hive-tls: renew the swarm-services leaf on a daily timer
The store's `swarm-services` role issues the services leaf for 720h, and `swarm-services-cert` only ever ran at boot or rebuild: it is a `RemainAfterExit` oneshot wanted by `multi-user.target` and no timer targeted it. A hive not rebuilt within 30 days served an expired leaf. `swarm-services-cert-renew` runs the same script from a daily timer. It is a unit of its own because a timer starting the `RemainAfterExit` unit is a no-op, and restarting that unit instead would propagate through `hive-gateway-self-signed-cert`'s `Requires=` to nginx, so a sealed store would take the gateway down over a still-valid leaf. Nothing requires or orders against the new unit; it has no `Restart=`, so a failure stays in `systemctl --failed` until the next tick, and the script only moves files into place after the store has answered. The re-issue threshold was `checkend 2592000`, the whole 30-day lifetime, so every run re-issued. It is now half the role's lifetime, read from a new internal option `deploy.bao.servicesPkiLeafTtlHours` that the role's `ttl`/`max_ttl` also read. Boot and timer share the script and so the threshold. The services-root re-check reads the same option, at the store's own replacement threshold (hours × 3600), so the hive asks for a new leaf when the store replaces its root. A `flock` keeps the two runs from interleaving one issuance's key with another's leaf. `checks.module-eval-hive-tls` pins the timer, that the unit it starts re-runs the issuance without `RemainAfterExit`, that nothing depends on it, and that both the leaf and root thresholds move with the option. Closes #4587
This commit is contained in:
parent
afde9f380f
commit
0649673ebf
5 changed files with 283 additions and 50 deletions
|
|
@ -376,8 +376,9 @@ let
|
|||
# compares the issuer's remaining life against this number, which it can
|
||||
# only do if this number exists. 720h matches
|
||||
# `deploy.hive-controller.tls.leafValidityDays`, the 30 days ./hive-tls.nix
|
||||
# documents for every other leaf it holds.
|
||||
servicesPkiLeafTtlHours = 720;
|
||||
# documents for every other leaf it holds. An option, read here and by
|
||||
# ./hive-tls.nix's renewal threshold, so the two cannot disagree.
|
||||
servicesPkiLeafTtlHours = baoDeploy.servicesPkiLeafTtlHours;
|
||||
servicesPkiLeafTtl = "${toString servicesPkiLeafTtlHours}h";
|
||||
servicesPkiLeafTtlSeconds = servicesPkiLeafTtlHours * 3600;
|
||||
|
||||
|
|
@ -1107,6 +1108,20 @@ in
|
|||
'';
|
||||
};
|
||||
|
||||
servicesPkiLeafTtlHours = lib.mkOption {
|
||||
type = lib.types.ints.positive;
|
||||
internal = true;
|
||||
default = 720;
|
||||
description = ''
|
||||
Lifetime, in hours, of a leaf issued through
|
||||
{option}`services.hyperhive.deploy.bao.servicesPkiRoleName`: the role's
|
||||
`ttl` and `max_ttl`. ./hive-tls.nix renews the swarm-services leaf at
|
||||
half of it, and a threshold spelled as its own number there drifts the
|
||||
day this one changes. Internal rather than read-only so a check can
|
||||
move it and see the threshold move too.
|
||||
'';
|
||||
};
|
||||
|
||||
servicesIssuerCommonName = lib.mkOption {
|
||||
type = lib.types.str;
|
||||
default = "swarm-services-issuer";
|
||||
|
|
|
|||
Loading…
Reference in a new issue