Watch
0
0
Fork
You've already forked hyperhive
0

bao: disable the unused approle auth method, declaratively

No Rust ever minted a secret_id; approle was dead attack surface. The
bootstrap step's check-then-enable case becomes check-then-disable: if
approle is mounted, `bao auth disable approle`; otherwise a no-op.

Disabling costs `delete`+`sudo` on `sys/auth/approle`, not
`create`/`update` — verified against `bao auth disable -output-policy`
on a live dev store. The bootstrap policy grant is narrowed to match.

nix/module-eval/bao-grants.nix pins the new shape: the bootstrap policy
may disable approle, and the granter's role unit never enables it.
This commit is contained in:
atlas 2026-09-28 21:54:40 +02:00 • committed by mara
commit 433429ebfd
4 changed files with 41 additions and 11 deletions

View file

@ -2687,9 +2687,11 @@ in
*) bao auth enable cert ;;
esac
# Nothing mints a secret_id; disabled rather than left unmounted,
# since a store from before this change may already have it.
case "$mounted" in
*'"approle/"'*) ;;
*) bao auth enable approle ;;
*'"approle/"'*) bao auth disable approle ;;
*) ;;
esac
# The UI's OIDC login; `swarm-bao-operator-viewer-policy` writes its