Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/cloud-deploy-relay-staging.yml
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,8 @@ jobs:
IMAGE_NAME: relay
EXPECTED_IMAGE_DIGEST: ${{ inputs.expected-image-digest }}
CAPACITY_SERVICE_ACCOUNT: ${{ vars.STAGING_GCP_RELAY_CAPACITY_SERVICE_ACCOUNT }}
# The director must trust the identity every staging Relay workflow authenticates as.
DEPLOY_SERVICE_ACCOUNT: ${{ vars.STAGING_GCP_RELAY_DEPLOY_SERVICE_ACCOUNT }}
ASIA_PROOF_SERVICE_ACCOUNT: ${{ vars.STAGING_GCP_RELAY_ASIA_PROOF_SERVICE_ACCOUNT }}
REGIONAL_PLACEMENT_SECRET: orca-cloud-relay-regional-placement-enabled
DIRECTOR_RUNTIME_SERVICE_ACCOUNT: orca-cloud-staging-relay-dir@onorca-cloud-staging.iam.gserviceaccount.com
Expand Down Expand Up @@ -199,6 +201,7 @@ jobs:
--role director \
--max-instances 2 \
--capacity-service-account "${CAPACITY_SERVICE_ACCOUNT}" \
--deploy-service-account "${DEPLOY_SERVICE_ACCOUNT}" \
--asia-proof-service-account "${ASIA_PROOF_SERVICE_ACCOUNT}" \
--regional-placement-secret-version "${regional_version}" \
"${floor_args[@]}" \
Expand Down
6 changes: 6 additions & 0 deletions cloud/dev/scripts/deploy-relay-blue-green.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -263,6 +263,7 @@ export function directorDeploymentEnvironment(config) {
}
const serviceAccount = projectServiceAccount(config, 'capacity-service-account')
const asiaProofServiceAccount = projectServiceAccount(config, 'asia-proof-service-account')
const deployServiceAccount = projectServiceAccount(config, 'deploy-service-account')
const rehomeDirectorServiceAccount = projectServiceAccount(
config,
'rehome-director-service-account'
Expand All @@ -274,6 +275,10 @@ export function directorDeploymentEnvironment(config) {
if (asiaProofServiceAccount !== undefined) {
environment.ORCA_RELAY_ASIA_PROOF_SERVICE_ACCOUNT = asiaProofServiceAccount
}
// The admin identity the director trusts; omitted, the serving revision's value carries over.
if (deployServiceAccount !== undefined) {
environment.ORCA_RELAY_DEPLOY_SERVICE_ACCOUNT = deployServiceAccount
}
if (rehomeDirectorServiceAccount !== undefined) {
environment[DIRECTOR_REHOME_IDENTITY_ENV] = rehomeDirectorServiceAccount
environment[DIRECTOR_REHOME_AUDIENCE_ENV] = config['rehome-audience']
Expand Down Expand Up @@ -330,6 +335,7 @@ export function parseArguments(argv) {
}
if (
values['capacity-service-account'] !== undefined ||
values['deploy-service-account'] !== undefined ||
values['director-cells-json'] !== undefined ||
values['runtime-service-account'] !== undefined ||
values['rehome-director-service-account'] !== undefined ||
Expand Down
24 changes: 24 additions & 0 deletions cloud/dev/scripts/deploy-relay-blue-green.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -1023,6 +1023,30 @@ test('reads a director placement from runtime-status, and reports an image witho
}
})

// Why: staging drifted to a director that trusts gha-deploy while every staging workflow
// authenticates as gha-relay; the deploy, not Terraform, owns the live value.
test('a director deploy sets the trusted deploy identity only when asked', () => {
const config = { project: 'onorca-cloud-staging' }
const relay = 'orca-cloud-staging-gha-relay@onorca-cloud-staging.iam.gserviceaccount.com'
assert.equal(
directorDeploymentEnvironment({ ...config, 'deploy-service-account': relay })
.ORCA_RELAY_DEPLOY_SERVICE_ACCOUNT,
relay
)
assert.equal(
'ORCA_RELAY_DEPLOY_SERVICE_ACCOUNT' in directorDeploymentEnvironment(config),
false
)
assert.throws(
() =>
directorDeploymentEnvironment({
...config,
'deploy-service-account': 'foreign@other-project.iam.gserviceaccount.com'
}),
/selected project/
)
})

// Staging's director trusted gha-deploy while the workflow authenticated as gha-relay: a bare 401.
test('the guard names the deploy identity a drifted director trusts instead of reading into a 401', async () => {
const servingImageDigest = `sha256:${'f'.repeat(64)}`
Expand Down
1 change: 1 addition & 0 deletions cloud/dev/scripts/relay-staging-deploy-identity.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -232,4 +232,5 @@ test('the staging director deploy runs as relay-dir with its rehome identity', (
assert.match(block, /--runtime-service-account "\$\{DIRECTOR_RUNTIME_SERVICE_ACCOUNT\}"/)
assert.match(block, /--rehome-director-service-account "\$\{DIRECTOR_RUNTIME_SERVICE_ACCOUNT\}"/)
assert.match(source, /DIRECTOR_RUNTIME_SERVICE_ACCOUNT: orca-cloud-staging-relay-dir@/)
assert.match(block, /--deploy-service-account "\$\{DEPLOY_SERVICE_ACCOUNT\}"/)
})
Loading