swarm-bao: grant the bootstrap token the queue's pki role, policy and login role
swarm-bao-nats-tls-policy acts with the bootstrap token, and main's module-eval-bao-grants now fails any such unit whose calls the policy file does not grant. Adds its three paths and counts it among the units the check must see.
This commit is contained in:
parent
1d261b3fed
commit
0081d75c86
2 changed files with 18 additions and 3 deletions
|
|
@ -760,7 +760,7 @@ let
|
|||
{
|
||||
# What makes the case above mean something: discovery by token path
|
||||
# reaches every unit that uses the token today, and each yields calls.
|
||||
name = "the bootstrap-policy check sees all eight units that use the token, and parses calls from each";
|
||||
name = "the bootstrap-policy check sees all nine units that use the token, and parses calls from each";
|
||||
ok =
|
||||
lib.all (n: bootstrapUnits ? ${n}) [
|
||||
"swarm-bao-controller-policy"
|
||||
|
|
@ -771,6 +771,7 @@ let
|
|||
"swarm-bao-grafana-oidc-policy"
|
||||
"swarm-bao-otel-oidc-policy"
|
||||
"swarm-bao-services-issuer-policy"
|
||||
"swarm-bao-nats-tls-policy"
|
||||
]
|
||||
&& lib.all (u: baoCalls u.script != [ ]) (lib.attrValues bootstrapUnits);
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue