Skip to content

fix(security): consolidate host environment leak guard - #1163

Merged
POWERFULMOVES merged 1 commit into
mainfrom
fix/ssl-env-leak-consolidation
Mar 31, 2026
Merged

POWERFULMOVES merged 1 commit into
mainfrom
fix/ssl-env-leak-consolidation

Conversation

@POWERFULMOVES

@POWERFULMOVES POWERFULMOVES commented Mar 31, 2026

Copy link
Copy Markdown
Owner

Standardizes 8-variable host leak guard across all Docker services. Fixes transcribe-backend crash from Windows SSL_CERT_FILE leak.

Summary by CodeRabbit

  • Chores
    • Updated submodule commit reference
    • Added proxy and certificate bundle environment variables (HTTP_PROXY, HTTPS_PROXY, NO_PROXY, REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS) with default empty values to configuration registry, compose setup, and environment templates.

…vices

Eliminates Windows host env var leakage into Docker containers by
standardizing a full 8-variable leak guard (SSL_CERT_FILE, SSL_CERT_DIR,
REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS, HTTP_PROXY,
HTTPS_PROXY, NO_PROXY) across all services.

Previously: 14 services had partial SSL-only nullification (2 vars),
3 services had SSL_CERT_FILE only, transcribe-and-fetch had zero.

Now: All 14+ main compose services + 6 transcribe submodule services
have the complete guard. Sanitizer allowlist, env.shared.example, and
bootstrap registry extended with the 6 new proxy/CA infrastructure vars.

Fixes pmoves-transcribe-backend-1 crash (SSL_CERT_FILE → FileNotFoundError).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@github-actions

Copy link
Copy Markdown
Contributor

Docker Hardening Validation

Hardening Validation Report

Validated: Tue Mar 31 02:44:21 UTC 2026

Services Checked

PMOVES.AI Docker Hardening Validation

[INFO] Checking: pmoves/docker-compose.hardened.yml

[INFO] Validating: hi-rag-gateway-v2
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: extract-worker
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: langextract
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: presign
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: render-webhook
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: retrieval-eval
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pdf-ingest
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: jellyfin-bridge
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: invidious-companion-proxy
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: ffmpeg-whisper
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-video
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-audio
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-v2-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: deepresearch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supaserch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: publisher-discord
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: mesh-agent
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-req
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-res
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: publisher
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: analysis-echo
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: graph-linker
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: comfy-watcher
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: grayjay-plugin-host
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: agent-zero
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: archon
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: channel-monitor
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pmoves-yt
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: notebook-sync
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supabase_service_role_key
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

[INFO] Validating: supabase_jwt_secret
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

======================================
Summary: 120 passed, 40 warnings, 0 errors

@coderabbitai

coderabbitai Bot commented Mar 31, 2026

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

This PR updates environment configuration to prevent Windows Docker Desktop host variable leaks by introducing proxy and CA-bundle variables (HTTP_PROXY, HTTPS_PROXY, NO_PROXY, REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS) across bootstrap registry, docker-compose services, and sanitization tooling while updating the PMOVES-transcribe-and-fetch submodule reference.

Changes

Cohort / File(s) Summary
Submodule Reference
PMOVES-transcribe-and-fetch
Updated submodule commit reference from 6d9c65d to 322f05f.
Bootstrap Registry & Environment Variables
pmoves/bootstrap/registry.json, pmoves/env.shared.example
Added six proxy and CA-bundle environment variables (HTTP_PROXY, HTTPS_PROXY, NO_PROXY, REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS) to registry declarations and env.shared example with empty defaults to prevent Windows host environment leaks.
Docker Compose Services
pmoves/docker-compose.yml
Updated environment blocks across multiple services to explicitly set proxy and CA-bundle variables to empty values alongside existing SSL cert neutralization logic, documented via "HOST ENVIRONMENT LEAK GUARD" YAML anchor.
Environment Sanitization Tool
pmoves/tools/sanitize_env_shared.py
Extended allowlist to include proxy and CA-bundle infrastructure variables to nullify host leaks when empty.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Possibly related PRs

Poem

🐰 A Windows host tried to sneak in,
With proxies and certs through Docker's thin skin,
But now we stand guard with variables clear,
Empty and ready to make leaks disappear! 🛡️

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The pull request description is incomplete. It lacks the required Summary section with bullet points, Testing section with commands/output, Required Checks checklist, and Review Coordination checklist from the template. Add the missing template sections: expand Summary with bullet points explaining what changed and why, document testing commands and results, complete the Required Checks and Review Coordination checklists.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main security objective of the changeset: consolidating a host environment leak guard across Docker services.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/ssl-env-leak-consolidation

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
pmoves/docker-compose.yml (1)

1776-1831: Remove duplicated leak-guard blocks in two services.

hi-rag-gateway-v2 and hi-rag-gateway-v2-gpu each define the same guard list twice in one environment: block. Keep a single copy per service to avoid drift.

♻️ Proposed cleanup
   hi-rag-gateway-v2:
@@
-    # Host environment leak guard (see x-host-leak-guard docs above)
-    - SSL_CERT_FILE=
-    - SSL_CERT_DIR=
-    - REQUESTS_CA_BUNDLE=
-    - CURL_CA_BUNDLE=
-    - NODE_EXTRA_CA_CERTS=
-    - HTTP_PROXY=
-    - HTTPS_PROXY=
-    - NO_PROXY=
@@
   hi-rag-gateway-v2-gpu:
@@
-    # Host environment leak guard (see x-host-leak-guard docs above)
-    - SSL_CERT_FILE=
-    - SSL_CERT_DIR=
-    - REQUESTS_CA_BUNDLE=
-    - CURL_CA_BUNDLE=
-    - NODE_EXTRA_CA_CERTS=
-    - HTTP_PROXY=
-    - HTTPS_PROXY=
-    - NO_PROXY=

Also applies to: 1946-2005

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/docker-compose.yml` around lines 1776 - 1831, The environment
leak-guard block (variables like SSL_CERT_FILE, SSL_CERT_DIR,
REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE, NODE_EXTRA_CA_CERTS, HTTP_PROXY,
HTTPS_PROXY, NO_PROXY, etc.) is duplicated inside the environment: of the
services hi-rag-gateway-v2 and hi-rag-gateway-v2-gpu; remove the second copy so
each service has only one leak-guard list, keeping the first (or canonical)
block and deleting the redundant repeated block to prevent drift.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In `@pmoves/docker-compose.yml`:
- Around line 1776-1831: The environment leak-guard block (variables like
SSL_CERT_FILE, SSL_CERT_DIR, REQUESTS_CA_BUNDLE, CURL_CA_BUNDLE,
NODE_EXTRA_CA_CERTS, HTTP_PROXY, HTTPS_PROXY, NO_PROXY, etc.) is duplicated
inside the environment: of the services hi-rag-gateway-v2 and
hi-rag-gateway-v2-gpu; remove the second copy so each service has only one
leak-guard list, keeping the first (or canonical) block and deleting the
redundant repeated block to prevent drift.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 11e51f87-5c85-4a68-a7f2-f9a15fd9c2ea

📥 Commits

Reviewing files that changed from the base of the PR and between d115aa3 and dbbb90b.

📒 Files selected for processing (5)
  • PMOVES-transcribe-and-fetch
  • pmoves/bootstrap/registry.json
  • pmoves/docker-compose.yml
  • pmoves/env.shared.example
  • pmoves/tools/sanitize_env_shared.py

@POWERFULMOVES
POWERFULMOVES merged commit eeee4c0 into main Mar 31, 2026
17 of 19 checks passed
@POWERFULMOVES
POWERFULMOVES deleted the fix/ssl-env-leak-consolidation branch March 31, 2026 02:53
POWERFULMOVES pushed a commit that referenced this pull request Apr 7, 2026
Missed in #1163 — transcribe-backend in main compose had no SSL/proxy
nullification, causing persistent crash from Windows SSL_CERT_FILE leak.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
POWERFULMOVES added a commit that referenced this pull request Apr 7, 2026
Missed in #1163 — transcribe-backend in main compose had no SSL/proxy
nullification, causing persistent crash from Windows SSL_CERT_FILE leak.

Co-authored-by: Shaela Bello <slbello@uncg.edu>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants