diff --git a/STATUS.md b/STATUS.md index 3ff2322..5ccf10b 100644 --- a/STATUS.md +++ b/STATUS.md @@ -5,7 +5,7 @@ ## Current State -**Phase:** Bitwarden access operational. Container-based CLI (native Rust, no Node.js) deployed and verified. Agent identity provisioning unblocked on BW access — still needs Cloudron invite links and Gitea push credentials. +**Phase:** All four systems provisioned for vp-techops (Cloudron+2FA, Gitea, Discourse, Redmine) with verified API keys in Bitwarden. 9-agent manifest merged and READY. Session 3 will loop the remaining agents. **Primary task:** Redmine [#442](https://projects.knownelement.com/issues/442) — stand up first 3 AI agent identities (vp-techops, vp-secops, vp-techcompliance). @@ -15,10 +15,10 @@ stand up first 3 AI agent identities (vp-techops, vp-secops, vp-techcompliance). ### This session (TSGCOO) — BW Infrastructure - [x] **Bitwarden access operational** — container-based CLI using native Rust binary (no Node.js at any layer, CMMC/ITAR/STIG-friendly) - - `docker/bw-native/Dockerfile` — minimal debian-slim + bw v2026.7.0 - - `scripts/bw-cli.sh` — host wrapper (auth lifecycle handled internally) - - `scripts/bw-entrypoint.sh` — container entrypoint (config, login, unlock, sync) - - `scripts/bw-install.sh` — one-command installer + - Source files **moved to KNELCredsManager repo** (staged in + `~/knelcredsmanager-staging/` pending clone/push — org-buildout is docs-only). + Deployed artifacts unaffected: image `reachableceo-bw-native:2026.7.0`, + `~/.local/bin/bw` wrapper, `~/.local/share/bw/entrypoint.sh`. - All scripts pass shellcheck (zero warnings, including info-level) - Verified: `bw status` (unlocked, coo@turnsys.com @ pwvault.turnsys.com) - [x] **Fixed `~/.config/bw/env`:** single-quoted all values (master password diff --git a/docker/bw-native/.gitignore b/docker/bw-native/.gitignore deleted file mode 100644 index 182c76a..0000000 --- a/docker/bw-native/.gitignore +++ /dev/null @@ -1 +0,0 @@ -bw diff --git a/docker/bw-native/Dockerfile b/docker/bw-native/Dockerfile deleted file mode 100644 index e970084..0000000 --- a/docker/bw-native/Dockerfile +++ /dev/null @@ -1,23 +0,0 @@ -# Dockerfile — Native Bitwarden CLI (Rust binary, no Node.js) -# -# Builds a minimal container image around the pre-compiled native bw CLI -# binary from the official Bitwarden GitHub releases. The binary is a -# Rust executable with glibc dependencies. No Node.js runtime is -# included or required. -# -# Build prerequisites: -# 1. Download the native binary: -# https://github.com/bitwarden/clients/releases/download/cli-v2026.7.0/bw-linux-2026.7.0.zip -# 2. Unzip and place the `bw` executable next to this Dockerfile. -# 3. Build: docker build -t reachableceo-bw-native:2026.7.0 . -# -# Or use the installer: scripts/bw-install.sh - -FROM debian:bookworm-slim - -RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates && rm -rf /var/lib/apt/lists/* - -COPY bw /usr/local/bin/bw -RUN chmod +x /usr/local/bin/bw - -ENTRYPOINT ["bw"] diff --git a/scripts/bw-cli.sh b/scripts/bw-cli.sh deleted file mode 100755 index b13bbe3..0000000 --- a/scripts/bw-cli.sh +++ /dev/null @@ -1,75 +0,0 @@ -#!/usr/bin/env bash -# bw-cli.sh — Bitwarden CLI host wrapper (container-based, native Rust binary). -# -# Provides transparent `bw` access on hosts where the CLI is not installed -# natively. Runs the pre-compiled Rust bw binary inside a minimal Docker -# container (debian-slim + ca-certificates, NO Node.js). -# -# All tool execution happens inside the container. Nothing runs on the host -# except this wrapper, which only invokes docker. -# -# Usage: -# bw-cli.sh status Check vault status -# bw-cli.sh list items List vault items -# bw-cli.sh list collections List collections -# bw-cli.sh get password "Item" Retrieve a password -# bw-cli.sh get totp "Item" Retrieve a TOTP code -# bw-cli.sh get item "Item" Full item JSON -# bw-cli.sh generate -ulns Generate a password -# -# Install to ~/.local/bin/bw via: -# scripts/bw-install.sh -# -# Environment overrides: -# BW_ENV_FILE Path to credentials (default: ~/.config/bw/env) -# BW_IMAGE Docker image (default: reachableceo-bw-native:2026.7.0) -# BW_VOLUME Docker volume for persisted login state -# (default: tsys-bw-cli-state) -# BW_LIB_DIR Directory containing entrypoint.sh (default: ~/.local/share/bw) - -set -euo pipefail - -BW_ENV_FILE="${BW_ENV_FILE:-$HOME/.config/bw/env}" -BW_IMAGE="${BW_IMAGE:-reachableceo-bw-native:2026.7.0}" -BW_VOLUME="${BW_VOLUME:-tsys-bw-cli-state}" -BW_LIB_DIR="${BW_LIB_DIR:-$HOME/.local/share/bw}" - -# --- Validate prerequisites --- -if [ ! -f "$BW_ENV_FILE" ]; then - echo "bw: credential file not found: $BW_ENV_FILE" >&2 - echo " expected BW_CLIENTID, BW_CLIENTSECRET, BW_PASSWORD, BW_SERVER" >&2 - exit 1 -fi - -if ! docker image inspect "$BW_IMAGE" >/dev/null 2>&1; then - echo "bw: Docker image not found: $BW_IMAGE" >&2 - echo " build it: scripts/bw-install.sh" >&2 - exit 1 -fi - -if [ ! -f "$BW_LIB_DIR/entrypoint.sh" ]; then - echo "bw: entrypoint script missing: $BW_LIB_DIR/entrypoint.sh" >&2 - echo " install via: scripts/bw-install.sh" >&2 - exit 1 -fi - -# --- Load credentials (values are single-quoted in env file) --- -set -a -# shellcheck source=/dev/null -. "$BW_ENV_FILE" -set +a - -# --- Create persistent volume for BW CLI login state --- -docker volume create "$BW_VOLUME" >/dev/null 2>&1 || true - -# --- Run bw inside the container --- -docker run --rm -i \ - -e BW_CLIENTID \ - -e BW_CLIENTSECRET \ - -e BW_PASSWORD \ - -e BW_SERVER \ - -v "$BW_VOLUME:/root/.config/Bitwarden CLI" \ - -v "$BW_LIB_DIR/entrypoint.sh:/opt/bw/entrypoint.sh:ro" \ - --entrypoint sh \ - "$BW_IMAGE" \ - /opt/bw/entrypoint.sh "$@" diff --git a/scripts/bw-entrypoint.sh b/scripts/bw-entrypoint.sh deleted file mode 100755 index 22a224a..0000000 --- a/scripts/bw-entrypoint.sh +++ /dev/null @@ -1,44 +0,0 @@ -#!/bin/sh -# bw-entrypoint.sh — Bitwarden auth lifecycle, runs inside the container. -# -# Mounted at /opt/bw/entrypoint.sh by the host-side wrapper (bw-cli.sh). -# Handles: server config, API-key login, vault unlock, sync. -# Then execs the real bw command with BW_SESSION set. -# -# API key authentication does NOT require TOTP. The API key itself is -# obtained from an authenticated web vault session, so 2FA is already -# satisfied at key-generation time. -# -# This script intentionally uses /bin/sh (not bash) for minimal container -# compatibility. shellcheck directive below silences the "not bash" note. -# shellcheck shell=sh - -set -e - -BW_SERVER="${BW_SERVER:-https://pwvault.turnsys.com}" - -# Suppress BW CLI data-dir creation noise and telemetry. -export BW_NO_SENTRY=true - -# --- Step 1: Configure server (fails harmlessly if already logged in) --- -bw config server "$BW_SERVER" >/dev/null 2>&1 || true - -# --- Step 2: Login via API key (silently skips if already authenticated) --- -bw login --apikey >/dev/null 2>&1 || true - -# --- Step 3: Unlock the vault --- -printf '%s' "$BW_PASSWORD" > /tmp/.bwpw -SESS=$(bw unlock --passwordfile /tmp/.bwpw --raw 2>/dev/null) -rm -f /tmp/.bwpw -if [ -z "$SESS" ]; then - echo "bw: unlock failed. Check BW_PASSWORD in ~/.config/bw/env" >&2 - echo " Values must be single-quoted; \$ chars get mangled if unquoted." >&2 - exit 1 -fi - -# --- Step 4: Sync --- -bw sync --session "$SESS" >/dev/null 2>&1 || true - -# --- Step 5: Execute the requested command --- -export BW_SESSION="$SESS" -exec bw "$@" diff --git a/scripts/bw-install.sh b/scripts/bw-install.sh deleted file mode 100755 index 32e7b5f..0000000 --- a/scripts/bw-install.sh +++ /dev/null @@ -1,125 +0,0 @@ -#!/usr/bin/env bash -# bw-install.sh — Install the container-based Bitwarden CLI wrapper. -# -# Downloads the native Rust bw binary, builds the Docker image, and installs -# the host-side wrapper plus container entrypoint to the user's local paths. -# No Node.js is involved at any layer. -# -# Usage: -# bw-install.sh Download, build, and install everything -# bw-install.sh --check Verify installation status without changes -# -# Prerequisites: -# - docker on PATH -# - BW env file at ~/.config/bw/env (see prereq-check.sh in TSYSGroupAIOS) -# -# After install, ~/.local/bin/bw provides transparent CLI access. Add -# ~/.local/bin to PATH if not already (most distros do this via ~/.profile). - -set -euo pipefail - -HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" -REPO_ROOT="$(cd "$HERE/.." && pwd)" - -BW_VERSION="2026.7.0" -BW_IMAGE="reachableceo-bw-native:${BW_VERSION}" -BW_BINARY_URL="https://github.com/bitwarden/clients/releases/download/cli-v${BW_VERSION}/bw-linux-${BW_VERSION}.zip" - -INSTALL_BIN="${HOME}/.local/bin" -INSTALL_LIB="${HOME}/.local/share/bw" -BUILD_DIR="" - -# --- Helpers --- -log_info() { printf '\033[0;34m›\033[0m %s\n' "$*"; } -log_ok() { printf '\033[0;32m✓\033[0m %s\n' "$*"; } -log_warn() { printf '\033[1;33m⚠\033[0m %s\n' "$*" >&2; } -log_error() { printf '\033[0;31m✗\033[0m %s\n' "$*" >&2; } -log_step() { printf '\n\033[1m== %s ==\033[0m\n' "$*"; } -die() { log_error "$*"; exit 1; } - -# --- Cleanup on exit --- -cleanup() { - [ -n "$BUILD_DIR" ] && rm -rf "$BUILD_DIR" -} -trap cleanup EXIT - -# --- Check mode --- -if [ "${1:-}" = "--check" ]; then - log_step "BW CLI installation check" - if command -v docker >/dev/null 2>&1; then - log_ok "docker on PATH" - else - log_error "docker not on PATH" - fi - if docker image inspect "$BW_IMAGE" >/dev/null 2>&1; then - log_ok "Docker image ${BW_IMAGE} exists" - else - log_error "Docker image ${BW_IMAGE} missing" - fi - if [ -x "${INSTALL_BIN}/bw" ]; then - log_ok "Host wrapper at ${INSTALL_BIN}/bw" - else - log_error "Host wrapper at ${INSTALL_BIN}/bw missing" - fi - if [ -f "${INSTALL_LIB}/entrypoint.sh" ]; then - log_ok "Entrypoint at ${INSTALL_LIB}/entrypoint.sh" - else - log_error "Entrypoint at ${INSTALL_LIB}/entrypoint.sh missing" - fi - exit 0 -fi - -# --- Prerequisites --- -command -v docker >/dev/null 2>&1 || die "docker not found on PATH" - -log_step "Installing container-based Bitwarden CLI (native Rust, no Node.js)" - -# --- Step 1: Download and extract the native binary --- -BUILD_DIR=$(mktemp -d) -log_info "Downloading bw ${BW_VERSION} native binary..." - -docker run --rm -v "${BUILD_DIR}:/build" alpine:3.20 \ - sh -c "apk add --no-cache unzip >/dev/null 2>&1 && \ - wget -q -O /build/bw.zip '${BW_BINARY_URL}' && \ - unzip -o /build/bw.zip -d /build/ && \ - rm /build/bw.zip && \ - chmod +x /build/bw" - -[ -f "${BUILD_DIR}/bw" ] || die "download failed: bw binary not found" -log_ok "Downloaded native binary" - -# --- Step 2: Build the Docker image --- -log_info "Building Docker image ${BW_IMAGE}..." - -DOCKERFILE_DIR="${REPO_ROOT}/docker/bw-native" -if [ ! -f "${DOCKERFILE_DIR}/Dockerfile" ]; then - die "Dockerfile not found: ${DOCKERFILE_DIR}/Dockerfile" -fi - -cp "${BUILD_DIR}/bw" "${DOCKERFILE_DIR}/bw" -docker build -t "$BW_IMAGE" "$DOCKERFILE_DIR" -rm -f "${DOCKERFILE_DIR}/bw" -log_ok "Built image ${BW_IMAGE}" - -# --- Step 3: Install host-side wrapper and entrypoint --- -mkdir -p "$INSTALL_BIN" "$INSTALL_LIB" - -cp "${HERE}/bw-cli.sh" "${INSTALL_BIN}/bw" -chmod 755 "${INSTALL_BIN}/bw" -log_ok "Installed wrapper to ${INSTALL_BIN}/bw" - -cp "${HERE}/bw-entrypoint.sh" "${INSTALL_LIB}/entrypoint.sh" -chmod 755 "${INSTALL_LIB}/entrypoint.sh" -log_ok "Installed entrypoint to ${INSTALL_LIB}/entrypoint.sh" - -# --- Step 4: Verify --- -log_info "Verifying installation..." -if "${INSTALL_BIN}/bw" --version >/dev/null 2>&1; then - log_ok "bw CLI is operational" -else - log_warn "bw wrapper installed but verification call failed" - log_warn "check ~/.config/bw/env credentials and try: bw status" -fi - -log_step "Installation complete" -log_info "Usage: bw status | bw list items | bw get password \"Item Name\""