swarm-bao: grant the bootstrap token the queue's pki role, policy and login role

swarm-bao-nats-tls-policy acts with the bootstrap token, and main's
module-eval-bao-grants now fails any such unit whose calls the policy
file does not grant. Adds its three paths and counts it among the units
the check must see.
This commit is contained in:
atlas 2026-09-24 16:31:49 +02:00 • committed by mara
commit 0081d75c86
2 changed files with 18 additions and 3 deletions

View file

@ -5,8 +5,8 @@
# Each stanza was derived with `bao <cmd> -output-policy`, which prints what a # Each stanza was derived with `bao <cmd> -output-policy`, which prints what a
# command requires without sending it. ../module-eval/bao-grants.nix reads # command requires without sending it. ../module-eval/bao-grants.nix reads
# this file and fails when a unit that uses the token calls a path it does not # this file and fails when a unit that uses the token calls a path it does not
# grant. The pki paths assume the default `servicesPkiMountPath` (`pki`) and # grant. The pki paths assume the default `servicesPkiMountPath` (`pki`),
# `servicesPkiRoleName` (`swarm-services`). # `servicesPkiRoleName` (`swarm-services`) and `natsPkiRoleName` (`swarm-nats`).
# swarm-bao-controller-policy: the controller's own policy and role. # swarm-bao-controller-policy: the controller's own policy and role.
path "sys/policies/acl/swarm-controller" { path "sys/policies/acl/swarm-controller" {
@ -116,6 +116,20 @@ path "auth/cert/certs/swarm-otel-oidc" {
capabilities = ["create", "update"] capabilities = ["create", "update"]
} }
# swarm-bao-nats-tls-policy: the queue's own pki role, beside
# `swarm-services` above, and its policy and login role.
path "pki/roles/swarm-nats" {
capabilities = ["create", "update"]
}
path "sys/policies/acl/swarm-nats" {
capabilities = ["create", "update"]
}
path "auth/cert/certs/swarm-nats" {
capabilities = ["create", "update"]
}
# swarm-bao-matrix-token-policy and swarm-bao-queue-agent-policy write one # swarm-bao-matrix-token-policy and swarm-bao-queue-agent-policy write one
# policy and role per hive, `<prefix>-<hive>`, so these two are globs. Each # policy and role per hive, `<prefix>-<hive>`, so these two are globs. Each
# stops at its own prefix. # stops at its own prefix.

View file

@ -760,7 +760,7 @@ let
{ {
# What makes the case above mean something: discovery by token path # What makes the case above mean something: discovery by token path
# reaches every unit that uses the token today, and each yields calls. # reaches every unit that uses the token today, and each yields calls.
name = "the bootstrap-policy check sees all eight units that use the token, and parses calls from each"; name = "the bootstrap-policy check sees all nine units that use the token, and parses calls from each";
ok = ok =
lib.all (n: bootstrapUnits ? ${n}) [ lib.all (n: bootstrapUnits ? ${n}) [
"swarm-bao-controller-policy" "swarm-bao-controller-policy"
@ -771,6 +771,7 @@ let
"swarm-bao-grafana-oidc-policy" "swarm-bao-grafana-oidc-policy"
"swarm-bao-otel-oidc-policy" "swarm-bao-otel-oidc-policy"
"swarm-bao-services-issuer-policy" "swarm-bao-services-issuer-policy"
"swarm-bao-nats-tls-policy"
] ]
&& lib.all (u: baoCalls u.script != [ ]) (lib.attrValues bootstrapUnits); && lib.all (u: baoCalls u.script != [ ]) (lib.attrValues bootstrapUnits);
} }