Skip to content

Harden create-env agent passwords in cloud metadata - #742

Draft
Alphasite wants to merge 5 commits into
mainfrom
tnz-129825-hash-http-agent-password
Draft

Alphasite wants to merge 5 commits into
mainfrom
tnz-129825-hash-http-agent-password

Conversation

@Alphasite

@Alphasite Alphasite commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Harden newly written HTTPS agent metadata against reusable password exposure reported in the discovered CVE. For supporting stemcells, create-env writes a salted HMAC-SHA256 verifier instead of the agent password.

The CLI detects agent_features: [http-password-hmac-sha256] in stemcell.MF. It transforms cloud_provider.properties.agent.mbus and overriding resource-pool env.bosh.mbus.urls before rendering CPI configuration. Client credentials, interpolation variables, and credential stores retain the original password. HTTP clients and health checks need no capability detection. NATS URLs are preserved.

The fast verifier requires cryptographically random passwords. The CLI warns that hardcoded or predictable passwords remain vulnerable to offline guessing; password length alone cannot establish entropy. The companion agent uses constant-time comparison without a verification queue, wait timeout, or HTTP 503 response.

Companion agent: cloudfoundry/bosh-agent#487.

Companion stemcell builder: cloudfoundry/bosh-linux-stemcell-builder#761. The builder queries the packaged agent's -features output. Capability advertisement follows the binary without changing CPI api_version. A normal supporting-agent release bump activates it; stemcells without the marker retain legacy behavior. The capability survives repacking.

Breaking change requiring rollout review

Supporting stemcells require an explicit cloud_provider.properties.agent.mbus. A stemcell upgrade can therefore reject a manifest that previously relied on implicit CPI credential defaults. Configure this field before upgrading; whether to retain this requirement remains a draft review decision.

Validation

The earlier PBKDF2 revision passed go test ./agentpassword ./stemcell ./cmd. Those results do not validate the HMAC revision. Current packages compile with go build ./agentpassword ./stemcell ./cmd. Existing verifier and capability assertions have been updated but have not been rerun.

Security scope and rollout

This is hardening, not complete remediation of historical credential exposure. Rotate exposed credentials first to invalidate historical copies. Existing VMs are not rewritten by a no-change create-env run. Recreating with the same password does not invalidate historical copies.

Agent TLS private keys and other secrets remain in metadata. An exposed TLS private key can allow agent impersonation and compromise client passwords. Assess and rotate those credentials as appropriate. See docs/http-agent-password-verifiers.md for the contract and limits.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Alphasite Alphasite changed the title Hash create-env HTTP agent passwords for capable stemcells Address HTTPS agent credential exposure in create-env metadata Oct 6, 2026
@Alphasite Alphasite changed the title Address HTTPS agent credential exposure in create-env metadata Harden create-env agent passwords in cloud metadata Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

1 participant