Skip to content

role nginx_location: ansure SRAM auth is active #403

Description

@dometto

Our nginx_location role supports the auth: sram option to configure SRAM auth via the REMOTE_USER header. We could check if this actually works by using ansible.builtin.get_url to get the <workspace_fqdn>/<configured_location_with_sram_auth> and seeing if we get the expected redirect or 403. This would make sure that accidental misconfigurations don't end up exposing a workspace without auth.

This could be either in addition to the require_src_nginx role check, or replace it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions