bao: disable the unused approle auth method, declaratively
No Rust ever minted a secret_id; approle was dead attack surface. The bootstrap step's check-then-enable case becomes check-then-disable: if approle is mounted, `bao auth disable approle`; otherwise a no-op. Disabling costs `delete`+`sudo` on `sys/auth/approle`, not `create`/`update` — verified against `bao auth disable -output-policy` on a live dev store. The bootstrap policy grant is narrowed to match. nix/module-eval/bao-grants.nix pins the new shape: the bootstrap policy may disable approle, and the granter's role unit never enables it.
This commit is contained in:
parent
7bc4b25f16
commit
433429ebfd
4 changed files with 41 additions and 11 deletions
|
|
@ -14,7 +14,7 @@
|
|||
# not grant.
|
||||
|
||||
# The auth mounts. Reading `sys/auth` is how the unit checks, and `sudo` is
|
||||
# what enabling one costs.
|
||||
# what enabling or disabling one costs.
|
||||
path "sys/auth" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
|
@ -23,8 +23,11 @@ path "sys/auth/cert" {
|
|||
capabilities = ["create", "update", "sudo"]
|
||||
}
|
||||
|
||||
# Nothing mints an approle secret_id; the bootstrap step disables the mount
|
||||
# rather than enabling it. `delete` is what `bao auth disable` costs, not
|
||||
# `create`/`update` (verified with `bao auth disable -output-policy`).
|
||||
path "sys/auth/approle" {
|
||||
capabilities = ["create", "update", "sudo"]
|
||||
capabilities = ["delete", "sudo"]
|
||||
}
|
||||
|
||||
path "sys/auth/oidc" {
|
||||
|
|
|
|||
Loading…
Reference in a new issue