relay: remove it; gitea already speaks Hermes's protocol
The relay existed on the premise that Gitea sends no header Hermes can read
an event name from, so something had to copy X-Gitea-Event into
X-GitHub-Event. That premise was wrong. Gitea's addDefaultHeaders sets
req.Header["X-GitHub-Delivery"] = []string{t.UUID}
req.Header["X-GitHub-Event"] = []string{event}
req.Header["X-GitHub-Event-Type"] = []string{eventType}
unconditionally, for every webhook type, alongside X-Hub-Signature-256 in
GitHub's exact format. (Direct map assignment rather than .Add() specifically
to keep the "GitHub" casing that canonicalisation would destroy.) Hermes
validates that signature on any route without provider gating and reads the
event name from that header, so gitea and hermes already speak the same
protocol and the translation layer was translating nothing.
Gitea now posts straight at http://mars.orbit.sol:8644/webhooks/gitea-pr-comments.
The URL path is the Hermes route name, so a second subscription is a second
hook and nothing else -- the route-in-path indirection the relay grew was a
reimplementation of something Hermes already had.
Removes the module, the 200-line relay, its test, the mars import, the 8645
listener, and the stale gitea-hermes-webhook-relay.service entry left in the
secret's restartUnits. hermes-agent-webhook-route moves to
hosts/mars/hermes-agent.nix, next to the container and the read-only prompt
and filter mounts it depends on.
Also makes that unit refuse to subscribe when GITEA_HERMES_WEBHOOK_SECRET is
unset in the container, matching the existing empty-prompt check. An empty
secret silently fails every delivery signature check afterwards while the
unit still reports success -- the worst possible failure shape, and one this
setup can actually produce on a first deploy.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S94o42aQ8VkBmEWvDem5xa
This commit is contained in:
@@ -40,11 +40,12 @@
|
||||
# restart it on its own. Without this line the very first deploy leaves the
|
||||
# container holding an empty GITEA_HERMES_WEBHOOK_SECRET, and
|
||||
# hermes-agent-webhook-route (which reads it back out of the running
|
||||
# container) subscribes with an empty secret — every relayed delivery then
|
||||
# fails signature validation inside Hermes with no obvious cause.
|
||||
# container) subscribes with an empty secret — every delivery then fails
|
||||
# signature validation inside Hermes with no obvious cause. That unit now
|
||||
# refuses to subscribe on an unset secret rather than doing it quietly, but
|
||||
# the ordering here is still what makes the rotation correct.
|
||||
sops.secrets.gitea_hermes_webhook_secret = {
|
||||
restartUnits = [
|
||||
"gitea-hermes-webhook-relay.service"
|
||||
"podman-hermes-agent.service"
|
||||
"hermes-agent-webhook-route.service"
|
||||
];
|
||||
|
||||
Reference in New Issue
Block a user