Summary
The bundle registration logic in .devcontainer/scripts/post-create.sh (lines 179-187) inserts new policy entries immediately before the targets: key rather than inside the policies: list. This places policy URLs in the wrong YAML section.
Problem
The awk block triggers on /^targets:/ and prints the new entry before the matched line. However, if the config has sections between policies: and targets: (e.g. complypacks:), the insertion lands outside the policies: list — either at the end of complypacks: or as a bare top-level entry.
awk -v name="${bundle_name}" '
/^targets:/ {
print " - url: http://localhost:8765/policies/" name
print " id: " name
}
{ print }
' "${CONFIG_FILE}" > "${CONFIG_FILE}.tmp"
Impact
- Mounted bundle policy URLs are parsed as complypack entries (wrong section)
complyctl get/generate for the mounted bundle ID fails silently
- Complypack sync may error on policy-shaped OCI artifacts
Expected Behavior
New policy entries should be inserted inside the policies: list block, not relative to the targets: key.
Location
.devcontainer/scripts/post-create.sh:179-187
Summary
The bundle registration logic in
.devcontainer/scripts/post-create.sh(lines 179-187) inserts new policy entries immediately before thetargets:key rather than inside thepolicies:list. This places policy URLs in the wrong YAML section.Problem
The awk block triggers on
/^targets:/and prints the new entry before the matched line. However, if the config has sections betweenpolicies:andtargets:(e.g.complypacks:), the insertion lands outside thepolicies:list — either at the end ofcomplypacks:or as a bare top-level entry.Impact
complyctl get/generatefor the mounted bundle ID fails silentlyExpected Behavior
New policy entries should be inserted inside the
policies:list block, not relative to thetargets:key.Location
.devcontainer/scripts/post-create.sh:179-187