diff --git a/nix/host-modules/swarm-bao-bootstrap-policy.hcl b/nix/host-modules/swarm-bao-bootstrap-policy.hcl index 6c40ea7c..21674749 100644 --- a/nix/host-modules/swarm-bao-bootstrap-policy.hcl +++ b/nix/host-modules/swarm-bao-bootstrap-policy.hcl @@ -5,8 +5,8 @@ # Each stanza was derived with `bao -output-policy`, which prints what a # command requires without sending it. ../module-eval/bao-grants.nix reads # this file and fails when a unit that uses the token calls a path it does not -# grant. The pki paths assume the default `servicesPkiMountPath` (`pki`) and -# `servicesPkiRoleName` (`swarm-services`). +# grant. The pki paths assume the default `servicesPkiMountPath` (`pki`), +# `servicesPkiRoleName` (`swarm-services`) and `natsPkiRoleName` (`swarm-nats`). # swarm-bao-controller-policy: the controller's own policy and role. path "sys/policies/acl/swarm-controller" { @@ -116,6 +116,20 @@ path "auth/cert/certs/swarm-otel-oidc" { capabilities = ["create", "update"] } +# swarm-bao-nats-tls-policy: the queue's own pki role, beside +# `swarm-services` above, and its policy and login role. +path "pki/roles/swarm-nats" { + capabilities = ["create", "update"] +} + +path "sys/policies/acl/swarm-nats" { + capabilities = ["create", "update"] +} + +path "auth/cert/certs/swarm-nats" { + capabilities = ["create", "update"] +} + # swarm-bao-matrix-token-policy and swarm-bao-queue-agent-policy write one # policy and role per hive, `-`, so these two are globs. Each # stops at its own prefix. diff --git a/nix/module-eval/bao-grants.nix b/nix/module-eval/bao-grants.nix index 55c4381e..b014a23e 100644 --- a/nix/module-eval/bao-grants.nix +++ b/nix/module-eval/bao-grants.nix @@ -760,7 +760,7 @@ let { # What makes the case above mean something: discovery by token path # reaches every unit that uses the token today, and each yields calls. - name = "the bootstrap-policy check sees all eight units that use the token, and parses calls from each"; + name = "the bootstrap-policy check sees all nine units that use the token, and parses calls from each"; ok = lib.all (n: bootstrapUnits ? ${n}) [ "swarm-bao-controller-policy" @@ -771,6 +771,7 @@ let "swarm-bao-grafana-oidc-policy" "swarm-bao-otel-oidc-policy" "swarm-bao-services-issuer-policy" + "swarm-bao-nats-tls-policy" ] && lib.all (u: baoCalls u.script != [ ]) (lib.attrValues bootstrapUnits); }