parent
bf81241744
commit
9545151b8d
10 changed files with 62 additions and 112 deletions
|
|
@ -53,19 +53,6 @@ wrapper carries an address, a CA and a client certificate but deliberately
|
|||
**no token**, so that read answers `403` whether or not the role exists. Read
|
||||
the unit's journal instead.
|
||||
|
||||
<details><summary>Upgrading a swarm set up with the older swarm-bootstrap policy</summary>
|
||||
|
||||
A store set up before the granter existed has every grant, but no `bao-granter`
|
||||
policy or role. After the deploy that introduces it, each `swarm-bao-*-policy`
|
||||
unit fails and logs the one-time step. Run the setup step as it stands. The
|
||||
old policy can go, with the root token again:
|
||||
|
||||
```bash
|
||||
bao policy delete swarm-bootstrap
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
### Residual risk
|
||||
|
||||
The granter is root-equivalent. It may write any `swarm-*` policy with any
|
||||
|
|
|
|||
Loading…
Reference in a new issue