Skip to content
This repository was archived by the owner on Sep 28, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/).
- Removed current-tree concrete operator home-path metadata and generalized regression tests so they assert classes of forbidden data instead of encoding real identities.
- First live `private-runtime-config.yml` stopped fail-closed (`changed=0`) at Vault OCID shape validation after Argo CD, scratch PV/PVC binding, and the OCI Secrets Store CSI Driver/provider were already healthy. The operator Vault ID had prefix `ocid1.vault.oc1`, length 105, and no whitespace; Git required `ocid1.vault.oc1.<region>.<unique>` and omitted the empty OCI future-use component. Git now validates regional Vault OCIDs as `ocid1.vault.oc1.<region>..<unique>` (optional future-use) and requires the OCID region component to equal `private_runtime_config_oci_region`. Private-runtime materialization, Instance Principal secret retrieval, generated Kubernetes Secrets, Postgres/MLflow/Monitoring health, and second-converge idempotency remain **not yet live proven**.
- First live Monitoring Application remained Healthy but OutOfSync: Argo client-side apply failed for multiple Prometheus Operator CRDs with `metadata.annotations: Too long: must have at most 262144 bytes`, after which dependent `Prometheus` and `Alertmanager` resources could not fully reconcile. Git now sets `ServerSideApply=true` on the Monitoring Application only, while keeping `CreateNamespace=true`, automated prune, selfHeal, and Helm `includeCRDs: true`. Monitoring Synced after this change is **not yet live proven**.
- A fresh OCI V2 clean-room apply failed while creating `oci_core_instance.node`: `launch_options` that only enabled PV encryption in transit produced `400-InvalidParameter` because LaunchOptions requires NetworkType. Git now sets `is_pv_encryption_in_transit_enabled = true` as the supported top-level instance create argument and keeps the scratch attachment paravirtualized with PV encryption in transit. Regression coverage requires that top-level assignment so nested `launch_options` alone cannot satisfy the contract. Renewed clean-room instance creation is **not yet live proven**.

## [0.1.0] - 2026-07-30

Expand Down
7 changes: 4 additions & 3 deletions terraform/compute.tf
Original file line number Diff line number Diff line change
Expand Up @@ -55,9 +55,10 @@ resource "oci_core_instance" "node" {
# The scratch volume attachment requires PV encryption in transit. Leaving
# this unset lets OCI default the instance to false, which then rejects the
# encrypted paravirtualized attachment.
launch_options {
is_pv_encryption_in_transit_enabled = true
}
# Use the instance create argument. A launch_options block that only sets
# this field is rejected with 400-InvalidParameter unless NetworkType is also
# specified; this pin does not need any other launch option.
is_pv_encryption_in_transit_enabled = true

metadata = {
ssh_authorized_keys = var.ssh_public_key
Expand Down
77 changes: 63 additions & 14 deletions tests/unit/test_terraform_pv_encryption_contract.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,6 @@
# Static regression for the OCI PV in-transit encryption contract.
# Inspects production Terraform blocks only.
# No OCI provider, no remote backend, no credentials, no root plan/apply.

set -euo pipefail

ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
Expand All @@ -19,8 +18,21 @@ ROOT = Path(sys.argv[1]).resolve()
TERRAFORM_DIR = ROOT / "terraform"
INSTANCE_RESOURCE = 'resource "oci_core_instance" "node"'
ATTACHMENT_RESOURCE = 'resource "oci_core_volume_attachment" "scratch"'
PV_ATTR = "is_pv_encryption_in_transit_enabled"
PV_TRUE = "is_pv_encryption_in_transit_enabled = true"
PV_FALSE = "is_pv_encryption_in_transit_enabled = false"
NESTED_INSTANCE_BLOCKS = (
"shape_config",
"create_vnic_details",
"source_details",
"launch_options",
"instance_options",
"availability_config",
"agent_config",
"platform_config",
"preemptible_instance_config",
"metadata",
)


def extract_hcl_block(source: str, marker: str, label: str) -> str:
Expand All @@ -41,6 +53,12 @@ def extract_hcl_block(source: str, marker: str, label: str) -> str:
raise SystemExit(f"{label} is unclosed")


def try_extract_hcl_block(source: str, marker: str) -> str | None:
if source.find(marker) < 0:
return None
return extract_hcl_block(source, marker, marker)


def strip_hcl_comments(text: str) -> str:
stripped_lines = []
for line in text.splitlines():
Expand Down Expand Up @@ -69,6 +87,16 @@ def quoted_assignment(block: str, name: str, value: str) -> bool:
)


def resource_top_level(resource_code: str) -> str:
remaining = resource_code
for name in NESTED_INSTANCE_BLOCKS:
nested = try_extract_hcl_block(remaining, name)
while nested is not None:
remaining = remaining.replace(nested, "", 1)
nested = try_extract_hcl_block(remaining, name)
return remaining


def main() -> None:
tf_files = sorted(TERRAFORM_DIR.glob("*.tf"))
if not tf_files:
Expand All @@ -84,33 +112,54 @@ def main() -> None:
instance_code = strip_hcl_comments(instance)
attachment_code = strip_hcl_comments(attachment)
production_code = strip_hcl_comments(joined)

launch_options = extract_hcl_block(
instance_code, "launch_options", "oci_core_instance.node launch_options"
)
if not assignment_true(launch_options, "is_pv_encryption_in_transit_enabled"):
top_level = resource_top_level(instance_code)
launch_options = try_extract_hcl_block(instance_code, "launch_options")

if launch_options is not None:
nested_true = assignment_true(launch_options, PV_ATTR)
nested_false = assignment_false(launch_options, PV_ATTR)
if nested_true and not assignment_true(top_level, PV_ATTR):
raise SystemExit(
"instance PV encryption must not be satisfied solely by "
"nested launch_options"
)
if nested_true or nested_false:
raise SystemExit(
"oci_core_instance.node must not assign "
"is_pv_encryption_in_transit_enabled inside launch_options"
)
if not re.search(r'(?m)^\s*network_type\s*=', launch_options):
raise SystemExit(
"oci_core_instance.node launch_options must set network_type; "
"OCI rejects LaunchOptions without NetworkType"
)
print("PASS: optional launch_options is not the PV encryption contract")
else:
print("PASS: instance does not use launch_options for PV encryption")

if not assignment_true(top_level, PV_ATTR):
raise SystemExit(
"oci_core_instance.node launch_options must set "
"is_pv_encryption_in_transit_enabled = true"
"oci_core_instance.node must set "
f"{PV_TRUE} at resource top level"
)
if assignment_false(launch_options, "is_pv_encryption_in_transit_enabled"):
if assignment_false(instance_code, PV_ATTR):
raise SystemExit(
"oci_core_instance.node must not disable PV encryption in transit"
)
print("PASS: instance launch_options enables PV encryption in transit")
print("PASS: instance top-level PV encryption in transit is enabled")

if not quoted_assignment(attachment_code, "attachment_type", "paravirtualized"):
raise SystemExit(
"oci_core_volume_attachment.scratch must remain paravirtualized"
)
print("PASS: scratch attachment type remains paravirtualized")

if not assignment_true(attachment_code, "is_pv_encryption_in_transit_enabled"):
if not assignment_true(attachment_code, PV_ATTR):
raise SystemExit(
"oci_core_volume_attachment.scratch must set "
"is_pv_encryption_in_transit_enabled = true"
f"{PV_TRUE}"
)
if assignment_false(attachment_code, "is_pv_encryption_in_transit_enabled"):
if assignment_false(attachment_code, PV_ATTR):
raise SystemExit(
"oci_core_volume_attachment.scratch must not disable PV encryption"
)
Expand All @@ -126,7 +175,7 @@ def main() -> None:
"production Terraform must not assign "
f"{PV_FALSE} (found in {', '.join(false_matches)})"
)
if PV_TRUE not in instance_code or PV_TRUE not in attachment_code:
if PV_TRUE not in top_level or PV_TRUE not in attachment_code:
raise SystemExit("instance and attachment PV encryption assignments drifted")
if "is_pv_encryption_in_transit_enabled" not in production_code:
raise SystemExit("PV encryption contract missing from production Terraform")
Expand Down
Loading