swarm-bao: grant the agent PKI mount (for #4756)

#4756 moves agent client certificates onto a PKI mount of their own,
`pki-agents`, whose root bao generates internally. The unit that sets
that mount up runs as the bao granter, and the granter's policy is only
written while #4754's one-time bootstrap token is in place. Adding these
grants after an operator has done that step would cost a second token
placement, so they go into the granter's policy here, before it.

Six stanzas: enable and tune the mount, list its issuers, read its CA,
generate its root internally, and write `swarm-*` roles on it. No root
delete or sudo: agent cert-auth roles pin that root by value, so
replacing it must not be something a deploy can do.

Adds deploy.bao.agentPkiMountPath (default `pki-agents`), which the
stanzas are rendered from. The module-eval case pinning the granter's
policy now lists all seventeen stanzas, and the "grants nothing outside"
case also refuses the agent mount's root, issue, sign and a roles/*
glob.
This commit is contained in:
atlas 2026-09-27 17:54:35 +02:00 • committed by mara
commit 5cd7f866f4
2 changed files with 81 additions and 4 deletions

View file

@ -820,7 +820,7 @@ let
{
# The granter's grants, whole. Pinned as the full list, because an added
# path or capability is exactly what a presence check misses.
name = "the granter's policy is exactly these eleven stanzas";
name = "the granter's policy is exactly these seventeen stanzas";
ok =
let
cu = [
@ -876,6 +876,30 @@ let
path = "pki/root/generate/internal";
caps = cu;
}
{
path = "sys/mounts/pki-agents";
caps = cu;
}
{
path = "sys/mounts/pki-agents/tune";
caps = cu;
}
{
path = "pki-agents/issuers";
caps = [ "list" ];
}
{
path = "pki-agents/cert/ca";
caps = [ "read" ];
}
{
path = "pki-agents/root/generate/internal";
caps = cu;
}
{
path = "pki-agents/roles/swarm-*";
caps = cu;
}
];
}
{
@ -908,6 +932,10 @@ let
"sys/policies/acl/root"
"pki/issue/swarm-services"
"pki/sign/swarm-services"
"pki-agents/root"
"pki-agents/issue/swarm-agent"
"pki-agents/sign/swarm-agent"
"pki-agents/sign-verbatim"
"*"
]
&& !(lib.any (
@ -917,6 +945,7 @@ let
"sys/policies/acl/*"
"auth/cert/certs/*"
"pki/roles/*"
"pki-agents/roles/*"
]
) granterGrants);
}