Skip to content

fix(security): fail closed when SPECTOR_MASTER_ENCRYPTION_KEY is unset outside dev/test (#1052) - #1082

Merged
sbharatjoshi merged 2 commits into
mainfrom
feat/1052-fail-closed-master-key
Oct 10, 2026
Merged

sbharatjoshi merged 2 commits into
mainfrom
feat/1052-fail-closed-master-key

Conversation

@jarvispectrayan

Copy link
Copy Markdown
Collaborator

Summary

Fixes #1052. Ensures that Spector fails closed at boot time when SPECTOR_MASTER_ENCRYPTION_KEY (or spector.security.master-key) is unset or blank in production environments (outside dev and test profiles), preventing the universal credentials vault and envelope encryption from operating with an insecure fallback key in production.

Changes

  • Error Taxonomy (ErrorCode.java):
    • Added error code MASTER_KEY_MISSING (SPE-820-002) with standard alias SPE-SEC-002.
    • Added alias mapping in ErrorCode.fromId("SPE-SEC-002").
  • Fail-Closed Enforcement (AesGcmCipher.java):
    • Injected Spring Environment to evaluate active profiles.
    • In production / default profiles without dev or test: aborts startup with IllegalStateException("[SPE-820-002 / SPE-SEC-002] Master encryption key is required outside dev/test profiles (set SPECTOR_MASTER_ENCRYPTION_KEY or spector.security.master-key)").
    • In dev profile: emits a prominent WARN banner alerting developers that the deterministic development key is active and insecure for production.
    • In test profile: permits fallback with a debug log to allow unit and integration test suites to execute without manual key management.
  • Configuration & Container Integration:
    • Added spector.security.master-key: ${SPECTOR_MASTER_ENCRYPTION_KEY:} under security: in application.yml.
    • Updated deploy/docker/entrypoint.sh to support /run/secrets/spector_master_encryption_key:SPECTOR_MASTER_ENCRYPTION_KEY.
  • Documentation:
    • Added Section 6 to docs/configuration/deployment-config.md documenting key generation (openssl rand -hex 32 / openssl rand -base64 32), secret injection methods, and rotation guidelines.
  • Testing & Verification:
    • Added unit test cases in AesGcmCipherTest.java verifying fail-closed behavior on missing keys in prod/default profiles, dev fallback, test fallback, and valid key operation.
    • Added Spring Boot contract integration tests in MasterEncryptionKeyFailClosedTest.java verifying ApplicationContextRunner fails fast under prod/default profiles and boots successfully under dev/test or when a key is provided.

Verification

  • mvn test -pl nucleus/spector-commons -Dtest=ErrorCodeTest (586/586 passed)
  • mvn test -pl synapse/spector-synapse -Dtest=AesGcmCipherTest,MasterEncryptionKeyFailClosedTest (16/16 passed)
  • mvn test -pl synapse/spector-synapse -Dtest=CredentialServiceTest,CredentialControllerTest,ConnectorDatabaseLifecycleIT (12/12 passed)
  • mvn license:check (100% compliant across all 29 modules)

— Forge (Maintainer)

…t outside dev/test (#1052)

- Add MASTER_KEY_MISSING (SPE-820-002 / SPE-SEC-002) error code to ErrorCode taxonomy
- Enforce fail-closed validation in AesGcmCipher outside dev and test profiles
- Log prominent WARN banner in dev profile when falling back to deterministic key
- Support spector_master_encryption_key in Docker secrets entrypoint loader
- Document master encryption key generation, injection, and rotation in deployment docs
- Add unit tests in AesGcmCipherTest and Spring Boot contract tests in MasterEncryptionKeyFailClosedTest

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
@jarvispectrayan
jarvispectrayan requested review from a team as code owners October 10, 2026 03:51
…ontexts (#1052)

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
@sbharatjoshi
sbharatjoshi merged commit 958eb27 into main Oct 10, 2026
21 checks passed
@sbharatjoshi
sbharatjoshi deleted the feat/1052-fail-closed-master-key branch October 10, 2026 04:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(security): fail closed when SPECTOR_MASTER_ENCRYPTION_KEY is unset outside dev profile

3 participants