Problem
After #2112, cudly configure gcp still registers SIGINT/SIGTERM handling only after Step 5 returns. An interrupt after IAM creates the key but before upload can leave both the plaintext file and the active remote key behind.
Step 5 prints the temporary path before returning. A full stdout pipe blocks that print indefinitely. A second print after remote deletion also runs before local file removal, so it can block plaintext cleanup.
Reproduction
Run the actual runConfigureGCP coordinator in a subprocess with local IAM and Secrets Manager fixture endpoints. Fill stdout when the IAM create response arrives, wait for the fixture plaintext file, then send SIGINT or SIGTERM. The pre-fix coordinator exits and the key file remains. Merged commit c9d01f55dadee115926c5e00b807577c6e9784ab retains that coordinator code.
Expected behavior and fix
Activate signal cancellation after the final interactive choice, before key creation, and retain the same context through upload and cleanup. Remove output before cleanup completes. Preserve default interrupt behavior at blocking input prompts.
Scope: cmd/configure_gcp.go and real-coordinator subprocess regression tests. This addresses the signal lifecycle and stdout backpressure gap. The separate assertions, panic handling, and repeated-interrupt questions in #2117 remain tracked there.
Severity: medium. The interrupted setup leaves a long-lived credential that was intended to be removed.
References: #1947, #2112, #2117.
Problem
After #2112,
cudly configure gcpstill registers SIGINT/SIGTERM handling only after Step 5 returns. An interrupt after IAM creates the key but before upload can leave both the plaintext file and the active remote key behind.Step 5 prints the temporary path before returning. A full stdout pipe blocks that print indefinitely. A second print after remote deletion also runs before local file removal, so it can block plaintext cleanup.
Reproduction
Run the actual
runConfigureGCPcoordinator in a subprocess with local IAM and Secrets Manager fixture endpoints. Fill stdout when the IAM create response arrives, wait for the fixture plaintext file, then send SIGINT or SIGTERM. The pre-fix coordinator exits and the key file remains. Merged commitc9d01f55dadee115926c5e00b807577c6e9784abretains that coordinator code.Expected behavior and fix
Activate signal cancellation after the final interactive choice, before key creation, and retain the same context through upload and cleanup. Remove output before cleanup completes. Preserve default interrupt behavior at blocking input prompts.
Scope:
cmd/configure_gcp.goand real-coordinator subprocess regression tests. This addresses the signal lifecycle and stdout backpressure gap. The separate assertions, panic handling, and repeated-interrupt questions in #2117 remain tracked there.Severity: medium. The interrupted setup leaves a long-lived credential that was intended to be removed.
References: #1947, #2112, #2117.