Skip to content

Add encrypted budget registry and management UI - #226

Merged
yoshifuminakamura merged 1 commit into
developfrom
feature/encrypted-budget-registry
Sep 28, 2026
Merged

yoshifuminakamura merged 1 commit into
developfrom
feature/encrypted-budget-registry

Conversation

@yoshifuminakamura

Copy link
Copy Markdown
Collaborator

Summary

  • Add an opt-in SQLCipher budget registry with explicit initialization, encrypted backup, and validation of storage permissions and schema compatibility.
  • Provide a Budget @ System management view with runner tags and selection of existing GitLab connections.
  • Separate CX administrator and assigned budget-manager permissions. Review shared changes before applying them, with revision checks, CSRF protection, and current identity validation.
  • Keep credential values outside the registry and restrict management routes to authenticated, authorized console access.

Validation

  • python result_server/tests/run_result_server_tests.py: 710 passed, with three existing deprecation warnings.
  • Add Python 3.12 and 3.13 CI coverage requiring SQLCipher for the storage and management-route tests.
  • Rebase onto current develop preserves the implementation unchanged.
  • Text integrity and diff checks passed.

Scope

  • Profile selection and pipeline submission are not yet connected to the registry.
  • Startup does not create or migrate databases. Existing databases are unchanged.
  • Encryption protects stored database contents without the key; it does not replace application authorization, process isolation, or separate recovery-key custody.
  • Key rotation and migration of populated legacy registries are not included.

Add opt-in SQLCipher storage, budget-manager administration, and shared execution settings with review-before-apply validation.

Reuse configured GitLab targets without duplicating connection details.

Signed-off-by: yoshifuminakamura <nakamura@riken.jp>
@yoshifuminakamura
yoshifuminakamura merged commit e2da9e5 into develop Sep 28, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant