From e19f1b8eb9ae3c9a1edddd9124c51ca45aa2c9bc Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Wed, 26 Aug 2026 15:44:02 +0530 Subject: [PATCH 01/10] renamed AWS Secret name --- .secrets.baseline | 4 +- .../mascli/functions/gitops_suite_app_config | 6 +- image/cli/mascli/functions/gitops_utils | 56 ++++++++++++------- 3 files changed, 41 insertions(+), 25 deletions(-) diff --git a/.secrets.baseline b/.secrets.baseline index 7defc27246..18fb37bf2e 100644 --- a/.secrets.baseline +++ b/.secrets.baseline @@ -3,7 +3,7 @@ "files": "build/bin/config/oscap/ssg-rhel9-ds.xml|^.secrets.baseline$|^docs/catalogs/", "lines": null }, - "generated_at": "2026-08-20T08:19:14Z", + "generated_at": "2026-08-26T10:10:54Z", "plugins_used": [ { "name": "AWSKeyDetector" @@ -550,7 +550,7 @@ "hashed_secret": "effb7852555adce89885fb075fb43a77a1e0e77e", "is_secret": false, "is_verified": false, - "line_number": 1370, + "line_number": 1386, "type": "Secret Keyword", "verified_result": null } diff --git a/image/cli/mascli/functions/gitops_suite_app_config b/image/cli/mascli/functions/gitops_suite_app_config index 564f93840a..58dec237f7 100644 --- a/image/cli/mascli/functions/gitops_suite_app_config +++ b/image/cli/mascli/functions/gitops_suite_app_config @@ -425,7 +425,7 @@ function gitops_suite_app_config() { if [[ -n "${ICN}" ]]; then echo "✓ ICN successfully resolved: ${ICN}" echo " This ICN will be used for customer-level secrets:" - echo " - ibm-customer/${ICN}/facilities/manage-mref-keystore-password" + echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities--vs${ICN}-sn" echo " - ibm-customer/${ICN}//..." else echo "⚠ WARNING: ICN not available - customer-level secrets cannot be used" @@ -640,11 +640,11 @@ function gitops_suite_app_config() { echo "- Verifying user-provided secret exists..." else # No user-provided name - use customer-level default - export FACILITIES_VAULT_SECRET_NAME="manage-mref-keystore-password" + export FACILITIES_VAULT_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities--vs-sn" echo "- Using customer-level vault secret name: ${FACILITIES_VAULT_SECRET_NAME}" # Ensure customer-level secret exists - manage_customer_mref_password "${ICN}" "${ACCOUNT_ID}" "${CLUSTER_ID}" "${MAS_INSTANCE_ID}" "${SECRETS_KEY_SEPERATOR}" + manage_customer_mref_password "${ICN}" "${ACCOUNT_ID}" "${CLUSTER_ID}" "${MAS_INSTANCE_ID}" "${MAS_WORKSPACE_ID}" "${SECRETS_KEY_SEPERATOR}" if [[ $? -ne 0 ]]; then echo "ERROR: Failed to create/retrieve customer-level MREF password" exit 1 diff --git a/image/cli/mascli/functions/gitops_utils b/image/cli/mascli/functions/gitops_utils index b625f3473d..57dd740c76 100644 --- a/image/cli/mascli/functions/gitops_utils +++ b/image/cli/mascli/functions/gitops_utils @@ -524,7 +524,7 @@ function sm_get_secret_arn() { # This prevents backflow issues when moving data between prod/dev/test environments. # # The function: -# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/manage-mref-keystore-password +# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities--vs{ICN}-sn # 2. If not, checks for legacy instance-level password and migrates it # 3. If neither exists, generates a new secure alphanumeric password # 4. Stores password at customer level for reuse across all customer instances @@ -534,7 +534,8 @@ function sm_get_secret_arn() { # $2 - ACCOUNT_ID # $3 - CLUSTER_ID # $4 - MAS_INSTANCE_ID -# $5 - SECRETS_KEY_SEPERATOR +# $5 - MAS_WORKSPACE_ID +# $6 - SECRETS_KEY_SEPERATOR # # Returns: # 0 on success, 1 on failure @@ -544,7 +545,8 @@ function manage_customer_mref_password() { local ACCOUNT_ID="$2" local CLUSTER_ID="$3" local MAS_INSTANCE_ID="$4" - local SECRETS_KEY_SEPERATOR="$5" + local MAS_WORKSPACE_ID="$5" + local SECRETS_KEY_SEPERATOR="$6" if [[ -z "${ICN}" ]]; then echo "ERROR: ICN is required for customer-level MREF password management" @@ -556,8 +558,9 @@ function manage_customer_mref_password() { echo "- Customer ICN: ${ICN}" # Define secret paths following customer-level secret pattern: ibm-customer/{ICN}/facilities/... - local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" - local LEGACY_SECRET_NAME="${ACCOUNT_ID}${SECRETS_KEY_SEPERATOR}${CLUSTER_ID}${SECRETS_KEY_SEPERATOR}${MAS_INSTANCE_ID}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" + local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities--vs${ICN}-sn" + local LEGACY_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" + local LEGACY_INSTANCE_SECRET_NAME="${ACCOUNT_ID}${SECRETS_KEY_SEPERATOR}${CLUSTER_ID}${SECRETS_KEY_SEPERATOR}${MAS_INSTANCE_ID}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" # Check if customer-level secret exists echo "- Checking for customer-level secret: ${CUSTOMER_SECRET_NAME}" @@ -570,29 +573,42 @@ function manage_customer_mref_password() { return 0 fi - # Customer-level secret doesn't exist, check for legacy instance-level secret - echo "- Customer-level secret not found, checking for legacy instance-level secret" + # Customer-level secret not found, check for legacy customer-level secret (manage-mref-keystore-password) + echo "- Customer-level secret not found, checking for legacy customer-level secret" echo "- Checking: ${LEGACY_SECRET_NAME}" set +o pipefail local LEGACY_PASSWORD=$(sm_get_secret_value "${LEGACY_SECRET_NAME}" "password" 2>/dev/null) set -o pipefail if [[ -n "${LEGACY_PASSWORD}" ]] && [[ "${LEGACY_PASSWORD}" != "null" ]]; then - echo "- Legacy instance-level password found, migrating to customer level" + echo "- Legacy customer-level password found, migrating to new customer-level secret" MREF_PASSWORD="${LEGACY_PASSWORD}" - local MIGRATION_NOTE="Migrated from instance-level secret: ${LEGACY_SECRET_NAME}" + local MIGRATION_NOTE="Migrated from legacy customer-level secret: ${LEGACY_SECRET_NAME}" else - echo "- No existing password found, generating new secure password" - # Generate secure alphanumeric password (no special characters to avoid escaping issues) - # Use a loop to ensure we get exactly 32 characters after filtering - while true; do - MREF_PASSWORD=$(cat /dev/urandom | tr -dc 'a-zA-Z0-9' | head -c 64) #pragma: allowlist secret - if [[ ${#MREF_PASSWORD} -ge 32 ]]; then - MREF_PASSWORD=${MREF_PASSWORD:0:32} #pragma: allowlist secret - break - fi - done - local MIGRATION_NOTE="Generated for first deployment" + # Legacy customer-level not found, check legacy instance-level secret + echo "- Legacy customer-level secret not found, checking for legacy instance-level secret" + echo "- Checking: ${LEGACY_INSTANCE_SECRET_NAME}" + set +o pipefail + local LEGACY_INSTANCE_PASSWORD=$(sm_get_secret_value "${LEGACY_INSTANCE_SECRET_NAME}" "password" 2>/dev/null) + set -o pipefail + + if [[ -n "${LEGACY_INSTANCE_PASSWORD}" ]] && [[ "${LEGACY_INSTANCE_PASSWORD}" != "null" ]]; then + echo "- Legacy instance-level password found, migrating to customer level" + MREF_PASSWORD="${LEGACY_INSTANCE_PASSWORD}" + local MIGRATION_NOTE="Migrated from instance-level secret: ${LEGACY_INSTANCE_SECRET_NAME}" + else + echo "- No existing password found, generating new secure password" + # Generate secure alphanumeric password (no special characters to avoid escaping issues) + # Use a loop to ensure we get exactly 32 characters after filtering + while true; do + MREF_PASSWORD=$(cat /dev/urandom | tr -dc 'a-zA-Z0-9' | head -c 64) #pragma: allowlist secret + if [[ ${#MREF_PASSWORD} -ge 32 ]]; then + MREF_PASSWORD=${MREF_PASSWORD:0:32} #pragma: allowlist secret + break + fi + done + local MIGRATION_NOTE="Generated for first deployment" + fi fi # Store password at customer level From 7f6a8a9f955b7f5ff64081012987d1f4ad1884fc Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Tue, 8 Sep 2026 11:12:45 +0530 Subject: [PATCH 02/10] renamed the secret --- image/cli/mascli/functions/gitops_suite_app_config | 2 +- image/cli/mascli/functions/gitops_utils | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/image/cli/mascli/functions/gitops_suite_app_config b/image/cli/mascli/functions/gitops_suite_app_config index 58dec237f7..0b6799f864 100644 --- a/image/cli/mascli/functions/gitops_suite_app_config +++ b/image/cli/mascli/functions/gitops_suite_app_config @@ -425,7 +425,7 @@ function gitops_suite_app_config() { if [[ -n "${ICN}" ]]; then echo "✓ ICN successfully resolved: ${ICN}" echo " This ICN will be used for customer-level secrets:" - echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities--vs${ICN}-sn" + echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities--vs-sn" echo " - ibm-customer/${ICN}//..." else echo "⚠ WARNING: ICN not available - customer-level secrets cannot be used" diff --git a/image/cli/mascli/functions/gitops_utils b/image/cli/mascli/functions/gitops_utils index 57dd740c76..bf67428de8 100644 --- a/image/cli/mascli/functions/gitops_utils +++ b/image/cli/mascli/functions/gitops_utils @@ -524,7 +524,7 @@ function sm_get_secret_arn() { # This prevents backflow issues when moving data between prod/dev/test environments. # # The function: -# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities--vs{ICN}-sn +# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities--vs-sn # 2. If not, checks for legacy instance-level password and migrates it # 3. If neither exists, generates a new secure alphanumeric password # 4. Stores password at customer level for reuse across all customer instances @@ -558,7 +558,7 @@ function manage_customer_mref_password() { echo "- Customer ICN: ${ICN}" # Define secret paths following customer-level secret pattern: ibm-customer/{ICN}/facilities/... - local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities--vs${ICN}-sn" + local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities--vs-sn" local LEGACY_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" local LEGACY_INSTANCE_SECRET_NAME="${ACCOUNT_ID}${SECRETS_KEY_SEPERATOR}${CLUSTER_ID}${SECRETS_KEY_SEPERATOR}${MAS_INSTANCE_ID}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" From c0f12a6c0b6df540fc57084846f1e4e1b4affd12 Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Tue, 8 Sep 2026 12:03:37 +0530 Subject: [PATCH 03/10] differentiating AWS and facilities vault secret --- image/cli/mascli/functions/gitops_suite_app_config | 5 +++-- image/cli/mascli/functions/gitops_utils | 4 ++-- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/image/cli/mascli/functions/gitops_suite_app_config b/image/cli/mascli/functions/gitops_suite_app_config index 0b6799f864..bbbb684d6e 100644 --- a/image/cli/mascli/functions/gitops_suite_app_config +++ b/image/cli/mascli/functions/gitops_suite_app_config @@ -425,7 +425,7 @@ function gitops_suite_app_config() { if [[ -n "${ICN}" ]]; then echo "✓ ICN successfully resolved: ${ICN}" echo " This ICN will be used for customer-level secrets:" - echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities--vs-sn" + echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities--vs${ICN}-sn" echo " - ibm-customer/${ICN}//..." else echo "⚠ WARNING: ICN not available - customer-level secrets cannot be used" @@ -642,6 +642,7 @@ function gitops_suite_app_config() { # No user-provided name - use customer-level default export FACILITIES_VAULT_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities--vs-sn" echo "- Using customer-level vault secret name: ${FACILITIES_VAULT_SECRET_NAME}" + local FACILITIES_AWS_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities--vs${ICN}-sn" # Ensure customer-level secret exists manage_customer_mref_password "${ICN}" "${ACCOUNT_ID}" "${CLUSTER_ID}" "${MAS_INSTANCE_ID}" "${MAS_WORKSPACE_ID}" "${SECRETS_KEY_SEPERATOR}" @@ -652,7 +653,7 @@ function gitops_suite_app_config() { fi # Verify vault secret exists - sm_verify_secret_exists "${FACILITIES_VAULT_SECRET}${SECRETS_KEY_SEPERATOR}${FACILITIES_VAULT_SECRET_NAME}" "password" + sm_verify_secret_exists "${FACILITIES_VAULT_SECRET}${SECRETS_KEY_SEPERATOR}${FACILITIES_AWS_SECRET_NAME:-${FACILITIES_VAULT_SECRET_NAME}}" "password" # Handle liberty extensions secret name if [[ -n "${USER_PROVIDED_LIBERTY_SECRET}" ]]; then diff --git a/image/cli/mascli/functions/gitops_utils b/image/cli/mascli/functions/gitops_utils index bf67428de8..57dd740c76 100644 --- a/image/cli/mascli/functions/gitops_utils +++ b/image/cli/mascli/functions/gitops_utils @@ -524,7 +524,7 @@ function sm_get_secret_arn() { # This prevents backflow issues when moving data between prod/dev/test environments. # # The function: -# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities--vs-sn +# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities--vs{ICN}-sn # 2. If not, checks for legacy instance-level password and migrates it # 3. If neither exists, generates a new secure alphanumeric password # 4. Stores password at customer level for reuse across all customer instances @@ -558,7 +558,7 @@ function manage_customer_mref_password() { echo "- Customer ICN: ${ICN}" # Define secret paths following customer-level secret pattern: ibm-customer/{ICN}/facilities/... - local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities--vs-sn" + local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities--vs${ICN}-sn" local LEGACY_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" local LEGACY_INSTANCE_SECRET_NAME="${ACCOUNT_ID}${SECRETS_KEY_SEPERATOR}${CLUSTER_ID}${SECRETS_KEY_SEPERATOR}${MAS_INSTANCE_ID}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" From 6cc4010fa65ef2ddaa9b6fd37da0ff4a9b23cc45 Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Wed, 9 Sep 2026 14:58:36 +0530 Subject: [PATCH 04/10] renamed secrets --- image/cli/mascli/functions/gitops_suite_app_config | 4 ++-- image/cli/mascli/functions/gitops_utils | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/image/cli/mascli/functions/gitops_suite_app_config b/image/cli/mascli/functions/gitops_suite_app_config index bbbb684d6e..92d3b0495d 100644 --- a/image/cli/mascli/functions/gitops_suite_app_config +++ b/image/cli/mascli/functions/gitops_suite_app_config @@ -425,7 +425,7 @@ function gitops_suite_app_config() { if [[ -n "${ICN}" ]]; then echo "✓ ICN successfully resolved: ${ICN}" echo " This ICN will be used for customer-level secrets:" - echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities--vs${ICN}-sn" + echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities--vs-sn" echo " - ibm-customer/${ICN}//..." else echo "⚠ WARNING: ICN not available - customer-level secrets cannot be used" @@ -642,7 +642,7 @@ function gitops_suite_app_config() { # No user-provided name - use customer-level default export FACILITIES_VAULT_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities--vs-sn" echo "- Using customer-level vault secret name: ${FACILITIES_VAULT_SECRET_NAME}" - local FACILITIES_AWS_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities--vs${ICN}-sn" + local FACILITIES_AWS_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities--vs-sn" # Ensure customer-level secret exists manage_customer_mref_password "${ICN}" "${ACCOUNT_ID}" "${CLUSTER_ID}" "${MAS_INSTANCE_ID}" "${MAS_WORKSPACE_ID}" "${SECRETS_KEY_SEPERATOR}" diff --git a/image/cli/mascli/functions/gitops_utils b/image/cli/mascli/functions/gitops_utils index 57dd740c76..bf67428de8 100644 --- a/image/cli/mascli/functions/gitops_utils +++ b/image/cli/mascli/functions/gitops_utils @@ -524,7 +524,7 @@ function sm_get_secret_arn() { # This prevents backflow issues when moving data between prod/dev/test environments. # # The function: -# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities--vs{ICN}-sn +# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities--vs-sn # 2. If not, checks for legacy instance-level password and migrates it # 3. If neither exists, generates a new secure alphanumeric password # 4. Stores password at customer level for reuse across all customer instances @@ -558,7 +558,7 @@ function manage_customer_mref_password() { echo "- Customer ICN: ${ICN}" # Define secret paths following customer-level secret pattern: ibm-customer/{ICN}/facilities/... - local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities--vs${ICN}-sn" + local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities--vs-sn" local LEGACY_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" local LEGACY_INSTANCE_SECRET_NAME="${ACCOUNT_ID}${SECRETS_KEY_SEPERATOR}${CLUSTER_ID}${SECRETS_KEY_SEPERATOR}${MAS_INSTANCE_ID}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" From 8d568466073e1e5e49f576bcb365fad49de4ce91 Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Thu, 17 Sep 2026 11:43:53 +0530 Subject: [PATCH 05/10] fixed secret typo --- image/cli/mascli/functions/gitops_suite_app_config | 6 +++--- image/cli/mascli/functions/gitops_utils | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/image/cli/mascli/functions/gitops_suite_app_config b/image/cli/mascli/functions/gitops_suite_app_config index 92d3b0495d..f6a40bf00e 100644 --- a/image/cli/mascli/functions/gitops_suite_app_config +++ b/image/cli/mascli/functions/gitops_suite_app_config @@ -425,7 +425,7 @@ function gitops_suite_app_config() { if [[ -n "${ICN}" ]]; then echo "✓ ICN successfully resolved: ${ICN}" echo " This ICN will be used for customer-level secrets:" - echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities--vs-sn" + echo " - ibm-customer/${ICN}/facilities/{workspace_id}-facilities-vs--sn" echo " - ibm-customer/${ICN}//..." else echo "⚠ WARNING: ICN not available - customer-level secrets cannot be used" @@ -640,9 +640,9 @@ function gitops_suite_app_config() { echo "- Verifying user-provided secret exists..." else # No user-provided name - use customer-level default - export FACILITIES_VAULT_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities--vs-sn" + export FACILITIES_VAULT_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities-vs--sn" echo "- Using customer-level vault secret name: ${FACILITIES_VAULT_SECRET_NAME}" - local FACILITIES_AWS_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities--vs-sn" + local FACILITIES_AWS_SECRET_NAME="${MAS_WORKSPACE_ID}-facilities-vs--sn" # Ensure customer-level secret exists manage_customer_mref_password "${ICN}" "${ACCOUNT_ID}" "${CLUSTER_ID}" "${MAS_INSTANCE_ID}" "${MAS_WORKSPACE_ID}" "${SECRETS_KEY_SEPERATOR}" diff --git a/image/cli/mascli/functions/gitops_utils b/image/cli/mascli/functions/gitops_utils index bf67428de8..1d504fdd6b 100644 --- a/image/cli/mascli/functions/gitops_utils +++ b/image/cli/mascli/functions/gitops_utils @@ -524,7 +524,7 @@ function sm_get_secret_arn() { # This prevents backflow issues when moving data between prod/dev/test environments. # # The function: -# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities--vs-sn +# 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities-vs--sn # 2. If not, checks for legacy instance-level password and migrates it # 3. If neither exists, generates a new secure alphanumeric password # 4. Stores password at customer level for reuse across all customer instances @@ -558,7 +558,7 @@ function manage_customer_mref_password() { echo "- Customer ICN: ${ICN}" # Define secret paths following customer-level secret pattern: ibm-customer/{ICN}/facilities/... - local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities--vs-sn" + local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities-vs--sn" local LEGACY_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" local LEGACY_INSTANCE_SECRET_NAME="${ACCOUNT_ID}${SECRETS_KEY_SEPERATOR}${CLUSTER_ID}${SECRETS_KEY_SEPERATOR}${MAS_INSTANCE_ID}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" From a7dd8dec4e09c948e04b7cbd888b7a395c0a4917 Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Thu, 17 Sep 2026 14:27:32 +0530 Subject: [PATCH 06/10] facilities expects pwd instead of password --- image/cli/mascli/functions/gitops_suite_app_config | 2 +- image/cli/mascli/functions/gitops_utils | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/image/cli/mascli/functions/gitops_suite_app_config b/image/cli/mascli/functions/gitops_suite_app_config index f6a40bf00e..f726095a89 100644 --- a/image/cli/mascli/functions/gitops_suite_app_config +++ b/image/cli/mascli/functions/gitops_suite_app_config @@ -653,7 +653,7 @@ function gitops_suite_app_config() { fi # Verify vault secret exists - sm_verify_secret_exists "${FACILITIES_VAULT_SECRET}${SECRETS_KEY_SEPERATOR}${FACILITIES_AWS_SECRET_NAME:-${FACILITIES_VAULT_SECRET_NAME}}" "password" + sm_verify_secret_exists "${FACILITIES_VAULT_SECRET}${SECRETS_KEY_SEPERATOR}${FACILITIES_AWS_SECRET_NAME:-${FACILITIES_VAULT_SECRET_NAME}}" "pwd" # Handle liberty extensions secret name if [[ -n "${USER_PROVIDED_LIBERTY_SECRET}" ]]; then diff --git a/image/cli/mascli/functions/gitops_utils b/image/cli/mascli/functions/gitops_utils index 1d504fdd6b..ae5658b710 100644 --- a/image/cli/mascli/functions/gitops_utils +++ b/image/cli/mascli/functions/gitops_utils @@ -565,7 +565,7 @@ function manage_customer_mref_password() { # Check if customer-level secret exists echo "- Checking for customer-level secret: ${CUSTOMER_SECRET_NAME}" set +o pipefail - local MREF_PASSWORD=$(sm_get_secret_value "${CUSTOMER_SECRET_NAME}" "password" 2>/dev/null) + local MREF_PASSWORD=$(sm_get_secret_value "${CUSTOMER_SECRET_NAME}" "pwd" 2>/dev/null) set -o pipefail if [[ -n "${MREF_PASSWORD}" ]] && [[ "${MREF_PASSWORD}" != "null" ]]; then @@ -615,7 +615,7 @@ function manage_customer_mref_password() { echo "- Storing password at customer level: ${CUSTOMER_SECRET_NAME}" local TAGS="[{\"Key\": \"source\", \"Value\": \"gitops_suite_app_config\"}, {\"Key\": \"icn\", \"Value\": \"${ICN}\"}, {\"Key\": \"type\", \"Value\": \"customer-level\"}, {\"Key\": \"purpose\", \"Value\": \"mref-aes-keystore\"}, {\"Key\": \"note\", \"Value\": \"${MIGRATION_NOTE}\"}]" - sm_update_secret "${CUSTOMER_SECRET_NAME}" "{\"password\": \"${MREF_PASSWORD}\"}" "${TAGS}" + sm_update_secret "${CUSTOMER_SECRET_NAME}" "{\"pwd\": \"${MREF_PASSWORD}\"}" "${TAGS}" if [[ $? -eq 0 ]]; then echo "- Customer-level MREF password successfully stored" From 98a6e77349991fe5f67ab4884eb13bbaf350fbaa Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Thu, 17 Sep 2026 15:43:11 +0530 Subject: [PATCH 07/10] facilities expects pwd instead of password --- .../cluster/instance/masapp/ibm-mas-masapp-config.yaml.j2 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image/cli/mascli/templates/gitops/appset-configs/cluster/instance/masapp/ibm-mas-masapp-config.yaml.j2 b/image/cli/mascli/templates/gitops/appset-configs/cluster/instance/masapp/ibm-mas-masapp-config.yaml.j2 index 0b1c304544..d78c9a5d87 100644 --- a/image/cli/mascli/templates/gitops/appset-configs/cluster/instance/masapp/ibm-mas-masapp-config.yaml.j2 +++ b/image/cli/mascli/templates/gitops/appset-configs/cluster/instance/masapp/ibm-mas-masapp-config.yaml.j2 @@ -34,7 +34,7 @@ manage_update_schedule: {{ MANAGE_UPDATE_SCHEDULE }} {%- if FACILITIES_VAULT_SECRET_NAME is defined and FACILITIES_VAULT_SECRET_NAME !='' %} facilities_vault_secret_name: {{ FACILITIES_VAULT_SECRET_NAME }} -facilities_vault_secret_value: +facilities_vault_secret_value: {%- endif %} {%- if FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME is defined and FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME !='' %} facilities_liberty_extensions_secret_name: {{ FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME }} From 4a14f9673a80d1224a7e09383e83b85dc49307da Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Fri, 18 Sep 2026 10:46:32 +0530 Subject: [PATCH 08/10] upgraded FACILITIES_LIBERTY_EXTENSIONS_SECRET to instance level --- image/cli/mascli/functions/gitops_suite_app_config | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/image/cli/mascli/functions/gitops_suite_app_config b/image/cli/mascli/functions/gitops_suite_app_config index f726095a89..2f447a3d49 100644 --- a/image/cli/mascli/functions/gitops_suite_app_config +++ b/image/cli/mascli/functions/gitops_suite_app_config @@ -626,7 +626,7 @@ function gitops_suite_app_config() { # Set customer-level secret path (without trailing separator) export FACILITIES_VAULT_SECRET="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities" - export FACILITIES_LIBERTY_EXTENSIONS_SECRET="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities" + export FACILITIES_LIBERTY_EXTENSIONS_SECRET="${ACCOUNT_ID}${SECRETS_KEY_SEPERATOR}${CLUSTER_ID}${SECRETS_KEY_SEPERATOR}${MAS_INSTANCE_ID}${SECRETS_KEY_SEPERATOR}facilities" # Get user-provided secret name from app spec (if any) USER_PROVIDED_VAULT_SECRET=$(yq eval '.mas_appws_spec.settings.vaultSecret.secretName // ""' ${MAS_APPWS_SPEC_YAML_RESOLVED}) From be575cbb515104c9a4a71ceb8dd4c258cc71f5f8 Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Fri, 18 Sep 2026 16:17:01 +0530 Subject: [PATCH 09/10] removed both customer and instance level legacy secret checks --- .secrets.baseline | 4 +- image/cli/mascli/functions/gitops_utils | 60 +++++++------------------ 2 files changed, 18 insertions(+), 46 deletions(-) diff --git a/.secrets.baseline b/.secrets.baseline index b241845d4d..e8084899b0 100644 --- a/.secrets.baseline +++ b/.secrets.baseline @@ -3,7 +3,7 @@ "files": "build/bin/config/oscap/ssg-rhel9-ds.xml|^.secrets.baseline$|^docs/catalogs/", "lines": null }, - "generated_at": "2026-08-26T10:10:54Z", + "generated_at": "2026-09-18T10:45:58Z", "plugins_used": [ { "name": "AWSKeyDetector" @@ -550,7 +550,7 @@ "hashed_secret": "effb7852555adce89885fb075fb43a77a1e0e77e", "is_secret": false, "is_verified": false, - "line_number": 1386, + "line_number": 1358, "type": "Secret Keyword", "verified_result": null } diff --git a/image/cli/mascli/functions/gitops_utils b/image/cli/mascli/functions/gitops_utils index ae5658b710..5696a3cf74 100644 --- a/image/cli/mascli/functions/gitops_utils +++ b/image/cli/mascli/functions/gitops_utils @@ -525,9 +525,8 @@ function sm_get_secret_arn() { # # The function: # 1. Checks if customer-level password exists at ibm-customer/{ICN}/facilities/{MAS_WORKSPACE_ID}-facilities-vs--sn -# 2. If not, checks for legacy instance-level password and migrates it -# 3. If neither exists, generates a new secure alphanumeric password -# 4. Stores password at customer level for reuse across all customer instances +# 2. If not, generates a new secure alphanumeric password +# 3. Stores password at customer level for reuse across all customer instances # # Args: # $1 - ICN (IBM Customer Number) @@ -557,59 +556,32 @@ function manage_customer_mref_password() { echo_h2 "Managing Customer-Level MREF AES Keystore Password" echo "- Customer ICN: ${ICN}" - # Define secret paths following customer-level secret pattern: ibm-customer/{ICN}/facilities/... + # Define secret path following customer-level secret pattern: ibm-customer/{ICN}/facilities/... local CUSTOMER_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}${MAS_WORKSPACE_ID}-facilities-vs--sn" - local LEGACY_SECRET_NAME="ibm-customer${SECRETS_KEY_SEPERATOR}${ICN}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" - local LEGACY_INSTANCE_SECRET_NAME="${ACCOUNT_ID}${SECRETS_KEY_SEPERATOR}${CLUSTER_ID}${SECRETS_KEY_SEPERATOR}${MAS_INSTANCE_ID}${SECRETS_KEY_SEPERATOR}facilities${SECRETS_KEY_SEPERATOR}manage-mref-keystore-password" - + # Check if customer-level secret exists echo "- Checking for customer-level secret: ${CUSTOMER_SECRET_NAME}" set +o pipefail local MREF_PASSWORD=$(sm_get_secret_value "${CUSTOMER_SECRET_NAME}" "pwd" 2>/dev/null) set -o pipefail - + if [[ -n "${MREF_PASSWORD}" ]] && [[ "${MREF_PASSWORD}" != "null" ]]; then echo "- Customer-level MREF password found, reusing existing password" return 0 fi - - # Customer-level secret not found, check for legacy customer-level secret (manage-mref-keystore-password) - echo "- Customer-level secret not found, checking for legacy customer-level secret" - echo "- Checking: ${LEGACY_SECRET_NAME}" - set +o pipefail - local LEGACY_PASSWORD=$(sm_get_secret_value "${LEGACY_SECRET_NAME}" "password" 2>/dev/null) - set -o pipefail - - if [[ -n "${LEGACY_PASSWORD}" ]] && [[ "${LEGACY_PASSWORD}" != "null" ]]; then - echo "- Legacy customer-level password found, migrating to new customer-level secret" - MREF_PASSWORD="${LEGACY_PASSWORD}" - local MIGRATION_NOTE="Migrated from legacy customer-level secret: ${LEGACY_SECRET_NAME}" - else - # Legacy customer-level not found, check legacy instance-level secret - echo "- Legacy customer-level secret not found, checking for legacy instance-level secret" - echo "- Checking: ${LEGACY_INSTANCE_SECRET_NAME}" - set +o pipefail - local LEGACY_INSTANCE_PASSWORD=$(sm_get_secret_value "${LEGACY_INSTANCE_SECRET_NAME}" "password" 2>/dev/null) - set -o pipefail - if [[ -n "${LEGACY_INSTANCE_PASSWORD}" ]] && [[ "${LEGACY_INSTANCE_PASSWORD}" != "null" ]]; then - echo "- Legacy instance-level password found, migrating to customer level" - MREF_PASSWORD="${LEGACY_INSTANCE_PASSWORD}" - local MIGRATION_NOTE="Migrated from instance-level secret: ${LEGACY_INSTANCE_SECRET_NAME}" - else - echo "- No existing password found, generating new secure password" - # Generate secure alphanumeric password (no special characters to avoid escaping issues) - # Use a loop to ensure we get exactly 32 characters after filtering - while true; do - MREF_PASSWORD=$(cat /dev/urandom | tr -dc 'a-zA-Z0-9' | head -c 64) #pragma: allowlist secret - if [[ ${#MREF_PASSWORD} -ge 32 ]]; then - MREF_PASSWORD=${MREF_PASSWORD:0:32} #pragma: allowlist secret - break - fi - done - local MIGRATION_NOTE="Generated for first deployment" + # Secret not found, generate new secure password + echo "- No existing password found, generating new secure password" + # Generate secure alphanumeric password (no special characters to avoid escaping issues) + # Use a loop to ensure we get exactly 32 characters after filtering + while true; do + MREF_PASSWORD=$(cat /dev/urandom | tr -dc 'a-zA-Z0-9' | head -c 64) #pragma: allowlist secret + if [[ ${#MREF_PASSWORD} -ge 32 ]]; then + MREF_PASSWORD=${MREF_PASSWORD:0:32} #pragma: allowlist secret + break fi - fi + done + local MIGRATION_NOTE="Generated for first deployment" # Store password at customer level echo "- Storing password at customer level: ${CUSTOMER_SECRET_NAME}" From b967e13afa4207e33edcaaa41afebff194b1c048 Mon Sep 17 00:00:00 2001 From: Adit Yarra Date: Fri, 18 Sep 2026 18:09:04 +0530 Subject: [PATCH 10/10] restored liberty extensions validation --- image/cli/mascli/functions/gitops_suite_app_config | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/image/cli/mascli/functions/gitops_suite_app_config b/image/cli/mascli/functions/gitops_suite_app_config index 2f447a3d49..3da428a28b 100644 --- a/image/cli/mascli/functions/gitops_suite_app_config +++ b/image/cli/mascli/functions/gitops_suite_app_config @@ -630,7 +630,6 @@ function gitops_suite_app_config() { # Get user-provided secret name from app spec (if any) USER_PROVIDED_VAULT_SECRET=$(yq eval '.mas_appws_spec.settings.vaultSecret.secretName // ""' ${MAS_APPWS_SPEC_YAML_RESOLVED}) - USER_PROVIDED_LIBERTY_SECRET=$(yq eval '.mas_appws_spec.settings.libertyExtensionXML.secretName // ""' ${MAS_APPWS_SPEC_YAML_RESOLVED}) # Handle vault secret name if [[ -n "${USER_PROVIDED_VAULT_SECRET}" ]]; then @@ -656,10 +655,13 @@ function gitops_suite_app_config() { sm_verify_secret_exists "${FACILITIES_VAULT_SECRET}${SECRETS_KEY_SEPERATOR}${FACILITIES_AWS_SECRET_NAME:-${FACILITIES_VAULT_SECRET_NAME}}" "pwd" # Handle liberty extensions secret name - if [[ -n "${USER_PROVIDED_LIBERTY_SECRET}" ]]; then - export FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME="${USER_PROVIDED_LIBERTY_SECRET}" - echo "- Using user-provided liberty extensions secret name: ${FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME}" - # Verify liberty secret exists + export FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME=$(yq eval '.mas_appws_spec.settings.libertyExtensionXML.secretName // ""' ${MAS_APPWS_SPEC_YAML_RESOLVED}) + if [[ -n "${FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME}" ]]; then + if [[ "${FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME}" != "${MAS_WORKSPACE_ID}-facilities-lexml--sn" ]]; then + echo "Error: Secret name ${FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME} does not match ${MAS_WORKSPACE_ID}-facilities-lexml--sn" + exit 1 + fi + echo "- Using liberty extensions secret name: ${FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME}" sm_verify_secret_exists "${FACILITIES_LIBERTY_EXTENSIONS_SECRET}${SECRETS_KEY_SEPERATOR}${FACILITIES_LIBERTY_EXTENSIONS_SECRET_NAME}" "b64_xml" fi fi # end if [[ "${MAS_APP_ID}" == "facilities" ]]