From 3b27a2e5a130db24426378bf77bc28f90ae029f5 Mon Sep 17 00:00:00 2001 From: atlas Date: Mon, 28 Sep 2026 18:54:55 +0200 Subject: [PATCH] docs: fix vale prose-lint errors in bao UI docs Passive voice and sentence-initial 'So' hits from PR #4776's vale error job. --- docs/swarm/ca.md | 4 ++-- docs/swarm/secrets.md | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/docs/swarm/ca.md b/docs/swarm/ca.md index 2994f8ac..0a8f7094 100644 --- a/docs/swarm/ca.md +++ b/docs/swarm/ca.md @@ -68,8 +68,8 @@ the store it's also at `/var/lib/swarm-bao-services-pki/services-root.pem`. That's the file to hand a browser, and reading it needs no store login — which matters, because every store listener but the loopback UI one demands a client -certificate, and that one is gated behind authelia to the `admins` -group, not open to an anonymous browser fetching a trust anchor. +certificate, and authelia gates that one to the `admins` group, not +open to an anonymous browser fetching a trust anchor. **The granting unit generates the root once, and never again.** It asks the mount whether it already has an issuer (`bao list pki/issuers`) diff --git a/docs/swarm/secrets.md b/docs/swarm/secrets.md index 9760a5db..0bf5c896 100644 --- a/docs/swarm/secrets.md +++ b/docs/swarm/secrets.md @@ -438,7 +438,7 @@ proxies to an nginx inside the store's container on a second openbao listener on `127.0.0.1:`, answers 403 on the unseal, seal, step-down, rekey and generate-root endpoints, and 404 on everything else. ⚠️ That listener asks for **no client certificate**, because -a browser has none to present. So on this one door a bao token is the whole +a browser has none to present, so on this one door a bao token is the whole credential. Anything on the store's host that can dial loopback, and any `admins` session through the vhost, needs only a token to use the API. Unseal from the host's `bao` CLI; the UI's unseal form gets a 403. On a self-signed