mirror of
https://github.com/turnstonelabs/turnstone.git
synced 2026-08-12 23:12:23 -06:00
62d2a0fe6a
* fix: remove non-auth support from bootstrap wizard Auth is now mandatory for all deployments. Remove the TURNSTONE_AUTH_ENABLED toggle and make JWT_SECRET and AUTH_TOKEN required in the wizard's system prompt. * fix: remove auth disable support from runtime and infra Remove AuthConfig.enabled field — auth is always on. Drop TURNSTONE_AUTH_ENABLED env var, config toggle, and the check_request bypass. Update compose.yaml, Helm chart, Terraform, docs, and tests to match. * feat: deprecate config tokens, require JWT secret, prefer JWT auth Phase 1 of config-token removal: - load_jwt_secret() now exits with error if no secret is configured (was: silently auto-generated ephemeral secret) - _authenticate_token() logs deprecation warning on config token use - CLI /cluster commands use ServiceTokenManager when JWT secret is set - turnstone-admin tls-list uses ServiceTokenManager when JWT secret is set - Update bootstrap wizard, docker.md, security.md to mark TURNSTONE_AUTH_TOKEN as deprecated and JWT_SECRET as required - Console test fixtures use auth token + headers (auth always enforced) * feat: add service scope for inter-service JWT auth Add "service" to VALID_SCOPES and SCOPE_HIERARCHY. Service tokens bypass require_permission() RBAC checks, replacing the old empty-user-id bypass that config tokens relied on. All ServiceTokenManager instances that need admin access now include "service" in their scopes (console proxy, channel gateway, CLI, admin CLI). Read-only services (collector, notification) unchanged. * feat: phase 2 config token deprecation - SDK doc examples now show API tokens (ts_) instead of config tokens - Remove _get_config_token() from admin CLI (dead code) - Block config token exchange in handle_auth_login — only password and API token login allowed - Update login tests to use password-based auth instead of config token exchange * feat: phase 3 — remove config tokens entirely Complete removal of config-file token authentication: - Delete AuthConfig.tokens, check(), _ROLE_TO_SCOPES, hmac dispatch branch, and config token loading from load_auth_config() - Remove auth_config parameter from _authenticate_token() and check_request() — callers updated throughout - Remove TURNSTONE_AUTH_TOKEN from compose.yaml, Helm charts, Terraform, turnstone.example.toml - Remove --auth-token CLI flags from turnstone, turnstone-admin, and turnstone-console - Simplify console main() — always use ServiceTokenManager (no fallback to static tokens) - Delete config-token-specific tests, rewrite check_request and integration tests to use JWT auth with proper audience claims - Remove all config token references from docs (security.md, docker.md, sdk.md, console.md, architecture.md, bootstrap prompt) * fix: address code review findings - Fix 33 broken tests: add JWT auth to test_api_versioning, test_console_routing_proxy, test_tls_admin, test_tls_manager, test_server_live (jwt_secret + audience-scoped auth headers) - Add TestRequirePermissionServiceScope: 4 tests covering the service scope RBAC bypass path - Remove stale comments referencing config tokens in auth.py and console/server.py - Remove dead proxy_auth_token parameter from console create_app() and static token fallback in _proxy_auth_headers() - Remove TURNSTONE_AUTH_TOKEN from env.py scrub list * fix: address Copilot review — JWT audience, compose require secret - CLI /cluster: add audience=JWT_AUD_CONSOLE to ServiceTokenManager (console validates audience, JWTs without it were rejected) - Admin CLI tls-list: same audience fix - compose.yaml: TURNSTONE_JWT_SECRET now uses :? to fail fast if unset - SDK console: fix default port from 8081 to 8090 * test: add auth enforcement tests for TLS admin endpoints 5 new tests: unauthenticated requests return 401 (list, renew, delete), read-only-scoped requests return 403 (renew, delete). Closes the TLS auth enforcement test gap noted in PROGRESS.md. * fix: address remaining Copilot review feedback - Fix token_source="config" → "test" in TLS test fixtures - Fix AuthResult.token_source docstring to include service origins - Require TURNSTONE_JWT_SECRET in cluster compose profile (:?) - Helm: add auth.jwtSecret + auth.existingSecret values, wire TURNSTONE_JWT_SECRET into secret.yaml and both deployments - Terraform: replace auth_token with jwt_secret variable + secret, remove orphaned auth_token resources and IAM reference - Remove [[auth.tokens]] from security.md config example * fix: address full code review — 10 findings Critical: - Terraform: replace concat(common_env, auth_env) with common_env (auth_env local was removed but still referenced) - Channel gateway: remove hmac static token auth from _check_auth(), use JWT-only validation. Remove --auth-token CLI arg from channel - Rebalancer: add token_manager support so migration requests carry JWT auth (was sending unauthenticated POST to /internal/migrate) Major: - Guard _permissions_to_scopes() against "service" privilege escalation from DB role permissions - Remove dead AuthConfig class, load_auth_config(), and all auth_config parameters from create_app() signatures - Helm: inject JWT secret for both inline and existingSecret paths Minor: - Remove dead auth_token param from ClusterCollector - Remove empty TestLoadAuthConfig class - Short JWT secret now exits instead of warning - Compose: add generation command comment above JWT_SECRET - Clean stale config token references from 6 doc files - Clean stale AUTH_TOKEN reference from bootstrap wizard prompt * fix: remove remaining stale config token references from docs - channels.md: remove --auth-token from options table - oidc.md: remove "config-file tokens still work" claim - security.md: remove config token section, fix JWT secret docs (now required/exits, no ephemeral fallback), remove hmac from ASCII diagram, remove --auth-token reference
112 lines
4.0 KiB
TOML
112 lines
4.0 KiB
TOML
# turnstone.toml — shared bootstrap configuration
|
|
#
|
|
# This file is read once at startup. Values here are overridden by
|
|
# environment variables, which are in turn overridden by CLI flags.
|
|
#
|
|
# All sections are optional. Missing sections use binary defaults.
|
|
# Config file location precedence:
|
|
# 1. --config flag
|
|
# 2. $TURNSTONE_CONFIG env var
|
|
# 3. ~/.config/turnstone/config.toml
|
|
|
|
# --- LLM API (turnstone, node, eval) ---
|
|
|
|
[api]
|
|
# base_url = "" # API endpoint; empty = binary default
|
|
# api_key = "" # env: OPENAI_API_KEY or ANTHROPIC_API_KEY
|
|
|
|
# --- Default Model (turnstone, node, eval) ---
|
|
|
|
[model]
|
|
# name = "" # Model ID; empty = provider default (gpt-5 / claude-sonnet-4)
|
|
# temperature = 0.0 # 0 = provider default
|
|
# reasoning_effort = "" # "low", "medium", "high", "max"
|
|
# context_window = 0 # 0 = auto-detect from provider capabilities
|
|
# max_tokens = 0 # 0 = provider default
|
|
|
|
# --- Named Models (turnstone, node, eval) ---
|
|
# Define model aliases with per-model overrides. Useful for local model
|
|
# servers or mixing providers. Reference by name with --model flag.
|
|
#
|
|
# [models.local]
|
|
# name = "llama-3-70b"
|
|
# provider = "openai"
|
|
# base_url = "http://localhost:8000/v1"
|
|
# context_window = 8192
|
|
#
|
|
# [models.local.capabilities]
|
|
# supports_vision = false
|
|
# supports_web_search = false
|
|
#
|
|
# [models.claude]
|
|
# name = "claude-opus-4-6"
|
|
# provider = "anthropic"
|
|
|
|
# --- Database (turnstone, node, console) ---
|
|
|
|
[database]
|
|
# url = "" # postgres://user:pass@host/db or /path/to.db
|
|
# env: TURNSTONE_DB_URL
|
|
# SSL params (passed through to SQLAlchemy connection):
|
|
# sslmode = "prefer" # disable, allow, prefer, require, verify-ca, verify-full
|
|
# sslrootcert = "" # path to CA cert for verify-ca/verify-full
|
|
# sslcert = "" # path to client cert (mTLS)
|
|
# sslkey = "" # path to client key (mTLS)
|
|
|
|
# --- Auth (node, console) ---
|
|
|
|
[auth]
|
|
# Auth is always enabled. JWT secret is required.
|
|
# jwt_secret = "" # HS256 signing secret (min 32 bytes recommended)
|
|
# env: TURNSTONE_JWT_SECRET
|
|
|
|
# --- Logging (turnstone, node, console) ---
|
|
|
|
[log]
|
|
# level = "" # "debug", "info", "warn", "error"
|
|
# empty = binary default (warn for CLI, info for servers)
|
|
# env: TURNSTONE_LOG_LEVEL
|
|
# json = false # JSON output; auto-enabled when stderr is not a TTY
|
|
|
|
# --- Session (turnstone, node) ---
|
|
|
|
[session]
|
|
# instructions = "" # Default system message
|
|
# compact_max_tokens = 32768 # Max tokens for context compaction summary
|
|
# auto_compact_pct = 0.8 # Trigger compaction at this % of context window
|
|
|
|
# --- Tools (turnstone, node) ---
|
|
|
|
[tools]
|
|
# timeout = 120 # Tool execution timeout in seconds
|
|
# skip_permissions = false # Auto-approve all tool calls
|
|
|
|
# --- Judge (turnstone, node) ---
|
|
|
|
[judge]
|
|
# enabled = true # Enable intent validation
|
|
# confidence_threshold = 0.7 # Minimum confidence for heuristic verdicts
|
|
# output_guard = true # Scan tool output for security signals
|
|
# redact_secrets = true # Redact detected credentials in output
|
|
|
|
# --- Memory (turnstone, node) ---
|
|
|
|
[memory]
|
|
# relevance_k = 5 # Top-K memories for context injection
|
|
# fetch_limit = 50 # Max memories to fetch for ranking
|
|
# max_content = 32768 # Max memory content size in chars
|
|
# nudge_cooldown = 300 # Min seconds between metacognitive nudges
|
|
# nudges = true # Enable memory nudges
|
|
|
|
# --- MCP (turnstone, node) ---
|
|
|
|
[mcp]
|
|
# config_path = "" # Path to MCP servers config file (JSON)
|
|
# refresh_interval = 14400 # Refresh interval in seconds (default: 4h)
|
|
|
|
# --- Server (node, console) ---
|
|
|
|
[server]
|
|
# max_workstreams = 50 # Maximum concurrent workstreams per node
|
|
# env: TURNSTONE_MAX_WORKSTREAMS
|