swarm-bao: grant the agent PKI mount (for #4756)
#4756 moves agent client certificates onto a PKI mount of their own, `pki-agents`, whose root bao generates internally. The unit that sets that mount up runs as the bao granter, and the granter's policy is only written while #4754's one-time bootstrap token is in place. Adding these grants after an operator has done that step would cost a second token placement, so they go into the granter's policy here, before it. Six stanzas: enable and tune the mount, list its issuers, read its CA, generate its root internally, and write `swarm-*` roles on it. No root delete or sudo: agent cert-auth roles pin that root by value, so replacing it must not be something a deploy can do. Adds deploy.bao.agentPkiMountPath (default `pki-agents`), which the stanzas are rendered from. The module-eval case pinning the granter's policy now lists all seventeen stanzas, and the "grants nothing outside" case also refuses the agent mount's root, issue, sign and a roles/* glob.
This commit is contained in:
parent
e9cec0da21
commit
5cd7f866f4
2 changed files with 81 additions and 4 deletions
|
|
@ -820,7 +820,7 @@ let
|
|||
{
|
||||
# The granter's grants, whole. Pinned as the full list, because an added
|
||||
# path or capability is exactly what a presence check misses.
|
||||
name = "the granter's policy is exactly these eleven stanzas";
|
||||
name = "the granter's policy is exactly these seventeen stanzas";
|
||||
ok =
|
||||
let
|
||||
cu = [
|
||||
|
|
@ -876,6 +876,30 @@ let
|
|||
path = "pki/root/generate/internal";
|
||||
caps = cu;
|
||||
}
|
||||
{
|
||||
path = "sys/mounts/pki-agents";
|
||||
caps = cu;
|
||||
}
|
||||
{
|
||||
path = "sys/mounts/pki-agents/tune";
|
||||
caps = cu;
|
||||
}
|
||||
{
|
||||
path = "pki-agents/issuers";
|
||||
caps = [ "list" ];
|
||||
}
|
||||
{
|
||||
path = "pki-agents/cert/ca";
|
||||
caps = [ "read" ];
|
||||
}
|
||||
{
|
||||
path = "pki-agents/root/generate/internal";
|
||||
caps = cu;
|
||||
}
|
||||
{
|
||||
path = "pki-agents/roles/swarm-*";
|
||||
caps = cu;
|
||||
}
|
||||
];
|
||||
}
|
||||
{
|
||||
|
|
@ -908,6 +932,10 @@ let
|
|||
"sys/policies/acl/root"
|
||||
"pki/issue/swarm-services"
|
||||
"pki/sign/swarm-services"
|
||||
"pki-agents/root"
|
||||
"pki-agents/issue/swarm-agent"
|
||||
"pki-agents/sign/swarm-agent"
|
||||
"pki-agents/sign-verbatim"
|
||||
"*"
|
||||
]
|
||||
&& !(lib.any (
|
||||
|
|
@ -917,6 +945,7 @@ let
|
|||
"sys/policies/acl/*"
|
||||
"auth/cert/certs/*"
|
||||
"pki/roles/*"
|
||||
"pki-agents/roles/*"
|
||||
]
|
||||
) granterGrants);
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue