mirror of
https://github.com/coder/coder.git
synced 2026-09-22 05:05:20 +08:00
## Overview Part of the **boundary correlation** feature. Fixes lazy creation of `boundary_sessions` rows so it works within the agent's RBAC constraints, and consumes the new `ConfinedProcessName` field reported by boundary. Pairs with coder/boundary#206, which adds `ConfinedProcessName` to `ReportBoundaryLogsRequest`. This branch bumps the `github.com/coder/boundary` module to pick up that work. ## Problem `ensureSession` did a pre-insert existence check via `GetBoundarySessionByID`. Agents are **not permitted to read boundary sessions**, so that read path is not viable when the session is created from an agent-reported log batch. ## Changes - **Remove the pre-insert read.** `ensureSession` now inserts directly and treats a primary-key unique violation as success, covering sessions already created by a prior batch, a reconnection, or another coderd replica — without requiring read access. - **Per-connection guard.** Add a mutex-protected `ensuredSessions` set so repeated log batches on the same connection skip the existence check and insert entirely, touching the database only for the logs. On a transient insert failure the session is left unmarked so the next batch retries. - **Consume `ConfinedProcessName`.** Pass `req.GetConfinedProcessName()` through to the session insert. - **Bump boundary module** from `v0.9.0` to `v0.9.1-0.20260706095856-35ba90f9e8b2`. - **Tests.** - Add `TestReportBoundaryLogsAgentRBAC` (`coderd/boundary_logs_test.go`), an integration test that connects as a real workspace agent, verifies the session and log are persisted under agent RBAC, and asserts the agent subject cannot read boundary sessions — guarding against reintroducing a pre-insert read. - Add `TestReportBoundaryLogsSessionGuard` (session inserted once across two batches, logs inserted per batch) and `TestReportBoundaryLogsSessionRetriedOnError` (insert retried after a transient error). - Regenerate `agent-firewall` CLI docs/golden files and adjust the clidocgen template to render the YAML path when a flag has no long name. > 🤖 This PR was opened by Coder Agents on behalf of @SasSwart.
60 lines
1.1 KiB
Smarty
60 lines
1.1 KiB
Smarty
<!-- DO NOT EDIT | GENERATED CONTENT -->
|
|
# {{ fullName . }}
|
|
|
|
{{ with .Short }}
|
|
{{ . }}
|
|
|
|
{{ end }}
|
|
|
|
{{ with .Aliases }}
|
|
Aliases:
|
|
{{- range $index, $alias := . }}
|
|
* {{ $alias }}
|
|
{{- end }}
|
|
{{ end }}
|
|
|
|
{{- if .Use }}
|
|
## Usage
|
|
```console
|
|
{{ .FullUsage }}
|
|
```
|
|
{{end}}
|
|
|
|
{{- if .Long}}
|
|
## Description
|
|
```console
|
|
{{.Long}}
|
|
```
|
|
{{end}}
|
|
|
|
{{- range $index, $cmd := visibleSubcommands . }}
|
|
{{- if eq $index 0 }}
|
|
## Subcommands
|
|
| Name | Purpose |
|
|
| ---- | ----- |
|
|
{{- end }}
|
|
| [{{ $cmd.Name | wrapCode }}](./{{commandURI $cmd}}) | {{ $cmd.Short }} |
|
|
{{- end}}
|
|
{{ "" }}
|
|
{{- range $index, $opt := visibleOptions . }}
|
|
{{- if eq $index 0 }}
|
|
## Options
|
|
{{- end }}
|
|
### {{ with $opt.FlagShorthand}}-{{ . }}, {{end}}{{ if $opt.Flag }}--{{ $opt.Flag }}{{ else }}{{ $opt.YAMLPath }}{{ end }}
|
|
{{" "}}
|
|
{{ tableHeader }}
|
|
| Type | {{ typeHelper $opt | wrapCode }} |
|
|
{{- with $opt.Env }}
|
|
| Environment | {{ (print "$" .) | wrapCode }} |
|
|
{{- end }}
|
|
{{- with $opt.YAMLPath }}
|
|
| YAML | {{ . | wrapCode }} |
|
|
{{- end }}
|
|
{{- with $opt.Default }}
|
|
| Default | {{- . | wrapCode }} |
|
|
{{ "" }}
|
|
{{ end }}
|
|
{{ "" }}
|
|
{{ $opt.Description | newLinesToBr }}
|
|
{{- end}}
|