swarm-bao: give the store forwarder's OIDC reader its own bao identity
`swarm-bao-forwarder-oidc` fetches the store container's collector secret, one path, and was the last reader still logging in with `deploy.bao.clientCertFile`: the hive's own leaf, whose policy reads every agent's credentials, the hive's tree and every service's OIDC secret. The four-way split gave grafana's and the swarm collector's readers leaves of their own and left this one behind. It now holds `forwarder-oidc.pem`, minted by `swarm-bao-pki`, and logs in under the `swarm-forwarder-oidc` cert-auth role, whose policy reads `secret/data/swarm/services/<store forwarder client id>/oidc/client` and nothing else. The role is written by `swarm-bao-forwarder-oidc-policy` from the bootstrap token, which gains the two grants that unit calls, and the reader is ordered after it. The subject is reserved as a hive name. A store host whose pair is null is refused at eval rather than falling back to the hive's leaf. The hive's own role and `client.pem` are untouched; nothing is revoked.
This commit is contained in:
parent
46d0b46670
commit
92e1909caf
9 changed files with 229 additions and 47 deletions
|
|
@ -76,6 +76,13 @@ let
|
|||
swarm.hives.otctl.domain = "o.t.local";
|
||||
};
|
||||
|
||||
# The store forwarder's OIDC reader, the fifth fixed subject.
|
||||
hiveNamedAfterForwarderOidcSubject = hive {
|
||||
deploy.swarm-otel.enable = false;
|
||||
deploy.bao.forwarderOidcCommonName = "fwctl";
|
||||
swarm.hives.fwctl.domain = "f.t.local";
|
||||
};
|
||||
|
||||
# 🩸 A different shape from every fixture above: the matrix-token and
|
||||
# queue-credential roles are written PER HIVE, so the subject a hive must not
|
||||
# be is `<prefix>-<some hive's name>` rather than the prefix itself. Reserving
|
||||
|
|
@ -157,6 +164,15 @@ let
|
|||
a: !a.assertion && lib.hasInfix "'otctl'" a.message
|
||||
) hiveNamedAfterOtelOidcSubject.assertions;
|
||||
}
|
||||
{
|
||||
# And the store forwarder's, for the same reason one element later.
|
||||
name = "a hive named after the store forwarder's OIDC-reader subject is refused too";
|
||||
ok =
|
||||
equalityGuardFired hiveNamedAfterForwarderOidcSubject
|
||||
&& lib.any (
|
||||
a: !a.assertion && lib.hasInfix "'fwctl'" a.message
|
||||
) hiveNamedAfterForwarderOidcSubject.assertions;
|
||||
}
|
||||
{
|
||||
# 🩸 The per-hive half, and the one a prefix-only reservation would miss:
|
||||
# the role is `<prefix>-<hive>`, so the reserved string has to be composed
|
||||
|
|
|
|||
Loading…
Reference in a new issue