bao: disable the unused approle auth method, declaratively
No Rust ever minted a secret_id; approle was dead attack surface. The bootstrap step's check-then-enable case becomes check-then-disable: if approle is mounted, `bao auth disable approle`; otherwise a no-op. Disabling costs `delete`+`sudo` on `sys/auth/approle`, not `create`/`update` — verified against `bao auth disable -output-policy` on a live dev store. The bootstrap policy grant is narrowed to match. nix/module-eval/bao-grants.nix pins the new shape: the bootstrap policy may disable approle, and the granter's role unit never enables it.
This commit is contained in:
parent
7bc4b25f16
commit
433429ebfd
4 changed files with 41 additions and 11 deletions
|
|
@ -112,8 +112,9 @@ The token file is `services.hyperhive.deploy.bao.bootstrapTokenFile`, which
|
|||
all-local names for you. On a store host that isn't all-local, set it and
|
||||
rebuild first.
|
||||
|
||||
`swarm-bao-granter-role` runs **on the host**. It enables the cert, approle
|
||||
and oidc auth methods, writes the `bao-granter` policy, and creates the
|
||||
`swarm-bao-granter-role` runs **on the host**. It enables the cert and oidc
|
||||
auth methods (and disables `approle` if an older store still has it mounted),
|
||||
writes the `bao-granter` policy, and creates the
|
||||
`bao-granter` role, which accepts the leaf
|
||||
`/var/lib/swarm-bao-pki/granter.pem`. Every
|
||||
`swarm-bao-*-policy` unit then logs in with that leaf. The controller's unit
|
||||
|
|
|
|||
Loading…
Reference in a new issue