Skip to content

fix(opencode): use supported ssl field for HSTS matching - #48

Merged
xnoto merged 1 commit into
mainfrom
fix/opencode-hsts-ssl-expression
Oct 5, 2026
Merged

xnoto merged 1 commit into
mainfrom
fix/opencode-hsts-ssl-expression

Conversation

@xnoto

@xnoto xnoto commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Correct the invalid HTTPS predicate introduced in #47. The owner requested this fix after apply attempt 2 failed with Cloudflare HTTP400/code20127: http.request.scheme is an unknown identifier.

One-line change in cf-opencode-hsts.tf: replace http.request.scheme eq "https" with ssl, retaining the exact hostname match. Cloudflare documents ssl as a Boolean that is true when the HTTP connection to the client is encrypted.

Type of change

  • Bug fix
  • Infrastructure (OpenTofu root or module)

Validation

  • Observed PR test and plan checks passed at 6c5e8d7536b27c9b981d4d6f7a0be4c64f568909: run 37247544593. Apply correctly skipped. Sanitized plan: 1 add, 0 change, 0 destroy, only the HSTS ruleset, with the corrected ssl predicate. No DNS updates proposed.
  • Generated or centrally distributed files were regenerated by their owning automation, not hand-edited — none changed; README resource inventory stays identical

Independent adversarial and infrastructure-security reviews of complete commit 6c5e8d7536b27c9b981d4d6f7a0be4c64f568909 found no Critical/High findings. QA review found the README/runbook remains consistent and needs no change; it explicitly identifies Cloudflare API acceptance and post-apply HTTPS/HTTP/sibling/phone behavior as uncovered by PR CI, not as completed tests. Those gates remain pending. The current Code Mode HTTP client follows redirects even with manual mode, so it cannot establish first-hop HTTP headers. Prior apply attempt 2 planned 1 add, 0 change, 0 destroy; DNS timestamp errors did not recur. This is historical evidence, not validation of this revision.

Important limit: the previous invalid expression passed OpenTofu planning. Passing new PR checks will not prove Cloudflare API acceptance or deployed HSTS. No local OpenTofu execution, live mutation, or authenticated test is part of this fix.

Impact and rollout

Producer: tfroot-cloudflare edge configuration. Sole consumer is the existing Cloudflare zone response-header phase. Native auth, existing HTTPS redirection, one-day max-age, no includeSubDomains/preload, Access deferral and sibling hostname scope are unchanged. No DNS/tunnel/AWX/provider pin change.

Shared workflow at a03d6b9 and images/tfroot-runner hook ownership at 2ac081d are unchanged. PR test/plan runs automatically; main merge triggers a fresh environment-associated apply, not a saved PR plan. Owner explicitly approved merge and automatic apply. Merged as 0b5b5517e94c43f4414060e986ded777f141c85b; main run 37247903691 completed successfully: main test and apply passed, plan job skipped as designed. Apply reported 1 added, 0 changed, 0 destroyed. No chart/image publication, GitOps selection/reconciliation, or workload restart is involved.

After approved apply, separately verify Cloudflare acceptance and HSTS on HTTPS UI and unauthenticated API responses, preserved API auth rejection, unchanged HTTP redirection and sibling-host behavior. Owner phone login/session continuity remains a separate functional check. Existing README rollback remains: serve max-age=0 over HTTPS before removing the rule; deleting a header alone does not clear cached policies. Reverting this correction would restore an invalid expression and is not a deployment rollback.

Safety and secrets

  • Contains no plaintext secrets, decrypted SOPS values, state files, kubeconfigs, tokens, or private endpoints
  • No local OpenTofu init/plan/apply/destroy/import/state operations were run or claimed — plans come from pull-request checks
  • Breaking or irreversible effects are described above with rollback notes

AI-authored correction and independent source reviews. The earlier field-name error was agent-authored; this correction uses the vendor field reference rather than inferring a field name.

Post-apply verification — 2026-10-05

Credentialless public checks confirmed Strict-Transport-Security: max-age=86400 on the OpenCode HTTPS UI (200) and /api/info (401 with the native Basic challenge). The HTTP probe followed a redirect to the HTTPS UI; first-hop HTTP headers are not observable with this client and are not claimed. Checked sibling hosts retained their prior statuses and no HSTS header. This establishes API acceptance and the checked public response behavior, not exhaustive sibling coverage or authenticated phone/session functionality. No credentials or cookies were retrieved. Phone login and existing-session continuity remain owner verification. No GitOps/workload rollout was required.

@xnoto
xnoto requested a review from a team as a code owner October 5, 2026 00:26
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

OpenTofu Test

OpenTofu test passed.

View the workflow run.

View run output
Terraform validate.......................................................Passed
Terraform validate with tflint...........................................Passed
Checkov..................................................................Passed
Terraform fmt............................................................Passed
Terraform docs...........................................................Passed
Detect hardcoded secrets.................................................Passed
check for case conflicts.................................................Passed
check for merge conflicts................................................Passed
check for broken symlinks............................(no files to check)Skipped
check vcs permalinks.....................................................Passed
detect destroyed symlinks................................................Passed
detect private key.......................................................Passed
fix end of files.........................................................Passed
mixed line ending........................................................Passed
trim trailing whitespace.................................................Passed
don't commit to branch..................................................Skipped
check for added large files..............................................Passed

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

OpenTofu Plan

OpenTofu plan passed.

View the workflow run.

View run output
OpenTofu will perform the following actions:

  # cloudflare_ruleset.response_headers will be created
  + resource "cloudflare_ruleset" "response_headers" {
      + description  = "Hostname-scoped response security headers"
      + id           = (known after apply)
      + kind         = "zone"
      + last_updated = (known after apply)
      + name         = "Response header transforms"
      + phase        = "http_response_headers_transform"
      + rules        = [
          + {
              + action            = "rewrite"
              + action_parameters = {
                  + headers = {
                      + "strict-transport-security" = {
                          + operation = "set"
                          + value     = "max-age=86400"
                        },
                    }
                }
              + description       = "One-day HSTS for the OpenCode HTTPS hostname only"
              + enabled           = true
              + expression        = "(http.host eq \"opencode.makeitwork.cloud\" and ssl)"
              + id                = (known after apply)
              + logging           = (known after apply)
              + ref               = "opencode_hsts"
            },
        ]
      + version      = (known after apply)
      + zone_id      = (sensitive value)
    }

Plan: 1 to add, 0 to change, 0 to destroy.
OpenTofu will perform the following actions:

  # cloudflare_ruleset.response_headers will be created
  + resource "cloudflare_ruleset" "response_headers" {
      + description  = "Hostname-scoped response security headers"
      + id           = (known after apply)
      + kind         = "zone"
      + last_updated = (known after apply)
      + name         = "Response header transforms"
      + phase        = "http_response_headers_transform"
      + rules        = [
          + {
              + action            = "rewrite"
              + action_parameters = {
                  + headers = {
                      + "strict-transport-security" = {
                          + operation = "set"
                          + value     = "max-age=86400"
                        },
                    }
                }
              + description       = "One-day HSTS for the OpenCode HTTPS hostname only"
              + enabled           = true
              + expression        = "(http.host eq \"opencode.makeitwork.cloud\" and ssl)"
              + id                = (known after apply)
              + logging           = (known after apply)
              + ref               = "opencode_hsts"
            },
        ]
      + version      = (known after apply)
      + zone_id      = (sensitive value)
    }

Plan: 1 to add, 0 to change, 0 to destroy.

@xnoto
xnoto merged commit 0b5b551 into main Oct 5, 2026
4 checks passed
@xnoto
xnoto deleted the fix/opencode-hsts-ssl-expression branch October 5, 2026 00:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant