Add optional Neo4j GDS plugin installation (#1) - #3
Conversation
There was a problem hiding this comment.
Pull Request Overview
This PR adds optional support for installing the Neo4j Graph Data Science (GDS) plugin to enhance BloodHound CE functionality. The installation is enabled by default but can be disabled via an environment variable.
Key Changes
- Added automatic GDS plugin download and installation with SHA-256 checksum verification
- Introduced
INSTALL_GDSenvironment variable (defaults totrue) to control plugin installation - Updated documentation to explain the GDS plugin feature and how to disable it
Reviewed Changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 5 comments.
| File | Description |
|---|---|
| bloodhound-ce | Implements GDS plugin installation logic with download, verification, and Neo4j configuration |
| README.md | Documents the new GDS plugin feature and usage instructions |
Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.
| function install_gds_plugin() { | ||
| if [ "$INSTALL_GDS" = "true" ]; then | ||
| local PLUGINS_DIR="$NEO4J_VOL/plugins" | ||
| local GDS_VERSION="2.6.7" |
There was a problem hiding this comment.
[nitpick] The GDS version is hardcoded. Consider making this configurable via an environment variable (e.g., GDS_VERSION="${GDS_VERSION:-2.6.7}") to allow users to specify different versions without modifying the script.
| local GDS_VERSION="2.6.7" | |
| local GDS_VERSION="${GDS_VERSION:-2.6.7}" |
| local GDS_VERSION="2.6.7" | ||
| local GDS_JAR="neo4j-graph-data-science-${GDS_VERSION}.jar" | ||
| local GDS_URL="https://github.com/neo4j/graph-data-science/releases/download/${GDS_VERSION}/${GDS_JAR}" | ||
| local GDS_SHA256="ecdad4b1050f7727af1af76579344b792b4ea8e48102955bec0e99d7cb8a46e9" |
There was a problem hiding this comment.
The hardcoded SHA-256 checksum is tightly coupled to the hardcoded version. If the version becomes configurable, this checksum validation will fail for other versions. Consider either documenting this limitation or implementing a version-to-checksum mapping.
| local GDS_SHA256="ecdad4b1050f7727af1af76579344b792b4ea8e48102955bec0e99d7cb8a46e9" | |
| # Mapping of supported GDS versions to their SHA-256 checksums. | |
| # To add support for a new version, add a new entry below: | |
| declare -A GDS_SHA256_MAP=( | |
| ["2.6.7"]="ecdad4b1050f7727af1af76579344b792b4ea8e48102955bec0e99d7cb8a46e9" | |
| # Add more versions here as needed, e.g.: | |
| # ["2.7.0"]="sha256sum_for_2.7.0" | |
| ) | |
| local GDS_SHA256="${GDS_SHA256_MAP[$GDS_VERSION]}" | |
| if [ -z "$GDS_SHA256" ]; then | |
| echo -e "${RED}Error: No SHA-256 checksum known for GDS version $GDS_VERSION.${NC}" | |
| echo "Please update the script to add the checksum for this version." | |
| return 1 | |
| fi |
| } | ||
|
|
||
| run_postgres | ||
| install_gds_plugin |
There was a problem hiding this comment.
The install_gds_plugin function is called before run_neo4j, but it attempts to download files to $NEO4J_VOL/plugins which may not exist yet. If Neo4j has never run, this directory won't exist and the mkdir at line 103 may fail silently due to || true. Consider ensuring the base $NEO4J_VOL directory exists before attempting plugin installation, or handle the case where the directory creation fails more explicitly.
|
|
||
| # Try to download directly to plugins directory | ||
| # This works on first run before Neo4j takes ownership | ||
| if [ -w "$PLUGINS_DIR" ] || [ ! -e "$PLUGINS_DIR" ]; then |
There was a problem hiding this comment.
The condition [ ! -e \"$PLUGINS_DIR\" ] will be true even if the parent directory doesn't exist, leading to attempted downloads that will fail. This doesn't properly guard against the case where $NEO4J_VOL itself doesn't exist. The download will fail but the error handling may not clearly indicate the root cause.
| --publish 127.0.0.1:7474:7474 \ | ||
| --publish 127.0.0.1:7687:7687 \ | ||
| -e "NEO4J_AUTH=neo4j/bloodhoundcommunityedition" \ | ||
| -e "NEO4J_PLUGINS=[\"graph-data-science\"]" \ |
There was a problem hiding this comment.
The NEO4J_PLUGINS environment variable is set unconditionally, even when INSTALL_GDS=false. This will cause Neo4j to expect the GDS plugin but it won't be present, potentially causing errors. This environment variable should only be set when INSTALL_GDS=true.
I added an option to the old script to install the GDS plugin into neo4J. I don't know if it's useful for you but I share it anyway