bao: disable the unused approle auth method, declaratively
No Rust ever minted a secret_id; approle was dead attack surface. The bootstrap step's check-then-enable case becomes check-then-disable: if approle is mounted, `bao auth disable approle`; otherwise a no-op. Disabling costs `delete`+`sudo` on `sys/auth/approle`, not `create`/`update` — verified against `bao auth disable -output-policy` on a live dev store. The bootstrap policy grant is narrowed to match. nix/module-eval/bao-grants.nix pins the new shape: the bootstrap policy may disable approle, and the granter's role unit never enables it.
This commit is contained in:
parent
7bc4b25f16
commit
433429ebfd
4 changed files with 41 additions and 11 deletions
|
|
@ -2687,9 +2687,11 @@ in
|
|||
*) bao auth enable cert ;;
|
||||
esac
|
||||
|
||||
# Nothing mints a secret_id; disabled rather than left unmounted,
|
||||
# since a store from before this change may already have it.
|
||||
case "$mounted" in
|
||||
*'"approle/"'*) ;;
|
||||
*) bao auth enable approle ;;
|
||||
*'"approle/"'*) bao auth disable approle ;;
|
||||
*) ;;
|
||||
esac
|
||||
|
||||
# The UI's OIDC login; `swarm-bao-operator-viewer-policy` writes its
|
||||
|
|
|
|||
Loading…
Reference in a new issue