docs: fix vale prose-lint errors in bao UI docs
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Passive voice and sentence-initial 'So' hits from PR #4776's vale error job.
This commit is contained in:
parent
3898ca33c7
commit
3b27a2e5a1
2 changed files with 3 additions and 3 deletions
|
|
@ -68,8 +68,8 @@ the store it's also at
|
||||||
`/var/lib/swarm-bao-services-pki/services-root.pem`. That's the file to
|
`/var/lib/swarm-bao-services-pki/services-root.pem`. That's the file to
|
||||||
hand a browser, and reading it needs no store login — which matters,
|
hand a browser, and reading it needs no store login — which matters,
|
||||||
because every store listener but the loopback UI one demands a client
|
because every store listener but the loopback UI one demands a client
|
||||||
certificate, and that one is gated behind authelia to the `admins`
|
certificate, and authelia gates that one to the `admins` group, not
|
||||||
group, not open to an anonymous browser fetching a trust anchor.
|
open to an anonymous browser fetching a trust anchor.
|
||||||
|
|
||||||
**The granting unit generates the root once, and never again.** It asks
|
**The granting unit generates the root once, and never again.** It asks
|
||||||
the mount whether it already has an issuer (`bao list pki/issuers`)
|
the mount whether it already has an issuer (`bao list pki/issuers`)
|
||||||
|
|
|
||||||
|
|
@ -438,7 +438,7 @@ proxies to an nginx inside the store's container on
|
||||||
a second openbao listener on `127.0.0.1:<deploy.bao.uiPort>`, answers 403 on
|
a second openbao listener on `127.0.0.1:<deploy.bao.uiPort>`, answers 403 on
|
||||||
the unseal, seal, step-down, rekey and generate-root endpoints, and 404 on
|
the unseal, seal, step-down, rekey and generate-root endpoints, and 404 on
|
||||||
everything else. ⚠️ That listener asks for **no client certificate**, because
|
everything else. ⚠️ That listener asks for **no client certificate**, because
|
||||||
a browser has none to present. So on this one door a bao token is the whole
|
a browser has none to present, so on this one door a bao token is the whole
|
||||||
credential. Anything on the store's host that can dial loopback, and any
|
credential. Anything on the store's host that can dial loopback, and any
|
||||||
`admins` session through the vhost, needs only a token to use the API. Unseal
|
`admins` session through the vhost, needs only a token to use the API. Unseal
|
||||||
from the host's `bao` CLI; the UI's unseal form gets a 403. On a self-signed
|
from the host's `bao` CLI; the UI's unseal form gets a 403. On a self-signed
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue