Skip to content

feat(socket-auth): generate the socket auth key on install - #11

Open
roncodes wants to merge 3 commits into
mainfrom
feature/socket-auth
Open

roncodes wants to merge 3 commits into
mainfrom
feature/socket-auth

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

What

flb install-fleetbase now configures realtime socket authentication:

  • Generates SOCKETCLUSTER_AUTH_KEY with crypto.randomBytes(32) (64 hex chars) and writes it, together with SOCKETCLUSTER_AUTH_MODE=enforce, to the project-root .env (next to docker-compose.yml).
  • On re-run, an existing key of 32+ characters and an existing mode are kept (a shorter key is replaced with a warning). Other lines in .env are left untouched; the file is written with mode 600.
  • SOCKETCLUSTER_OPTIONS origins are still written to docker-compose.override.yml as before.
  • The post-install summary lists "Socket authentication (; key in .env)".
  • README documents the two variables.

Why

fleetbase/fleetbase#704 replaces the stock SocketCluster image with fleetbase/fleetbase-socket, which authenticates subscriptions using a secret shared with the API. Its docker-compose.yml passes ${SOCKETCLUSTER_AUTH_KEY:-} / ${SOCKETCLUSTER_AUTH_MODE:-} from the project .env to the application, queue, scheduler and socket containers, so the key must live there (setting it in api/.env has no effect). This mirrors what scripts/docker-install.sh does in that PR. Keeping the key across re-runs avoids invalidating socket tokens already issued.

Test plan

  • Verified by CI (this repo has no test suite).
  • Manual: fresh flb install-fleetbase --non-interactive creates .env with a 64-char key and enforce; re-running keeps the same key and mode; a pre-set SOCKETCLUSTER_AUTH_MODE=log is preserved.

Related PRs

Part of the authenticated realtime channels rollout (socket auth), one PR per repo:

flb install-fleetbase now writes SOCKETCLUSTER_AUTH_KEY (crypto.randomBytes, 64 hex
chars) and SOCKETCLUSTER_AUTH_MODE=enforce to the project-root .env, where
docker-compose.yml reads them for the application, queue, scheduler and socket
containers. An existing key (>= 32 chars) and mode are preserved on re-run.
SOCKETCLUSTER_OPTIONS origins are still written to docker-compose.override.yml.
…stalls

The API now gates socket auth (token routes, authorize endpoint, signed HTTP
publishing) behind SOCKETCLUSTER_AUTH_ENABLED, default false. With it off the
API publishes over the legacy websocket path, which a socket server in enforce
mode refuses. Fresh installs get true next to the key and mode; an existing
value is kept on re-run, with a warning when enforce is paired with a switch
that is not on. README documents the switch and the rollout order.
…ike docker-install.sh

fleetbase/fleetbase 044911e49 made the socket server honour
SOCKETCLUSTER_AUTH_ENABLED too, and scripts/docker-install.sh writes it false
with mode log, so released mobile apps and integrations that don't fetch socket
tokens keep working until the operator turns it on. Writing true + enforce from
the CLI would refuse those clients on day one. Use the same defaults (existing
values still kept) and report the state in the install summary. README: the
switch, what it gates, enforce needing it, and the rollout order.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant