Repository navigation
Change in git_config results in inability to use combined ca certs #476
Description
Activity
The change results in different behaviour depending on if you're looking at a native git resource in concourse or a custom script.
Could a variable please be created for opting out and using the original behaviour where custom script/container can use the default store for ca certs?
Could you explain this a bit more please? Why do you mean by "or a custom script"? What custom script? Are you pulling in the code from this repo into something else that isn't a Concourse resource?
This part too in "Expected behavior":
Concourse can also run scripts with custom images for various distros and use the system ca-cert store. not necessarily inheriting from the original resource
Concourse can run scripts with custom images (??) using
tasksteps (??).Just looking for more clarification because I'm unsure how this broke things for you. An example pipeline, even if it's just psuedo-code, would be helpful to illustrate the problem you're having. TY!
Apologies for being so vague. Here's a little more
We have a git-resource configured in a Concourse pipeline. We are Enterprise so have proxy and private repos. As such we need to provide ca certs and creds.
- name: thingy type: git check_every: 30s source: uri: https://github.com/im_a_lovely_repo ignore_paths: - stuff branch: master disable_ci_skip: true git_config: - name: http.sslCAInfo value: /etc/ssl/certs/worker-additional-certs.pem"We can see
/etc/ssl/certs/worker-additional-certs.pemin our workers and the git-resource is able to use this git_config. This is what the/etc/ssl/certslooks like from the perspective of a hijacked git-resource.bash-5.3# ls -lah /etc/ssl/certs total 772K drwxr-xr-x. 2 root root 4.0K Jun 26 08:46 . drwxr-xr-x. 3 root root 4.0K Jun 26 08:46 .. -rw-r--r--. 1 root root xxK Jun 26 08:46 ca-bundle.crt -rw-r--r--. 1 root root xxK Jun 26 08:46 ca-certificates.crt -rw-r--r--. 1 root root xxK Jun 26 08:46 worker-additional-certs.pemIt looks the same if you shell into any of the workers as root.
We have a job with a task which uses an ubuntu 22.04.5 based image with our own tooling deployed.
Part of the script which runs cds into the repo and does some git commands. These fail because the container cannot see
/etc/ssl/certs/worker-additional-certs.pemTo us, it looks like git-resources can be grabbed as they have access to
/etc/ssl/certs/worker-additional-certs.pemBut as soon as our container starts, that certificate does not exist anymore and instead the
/etc/ssl/certs/worker-additional-certs.pemfile has been injected intoca-certificates.crtand split out into individual separate cert files. If you have no git_config set, the resource is able to use the default store which now includes these certs. If it inherits from the parent git-resource, it cannot find the specific file so fails.I've set an env var of GIT_SSL_CAINFO: /etc/ssl/certs/ca-certificates.crt on the task and that make it possible to do git commands. so using a git override to override the inherited "more consistent config" with the certs that are available.
I've got a workaround so I'm happy to close but it's not very elegant.
AH okay, I understand how that PR broke things for you now.
I'm not sure how to reconcile this with the issue originally raised in #369 which is what the PR resolved. That issue is basically asking for the reverse of what you're asking for here (kind of).
Only thought that comes to mind is to add another config option that disables persisting the git config in the resource's output.
I'm fine leaving this open and am open to a PR to resolve this scenario or other ideas folks have.
Describe the bug
#457
The change results in different behaviour depending on if you're looking at a native git resource in concourse or a custom script.
Could a variable please be created for opting out and using the original behaviour where custom script/container can use the default store for ca certs?
Reproduction steps
...
Expected behavior
Concourse can clone repos nicely using specific ca certs
Concourse can also run scripts with custom images for various distros and use the system ca-cert store. not necessarily inheriting from the original resource
Additional context
No response