Public pass: HOME in the image, drop the pre-release framing, add the repo furniture - #10
Merged
Merged
Conversation
Two things, both surfaced by the first production deployment. HOME is load-bearing and the image never set it. The daemon passes HOME straight through to `p4`, which reads $HOME/.p4trust and $HOME/.p4tickets. With HOME empty, p4 never finds the trust file and every p4.* verb fails against an SSL-enabled p4d with `exit status 1`, even when the mount is correct. The first studio deployment hit this and worked around it with a compose-level `HOME:` env var; that belongs in the image, so nobody else has to rediscover it. Set on both the runtime and uat stages, so moving between them still changes only the digest. The docs still described a day-1 spike against a mock broker. The Perforce path now runs in production: a real changelist travelled from a studio's own Helix Core, through the connector, over one outbound TLS connection to the broker, and was recorded on a ButterStack project. So: - README drops "Status: pre-release" and the link to a tracking issue in a private repo (a 404 for every public reader), and says what is actually proven. - PROTOCOL.md is v0, the protocol the shipped connector speaks, not a schema waiting for a server half. The server half exists. - design-notes.md's "What the spike does not prove" becomes "What is not yet proven", with the items production closed out moved into a "proven since" note and the honest remainder kept: the drills have no production-side result, TeamCity is off until a connector-scoped credential exists, home-connection latency, Sigstore signing and egress.md, scale and multi-node routing, and the uncompiled verbs.
The repo had a LICENSE and nothing else. Every sibling public repo (butterstack-cli, butterstack-mcp, gamedev-agents, perforce-docker) carries CONTRIBUTING.md and issue templates, and the two that handle credentials carry SECURITY.md. This one handles credentials more directly than any of them and had no disclosure path at all, so a reporter's only option was a public issue. SECURITY.md is written around the daemon's four standing claims (outbound only, the allowlist is the boundary, credentials stay local, the broker cannot reconfigure the connector), so a reporter can tell whether what they found is in scope. It also says what is not a security issue, since a reserved verb returning a denial and a hard startup failure on a bad config are both working as designed and both look alarming from the outside. CONTRIBUTING.md leads with the constraint that actually governs changes here: the vocabulary is the security boundary, argument constraints are schema, and a denial path with no drill is an untested security claim. The bug template asks for the connector log and a redacted connector.yml, and warns before the paste rather than after. Two accuracy fixes found while writing these: - README asked for Go 1.25 to build from source; the module's own `go` directive is 1.23. Release builds do use 1.25, so both numbers are now stated for what each one is. - `make check` already runs both test and drills, so telling contributors to run them separately was wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A public pass on the repo now that the Perforce path runs in production. Two commits: one code fix and the docs that were still describing a spike, then the repo furniture the repo never had.
1.
HOMEis load-bearing and the image never set itThe daemon passes
HOMEstraight through top4(internal/tools/perforce.go,env()), andp4reads$HOME/.p4trustand$HOME/.p4tickets. The image setsWORKDIR /home/connectorbut noENV HOME, sop4receives an emptyHOME, never consults the trust file, and everyp4.*verb fails against an SSL-enabled p4d withperforce: exit status 1, even when the trust file is mounted correctly.The first studio deployment hit exactly this and worked around it with a compose-level
HOME:env var. That belongs in the image so nobody else has to rediscover it. Set on both theruntimeanduatstages, so moving a deployment between the two still changes only the digest.Verified on a local build of the
runtimetarget:docker image inspectnow reportsHOME=/home/connectoralongsidePATHandSSL_CERT_FILE, user still10001:10001.2. The docs still described a day-1 spike
The Perforce path now runs in production: a real changelist travelled from a studio's own Helix Core server, through the connector on the studio's box, over one outbound TLS connection to the broker, and was recorded on a ButterStack project. The docs had not caught up.
Status: pre-releaseand the link to a tracking issue in a private repo (a 404 for every public reader), and says what is actually proven instead.v0, the protocol the shipped connector speaks, rather than a schema waiting for a server half. The "does not describe an endpoint that exists" paragraph is gone, because the endpoint exists. The tenant-context drill pointer now points at design-notes instead of a README section that moved.egress.md, scale and multi-node routing, and everything beyond the five compiled verbs.3. Repo furniture
The repo had a LICENSE and nothing else. Every sibling public repo carries CONTRIBUTING.md and issue templates, and the two that handle credentials carry SECURITY.md. This one handles credentials more directly than any of them and had no private disclosure path at all, so a reporter's only option was a public issue.
config.ymlthat routes security reports to SECURITY.md before someone files one publicly. The bug template asks for the connector log and a redactedconnector.yml, and warns before the paste rather than after.Two accuracy fixes found while writing those:
godirective is 1.23. Release builds do use 1.25, so both numbers are now stated for what each one is.make checkalready runstestanddrills, so telling contributors to run them separately was wrong.Done outside this PR (repo settings, no diff)
ghcr.io/butterstack/butterstack-connector:v0.2.0pulls anonymously (HTTP 200 on the manifest with an anonymous ghcr token), so the README's install instructions work for a stranger.After merge
Releases here are tag-driven (
on: push: tags: ["v*"]); merging tomainpublishes nothing. Tagv0.2.1so the published image carries theHOMEfix, then bump thedocker runexample in the README to that tag.No Go code changed;
go build ./...is green and the runtime image builds.