chmod=0444 deploy/console/ql3-cluster-copilot/host-environment.example.json',
|
||||
'share/ql3-copilot-console/host-environment.example.json',
|
||||
'COPY --chmod=0444 deploy/console/ql3-cluster-copilot/run-management-client-config.example.json',
|
||||
'share/ql3-copilot-console/run-management-client-config.example.json',
|
||||
],
|
||||
'QL3_COPILOT_CONSOLE_IMAGE_DISTRIBUTION_DRIFT',
|
||||
);
|
||||
@@ -315,6 +323,7 @@ function auditClusterCopilotConsoleDistribution(options = {}) {
|
||||
hostPublication: '127.0.0.1',
|
||||
kubernetesResident: false,
|
||||
additionalWorkspacePackages: 0,
|
||||
runManagementAuthorityDefault: 'disabled',
|
||||
externalWorkstationCeremony: 'source-tag-private-report',
|
||||
ceremonyStatus: 'implementation-ready-public-release-pending',
|
||||
findings: Object.freeze(findings),
|
||||
|
||||
Reference in New Issue
Block a user