Repository navigation
Conversation
flb install-fleetbase now writes SOCKETCLUSTER_AUTH_KEY (crypto.randomBytes, 64 hex chars) and SOCKETCLUSTER_AUTH_MODE=enforce to the project-root .env, where docker-compose.yml reads them for the application, queue, scheduler and socket containers. An existing key (>= 32 chars) and mode are preserved on re-run. SOCKETCLUSTER_OPTIONS origins are still written to docker-compose.override.yml.
This was referenced Oct 6, 2026
feat(socket-auth): show channel authorization failures in the sockets viewer
fleetbase/dev-engine#51
Open
Open
…stalls The API now gates socket auth (token routes, authorize endpoint, signed HTTP publishing) behind SOCKETCLUSTER_AUTH_ENABLED, default false. With it off the API publishes over the legacy websocket path, which a socket server in enforce mode refuses. Fresh installs get true next to the key and mode; an existing value is kept on re-run, with a warning when enforce is paired with a switch that is not on. README documents the switch and the rollout order.
…ike docker-install.sh fleetbase/fleetbase 044911e49 made the socket server honour SOCKETCLUSTER_AUTH_ENABLED too, and scripts/docker-install.sh writes it false with mode log, so released mobile apps and integrations that don't fetch socket tokens keep working until the operator turns it on. Writing true + enforce from the CLI would refuse those clients on day one. Use the same defaults (existing values still kept) and report the state in the install summary. README: the switch, what it gates, enforce needing it, and the rollout order.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
flb install-fleetbasenow configures realtime socket authentication:SOCKETCLUSTER_AUTH_KEYwithcrypto.randomBytes(32)(64 hex chars) and writes it, together withSOCKETCLUSTER_AUTH_MODE=enforce, to the project-root.env(next todocker-compose.yml)..envare left untouched; the file is written with mode 600.SOCKETCLUSTER_OPTIONSorigins are still written todocker-compose.override.ymlas before.Why
fleetbase/fleetbase#704 replaces the stock SocketCluster image with
fleetbase/fleetbase-socket, which authenticates subscriptions using a secret shared with the API. Itsdocker-compose.ymlpasses${SOCKETCLUSTER_AUTH_KEY:-}/${SOCKETCLUSTER_AUTH_MODE:-}from the project.envto the application, queue, scheduler and socket containers, so the key must live there (setting it inapi/.envhas no effect). This mirrors whatscripts/docker-install.shdoes in that PR. Keeping the key across re-runs avoids invalidating socket tokens already issued.Test plan
flb install-fleetbase --non-interactivecreates.envwith a 64-char key andenforce; re-running keeps the same key and mode; a pre-setSOCKETCLUSTER_AUTH_MODE=logis preserved.Related PRs
Part of the authenticated realtime channels rollout (socket auth), one PR per repo:
fleetbase/core-api ^1.6.69)fleetbase/fleetbase-socketserver, compose/helm/installer, console socket test page