swarm-bao: give the store forwarder's OIDC reader its own bao identity
`swarm-bao-forwarder-oidc` fetches the store container's collector secret, one path, and was the last reader still logging in with `deploy.bao.clientCertFile`: the hive's own leaf, whose policy reads every agent's credentials, the hive's tree and every service's OIDC secret. The four-way split gave grafana's and the swarm collector's readers leaves of their own and left this one behind. It now holds `forwarder-oidc.pem`, minted by `swarm-bao-pki`, and logs in under the `swarm-forwarder-oidc` cert-auth role, whose policy reads `secret/data/swarm/services/<store forwarder client id>/oidc/client` and nothing else. The role is written by `swarm-bao-forwarder-oidc-policy` from the bootstrap token, which gains the two grants that unit calls, and the reader is ordered after it. The subject is reserved as a hive name. A store host whose pair is null is refused at eval rather than falling back to the hive's leaf. The hive's own role and `client.pem` are untouched; nothing is revoked.
This commit is contained in:
parent
46d0b46670
commit
92e1909caf
9 changed files with 229 additions and 47 deletions
|
|
@ -103,6 +103,10 @@ in
|
|||
grafanaOidcClientKeyFile = lib.mkDefault "${pkiDir}/grafana-oidc-key.pem";
|
||||
otelOidcClientCertFile = lib.mkDefault "${pkiDir}/otel-oidc.pem";
|
||||
otelOidcClientKeyFile = lib.mkDefault "${pkiDir}/otel-oidc-key.pem";
|
||||
# The fifth, the store forwarder's: the reader the four-way split left
|
||||
# on `client.pem`.
|
||||
forwarderOidcClientCertFile = lib.mkDefault "${pkiDir}/forwarder-oidc.pem";
|
||||
forwarderOidcClientKeyFile = lib.mkDefault "${pkiDir}/forwarder-oidc-key.pem";
|
||||
};
|
||||
|
||||
# Idempotent on ABSENCE, never on content. Re-issuing the CA invalidates
|
||||
|
|
@ -219,6 +223,9 @@ in
|
|||
[ -s ${pkiDir}/otel-oidc.pem ] || ${signLeaf} ${pkiDir} otel-oidc \
|
||||
${lib.escapeShellArg deployCfg.bao.otelOidcCommonName} "" clientAuth
|
||||
|
||||
[ -s ${pkiDir}/forwarder-oidc.pem ] || ${signLeaf} ${pkiDir} forwarder-oidc \
|
||||
${lib.escapeShellArg deployCfg.bao.forwarderOidcCommonName} "" clientAuth
|
||||
|
||||
# The identity a hive presents to ask the store's `pki` mount for the
|
||||
# swarm-services certificate its gateway serves. Minted here like the
|
||||
# three above, and the reason is the sharpest of the four: this leaf
|
||||
|
|
|
|||
Loading…
Reference in a new issue