swarm-secret-client: give the store one namespace instead of one prefix
The crate had a single path convention and it was per-agent: `swarm/agents/<agent>/matrix/<account>`. The secrets still to move into the store do not fit it — one belongs to a hive, one to a swarm service, one to the controller itself — so each would have picked its own shape, and each would have been a separate grant to get wrong. mara ruled the scheme on the epic: `swarm/<kind>/<name>/<secret>`, over `agents`, `hives`, `services` and `controller`. This lands it. `Kind` is an enum rather than free strings for one reason: the store's grant is written in nix and cannot be reached from Rust, so a misspelled kind is a 403 at provision time and not a compile error. `Kind::ALL` lets a test enumerate the set instead of restating it, which is what makes adding a kind a deliberate edit rather than an accidental grant. Note `Kind` sits beside `checked_segment`'s existing `kind` argument, which means something else entirely — the label of the name being validated. They are not the same concept and should not be merged. Nothing about the rendered policy changes. `policy::render` still grants read on the agent kind alone; the other kinds are absent on purpose, because what a hive may read of its own kind is a boundary question and not a consequence of the namespace growing. The controller's write grant likewise stays scoped to `agents/` — it widens when a path outside it gains a writer, not when the kinds are declared. Verified: `cargo test -p swarm-secret-client` 23 passed, 0 failed. The two tests pinning the rendered strings (`the_document_grants_read_over_the_whole_agent_prefix` and matrix's path assertion) still assert the same literals they did before, which is what shows this is a faithful port rather than a reshape. `nix fmt` 710 emitted, 10 formatted, 0 changed; the three scripts/check-*.sh lints pass with the change staged. No reference to the removed `path::AGENT_PREFIX` survives in the crate or in nix — checked with a scoped pattern, because the unqualified name also belongs to hive-host-sock's container prefix and greps for it are answering a different question.
This commit is contained in:
parent
47d53f5c23
commit
2979fcf5d5
5 changed files with 135 additions and 19 deletions
|
|
@ -17,7 +17,7 @@
|
|||
|
||||
use crate::{
|
||||
Error,
|
||||
path::{AGENT_PREFIX, MOUNT, checked_segment},
|
||||
path::{Kind, MOUNT, ROOT, checked_segment},
|
||||
};
|
||||
|
||||
/// Namespace for a hive's own policy and cert-auth role.
|
||||
|
|
@ -45,9 +45,17 @@ pub fn hive_object_name(hive: &str) -> Result<String, Error> {
|
|||
/// object rather than derived state with a re-emission to get wrong.
|
||||
///
|
||||
/// Read-only: the controller mints these and never reads one back.
|
||||
/// ⚠️ Still the agent kind alone. The other kinds are deliberately absent: a
|
||||
/// hive has no business reading a service's or the controller's credentials,
|
||||
/// and what a hive may read of its *own* kind is a boundary question this
|
||||
/// module's header answers only for agents. Widening it is a decision, not a
|
||||
/// consequence of the namespace growing.
|
||||
#[must_use]
|
||||
pub fn render() -> String {
|
||||
format!("path \"{MOUNT}/data/{AGENT_PREFIX}/*\" {{\n capabilities = [\"read\"]\n}}\n")
|
||||
format!(
|
||||
"path \"{MOUNT}/data/{ROOT}/{}/*\" {{\n capabilities = [\"read\"]\n}}\n",
|
||||
Kind::Agent.as_str()
|
||||
)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
|
|
|
|||
Loading…
Reference in a new issue