feat(werkbank): runner queue endpoints + result persistence (WB-05)
CI / Check (pull_request) Successful in 5m35s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
CI / Check (pull_request) Successful in 5m35s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
The control-plane side of the pull API (implements sharang/werkbank#6), so a Werkbank runner can reach a real queue end-to-end: - POST /api/v1/werkbank/jobs/{lease,heartbeat,complete} — thin handlers over the JobQueue (WB-02), tenant-scoped from the request's `tenant` (db_pool .for_tenant_id). lease→204 when empty; heartbeat→409 on a lost lease. - Machine auth: a static WERKBANK_RUNNER_TOKEN bearer (require_runner_token), mounted only when the token is set — like the admin API, and NOT a Keycloak JWT (a runner acts across tenants). /api/v1/werkbank/* is added to the JWT PUBLIC_PREFIXES so it routes to the runner-token gate, not the customer-JWT one. - On completion, the runner's findings + DAST findings are persisted against the job's target (dedup'd by fingerprint), so a job run by a remote runner lands the same findings an in-process run would. - Shared transport types (LeaseRequest/HeartbeatRequest/CompleteRequest/ CompleteResponse) live in compliance-core so the runner (client) and control plane (server) agree on shapes. Tests: 3 HTTP integration tests against a live Mongo (lease→complete→persist, empty-queue 204, and the bearer-token gate) + a token-compare unit test. Skips cleanly with no Mongo. clippy + fmt clean. Follow-up: wiring the scan pipeline to enqueue plc-provision jobs needs an artifact-fetch path for the runner (so it can pull the program blob); tracked with the on-prem work. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
633f945a1e
commit
420af3af9e
@@ -64,11 +64,11 @@ struct Claims {
|
||||
const PUBLIC_ENDPOINTS: &[&str] = &["/api/v1/health"];
|
||||
|
||||
/// Path prefixes that bypass JWT validation. The admin sub-router
|
||||
/// (`/api/v1/admin/*`) has its own static-bearer middleware and must
|
||||
/// not be routed through the customer-JWT path — a Keycloak token
|
||||
/// always carries a single tenant_id and would semantically conflict
|
||||
/// with cross-tenant admin operations.
|
||||
const PUBLIC_PREFIXES: &[&str] = &["/api/v1/admin/"];
|
||||
/// (`/api/v1/admin/*`) and the Werkbank runner API (`/api/v1/werkbank/*`)
|
||||
/// have their own static-bearer middleware and must not be routed through the
|
||||
/// customer-JWT path — a Keycloak token always carries a single tenant_id and
|
||||
/// would semantically conflict with these cross-tenant / machine operations.
|
||||
const PUBLIC_PREFIXES: &[&str] = &["/api/v1/admin/", "/api/v1/werkbank/"];
|
||||
|
||||
/// Middleware that validates Bearer JWT tokens against Keycloak's JWKS
|
||||
/// and attaches a `TenantContext` extension on success.
|
||||
|
||||
@@ -53,6 +53,11 @@ pub struct AgentConfig {
|
||||
/// default: it needs Docker access in the agent's runtime, which is a
|
||||
/// deployment opt-in.
|
||||
pub plc_runtime: PlcRuntimeConfig,
|
||||
/// Static bearer for the Werkbank runner endpoints
|
||||
/// (`/api/v1/werkbank/jobs/*`). Machine auth for runners leasing/completing
|
||||
/// jobs — NOT a Keycloak JWT, since a runner acts across tenants. When
|
||||
/// `None`, those endpoints are not mounted at all.
|
||||
pub werkbank_runner_token: Option<SecretString>,
|
||||
}
|
||||
|
||||
/// Configuration for the ephemeral soft-PLC "provision-and-test" path (#183).
|
||||
|
||||
@@ -49,6 +49,7 @@ pub use repository::ScanTrigger;
|
||||
pub use sbom::{SbomEntry, VulnRef};
|
||||
pub use scan::{ScanPhase, ScanRun, ScanRunStatus, ScanType};
|
||||
pub use werkbank::{
|
||||
DastCollect, Executor, HeartbeatAck, InputRef, Job, JobCollect, JobRecord, JobResult,
|
||||
JobRuntime, JobStatus, JobType, LeasedJob,
|
||||
CompleteRequest, CompleteResponse, DastCollect, Executor, HeartbeatAck, HeartbeatRequest,
|
||||
InputRef, Job, JobCollect, JobRecord, JobResult, JobRuntime, JobStatus, JobType, LeaseRequest,
|
||||
LeasedJob,
|
||||
};
|
||||
|
||||
@@ -349,6 +349,59 @@ pub struct HeartbeatAck {
|
||||
pub cancelled: bool,
|
||||
}
|
||||
|
||||
// --- Runner ↔ control-plane transport (the pull API wire types) ---------------
|
||||
// Shared so the runner (client) and the control plane (server) agree on shapes.
|
||||
|
||||
/// Runner → control plane: lease the oldest runnable job for this runner.
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
pub struct LeaseRequest {
|
||||
/// The tenant queue to lease from.
|
||||
pub tenant: String,
|
||||
/// The runner id (advertised for attribution).
|
||||
pub runner_id: String,
|
||||
/// The executor this runner provides.
|
||||
pub executor: Executor,
|
||||
/// The capability labels this runner advertises.
|
||||
#[serde(default)]
|
||||
pub labels: Vec<String>,
|
||||
/// Requested lease lifetime (the visibility timeout), in seconds.
|
||||
pub lease_ttl_secs: u64,
|
||||
}
|
||||
|
||||
/// Runner → control plane: prove lease ownership and extend it.
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
pub struct HeartbeatRequest {
|
||||
/// The tenant queue.
|
||||
pub tenant: String,
|
||||
/// The job being worked.
|
||||
pub job_id: String,
|
||||
/// The lease token from the [`LeasedJob`].
|
||||
pub lease_token: String,
|
||||
/// Lease lifetime to extend to, in seconds.
|
||||
pub lease_ttl_secs: u64,
|
||||
}
|
||||
|
||||
/// Runner → control plane: record a job's terminal result.
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
pub struct CompleteRequest {
|
||||
/// The tenant queue.
|
||||
pub tenant: String,
|
||||
/// The job being completed.
|
||||
pub job_id: String,
|
||||
/// The lease token proving ownership.
|
||||
pub lease_token: String,
|
||||
/// The result to record.
|
||||
pub result: JobResult,
|
||||
}
|
||||
|
||||
/// Control plane → runner: whether the completion was recorded (false if the
|
||||
/// lease was already lost — token mismatch or the job had become terminal).
|
||||
#[derive(Debug, Clone, Copy, Serialize, Deserialize)]
|
||||
pub struct CompleteResponse {
|
||||
/// Whether the result was recorded.
|
||||
pub recorded: bool,
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
#[allow(clippy::expect_used, clippy::unwrap_used)]
|
||||
mod tests {
|
||||
|
||||
Reference in New Issue
Block a user