Replace Unix socket admin API with authenticated HTTP admin API (ADR-028)
Remove src/admin/socket.rs and replace with Bearer token HTTP auth on the health check listener (port 9900). New src/admin/auth.rs provides SHA-256 key hashing with constant-time comparison; src/admin/handler.rs implements /admin/reload, /admin/status, and /admin/rotate-key. Admin endpoints return 404 when disabled (empty admin_key_path), 401 on bad auth. Config field renamed admin_socket_path → admin_key_path. Deployment files updated for key file mount instead of socket directory.
This commit is contained in:
1 parent
cfe0ae522d
commit
3ea3f56de7
19 files changed
+925
-908
No files matched your search
@@ -1,7 +1,7 @@
|
||||
---
|
||||
id: fix/admin-http-api
|
||||
name: Replace Unix domain socket admin API with authenticated HTTP admin API (ADR-028)
|
||||
status: pending
|
||||
status: completed
|
||||
depends_on: []
|
||||
scope: broad
|
||||
risk: high
|
||||
@@ -181,4 +181,10 @@ Bearer token authentication middleware.
|
||||
|
||||
## Summary
|
||||
|
||||
> To be filled on completion
|
||||
Replaced Unix domain socket admin API with authenticated HTTP admin API on the
|
||||
existing health check listener (port 9900). Bearer token auth with SHA-256 +
|
||||
constant-time comparison protects `/admin/reload`, `/admin/status`, and
|
||||
`/admin/rotate-key`. Admin disabled (empty `admin_key_path`) returns 404.
|
||||
Config field renamed `admin_socket_path` → `admin_key_path`. Deployment files
|
||||
updated for key file mount instead of socket directory. All 203 unit tests and
|
||||
37 integration tests pass; `cargo clippy` clean.
|
||||
Reference in new issue
Block a user