docs: fix vale prose-lint errors in bao UI docs
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Passive voice and sentence-initial 'So' hits from PR #4776's vale error job.
This commit is contained in:
parent
3898ca33c7
commit
3b27a2e5a1
2 changed files with 3 additions and 3 deletions
|
|
@ -68,8 +68,8 @@ the store it's also at
|
|||
`/var/lib/swarm-bao-services-pki/services-root.pem`. That's the file to
|
||||
hand a browser, and reading it needs no store login — which matters,
|
||||
because every store listener but the loopback UI one demands a client
|
||||
certificate, and that one is gated behind authelia to the `admins`
|
||||
group, not open to an anonymous browser fetching a trust anchor.
|
||||
certificate, and authelia gates that one to the `admins` group, not
|
||||
open to an anonymous browser fetching a trust anchor.
|
||||
|
||||
**The granting unit generates the root once, and never again.** It asks
|
||||
the mount whether it already has an issuer (`bao list pki/issuers`)
|
||||
|
|
|
|||
|
|
@ -438,7 +438,7 @@ proxies to an nginx inside the store's container on
|
|||
a second openbao listener on `127.0.0.1:<deploy.bao.uiPort>`, answers 403 on
|
||||
the unseal, seal, step-down, rekey and generate-root endpoints, and 404 on
|
||||
everything else. ⚠️ That listener asks for **no client certificate**, because
|
||||
a browser has none to present. So on this one door a bao token is the whole
|
||||
a browser has none to present, so on this one door a bao token is the whole
|
||||
credential. Anything on the store's host that can dial loopback, and any
|
||||
`admins` session through the vhost, needs only a token to use the API. Unseal
|
||||
from the host's `bao` CLI; the UI's unseal form gets a 403. On a self-signed
|
||||
|
|
|
|||
Loading…
Reference in a new issue