From 0081d75c86a67cd7d2e478f5fe874c96ee26afb5 Mon Sep 17 00:00:00 2001 From: atlas Date: Thu, 24 Sep 2026 16:31:49 +0200 Subject: [PATCH] swarm-bao: grant the bootstrap token the queue's pki role, policy and login role swarm-bao-nats-tls-policy acts with the bootstrap token, and main's module-eval-bao-grants now fails any such unit whose calls the policy file does not grant. Adds its three paths and counts it among the units the check must see. --- .../swarm-bao-bootstrap-policy.hcl | 18 ++++++++++++++++-- nix/module-eval/bao-grants.nix | 3 ++- 2 files changed, 18 insertions(+), 3 deletions(-) diff --git a/nix/host-modules/swarm-bao-bootstrap-policy.hcl b/nix/host-modules/swarm-bao-bootstrap-policy.hcl index 6c40ea7c..21674749 100644 --- a/nix/host-modules/swarm-bao-bootstrap-policy.hcl +++ b/nix/host-modules/swarm-bao-bootstrap-policy.hcl @@ -5,8 +5,8 @@ # Each stanza was derived with `bao -output-policy`, which prints what a # command requires without sending it. ../module-eval/bao-grants.nix reads # this file and fails when a unit that uses the token calls a path it does not -# grant. The pki paths assume the default `servicesPkiMountPath` (`pki`) and -# `servicesPkiRoleName` (`swarm-services`). +# grant. The pki paths assume the default `servicesPkiMountPath` (`pki`), +# `servicesPkiRoleName` (`swarm-services`) and `natsPkiRoleName` (`swarm-nats`). # swarm-bao-controller-policy: the controller's own policy and role. path "sys/policies/acl/swarm-controller" { @@ -116,6 +116,20 @@ path "auth/cert/certs/swarm-otel-oidc" { capabilities = ["create", "update"] } +# swarm-bao-nats-tls-policy: the queue's own pki role, beside +# `swarm-services` above, and its policy and login role. +path "pki/roles/swarm-nats" { + capabilities = ["create", "update"] +} + +path "sys/policies/acl/swarm-nats" { + capabilities = ["create", "update"] +} + +path "auth/cert/certs/swarm-nats" { + capabilities = ["create", "update"] +} + # swarm-bao-matrix-token-policy and swarm-bao-queue-agent-policy write one # policy and role per hive, `-`, so these two are globs. Each # stops at its own prefix. diff --git a/nix/module-eval/bao-grants.nix b/nix/module-eval/bao-grants.nix index 55c4381e..b014a23e 100644 --- a/nix/module-eval/bao-grants.nix +++ b/nix/module-eval/bao-grants.nix @@ -760,7 +760,7 @@ let { # What makes the case above mean something: discovery by token path # reaches every unit that uses the token today, and each yields calls. - name = "the bootstrap-policy check sees all eight units that use the token, and parses calls from each"; + name = "the bootstrap-policy check sees all nine units that use the token, and parses calls from each"; ok = lib.all (n: bootstrapUnits ? ${n}) [ "swarm-bao-controller-policy" @@ -771,6 +771,7 @@ let "swarm-bao-grafana-oidc-policy" "swarm-bao-otel-oidc-policy" "swarm-bao-services-issuer-policy" + "swarm-bao-nats-tls-policy" ] && lib.all (u: baoCalls u.script != [ ]) (lib.attrValues bootstrapUnits); }