diff --git a/.github/workflows/cloud-deploy-relay-staging.yml b/.github/workflows/cloud-deploy-relay-staging.yml index 4e74c835100..93ef7acd264 100644 --- a/.github/workflows/cloud-deploy-relay-staging.yml +++ b/.github/workflows/cloud-deploy-relay-staging.yml @@ -74,6 +74,8 @@ jobs: IMAGE_NAME: relay EXPECTED_IMAGE_DIGEST: ${{ inputs.expected-image-digest }} CAPACITY_SERVICE_ACCOUNT: ${{ vars.STAGING_GCP_RELAY_CAPACITY_SERVICE_ACCOUNT }} + # The director must trust the identity every staging Relay workflow authenticates as. + DEPLOY_SERVICE_ACCOUNT: ${{ vars.STAGING_GCP_RELAY_DEPLOY_SERVICE_ACCOUNT }} ASIA_PROOF_SERVICE_ACCOUNT: ${{ vars.STAGING_GCP_RELAY_ASIA_PROOF_SERVICE_ACCOUNT }} REGIONAL_PLACEMENT_SECRET: orca-cloud-relay-regional-placement-enabled DIRECTOR_RUNTIME_SERVICE_ACCOUNT: orca-cloud-staging-relay-dir@onorca-cloud-staging.iam.gserviceaccount.com @@ -199,6 +201,7 @@ jobs: --role director \ --max-instances 2 \ --capacity-service-account "${CAPACITY_SERVICE_ACCOUNT}" \ + --deploy-service-account "${DEPLOY_SERVICE_ACCOUNT}" \ --asia-proof-service-account "${ASIA_PROOF_SERVICE_ACCOUNT}" \ --regional-placement-secret-version "${regional_version}" \ "${floor_args[@]}" \ diff --git a/cloud/dev/scripts/deploy-relay-blue-green.mjs b/cloud/dev/scripts/deploy-relay-blue-green.mjs index 72bb6355986..d93b2617e86 100644 --- a/cloud/dev/scripts/deploy-relay-blue-green.mjs +++ b/cloud/dev/scripts/deploy-relay-blue-green.mjs @@ -263,6 +263,7 @@ export function directorDeploymentEnvironment(config) { } const serviceAccount = projectServiceAccount(config, 'capacity-service-account') const asiaProofServiceAccount = projectServiceAccount(config, 'asia-proof-service-account') + const deployServiceAccount = projectServiceAccount(config, 'deploy-service-account') const rehomeDirectorServiceAccount = projectServiceAccount( config, 'rehome-director-service-account' @@ -274,6 +275,10 @@ export function directorDeploymentEnvironment(config) { if (asiaProofServiceAccount !== undefined) { environment.ORCA_RELAY_ASIA_PROOF_SERVICE_ACCOUNT = asiaProofServiceAccount } + // The admin identity the director trusts; omitted, the serving revision's value carries over. + if (deployServiceAccount !== undefined) { + environment.ORCA_RELAY_DEPLOY_SERVICE_ACCOUNT = deployServiceAccount + } if (rehomeDirectorServiceAccount !== undefined) { environment[DIRECTOR_REHOME_IDENTITY_ENV] = rehomeDirectorServiceAccount environment[DIRECTOR_REHOME_AUDIENCE_ENV] = config['rehome-audience'] @@ -330,6 +335,7 @@ export function parseArguments(argv) { } if ( values['capacity-service-account'] !== undefined || + values['deploy-service-account'] !== undefined || values['director-cells-json'] !== undefined || values['runtime-service-account'] !== undefined || values['rehome-director-service-account'] !== undefined || diff --git a/cloud/dev/scripts/deploy-relay-blue-green.test.mjs b/cloud/dev/scripts/deploy-relay-blue-green.test.mjs index 782ace852c7..4ab531b58a7 100644 --- a/cloud/dev/scripts/deploy-relay-blue-green.test.mjs +++ b/cloud/dev/scripts/deploy-relay-blue-green.test.mjs @@ -1023,6 +1023,30 @@ test('reads a director placement from runtime-status, and reports an image witho } }) +// Why: staging drifted to a director that trusts gha-deploy while every staging workflow +// authenticates as gha-relay; the deploy, not Terraform, owns the live value. +test('a director deploy sets the trusted deploy identity only when asked', () => { + const config = { project: 'onorca-cloud-staging' } + const relay = 'orca-cloud-staging-gha-relay@onorca-cloud-staging.iam.gserviceaccount.com' + assert.equal( + directorDeploymentEnvironment({ ...config, 'deploy-service-account': relay }) + .ORCA_RELAY_DEPLOY_SERVICE_ACCOUNT, + relay + ) + assert.equal( + 'ORCA_RELAY_DEPLOY_SERVICE_ACCOUNT' in directorDeploymentEnvironment(config), + false + ) + assert.throws( + () => + directorDeploymentEnvironment({ + ...config, + 'deploy-service-account': 'foreign@other-project.iam.gserviceaccount.com' + }), + /selected project/ + ) +}) + // Staging's director trusted gha-deploy while the workflow authenticated as gha-relay: a bare 401. test('the guard names the deploy identity a drifted director trusts instead of reading into a 401', async () => { const servingImageDigest = `sha256:${'f'.repeat(64)}` diff --git a/cloud/dev/scripts/relay-staging-deploy-identity.test.mjs b/cloud/dev/scripts/relay-staging-deploy-identity.test.mjs index 8b7fb069915..dbb3f1d7a14 100644 --- a/cloud/dev/scripts/relay-staging-deploy-identity.test.mjs +++ b/cloud/dev/scripts/relay-staging-deploy-identity.test.mjs @@ -232,4 +232,5 @@ test('the staging director deploy runs as relay-dir with its rehome identity', ( assert.match(block, /--runtime-service-account "\$\{DIRECTOR_RUNTIME_SERVICE_ACCOUNT\}"/) assert.match(block, /--rehome-director-service-account "\$\{DIRECTOR_RUNTIME_SERVICE_ACCOUNT\}"/) assert.match(source, /DIRECTOR_RUNTIME_SERVICE_ACCOUNT: orca-cloud-staging-relay-dir@/) + assert.match(block, /--deploy-service-account "\$\{DEPLOY_SERVICE_ACCOUNT\}"/) })