Watch
0
0
Fork
You've already forked hyperhive
0

docs: fix vale prose-lint errors in bao UI docs
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped

Passive voice and sentence-initial 'So' hits from PR #4776's vale error job.
This commit is contained in:
atlas 2026-09-28 18:54:55 +02:00 • committed by mara
commit 3b27a2e5a1
2 changed files with 3 additions and 3 deletions

View file

@ -68,8 +68,8 @@ the store it's also at
`/var/lib/swarm-bao-services-pki/services-root.pem`. That's the file to
hand a browser, and reading it needs no store login — which matters,
because every store listener but the loopback UI one demands a client
certificate, and that one is gated behind authelia to the `admins`
group, not open to an anonymous browser fetching a trust anchor.
certificate, and authelia gates that one to the `admins` group, not
open to an anonymous browser fetching a trust anchor.
**The granting unit generates the root once, and never again.** It asks
the mount whether it already has an issuer (`bao list pki/issuers`)

View file

@ -438,7 +438,7 @@ proxies to an nginx inside the store's container on
a second openbao listener on `127.0.0.1:<deploy.bao.uiPort>`, answers 403 on
the unseal, seal, step-down, rekey and generate-root endpoints, and 404 on
everything else. ⚠️ That listener asks for **no client certificate**, because
a browser has none to present. So on this one door a bao token is the whole
a browser has none to present, so on this one door a bao token is the whole
credential. Anything on the store's host that can dial loopback, and any
`admins` session through the vhost, needs only a token to use the API. Unseal
from the host's `bao` CLI; the UI's unseal form gets a 403. On a self-signed