docs: clear write-good.Passive hits in docs/swarm/sso.md
6 genuine passive-voice rewrites (actor named — the operator,
secrets.md, swarm-authelia.nix, the person who introduced the split,
swarmctl); 1 false positive left untouched — a quoted phrase +
predicate adjective ('presenting as "the forge is broken"').
This commit is contained in:
parent
f304fd3069
commit
c75604aa42
1 changed files with 15 additions and 13 deletions
|
|
@ -1,9 +1,9 @@
|
||||||
# Swarm SSO
|
# Swarm SSO
|
||||||
|
|
||||||
The swarm runs one authelia, and it's two things at once: the **session
|
The swarm runs one authelia, and it's two things at once: the **session
|
||||||
provider** every protected vhost checks (`auth_request`), and — once any
|
provider** every protected vhost checks (`auth_request`), and — once an
|
||||||
client is declared — an **OIDC provider** issuing tokens to relying
|
operator declares any client — an **OIDC provider** issuing tokens to
|
||||||
parties: the forge and the matrix homeserver.
|
relying parties: the forge and the matrix homeserver.
|
||||||
|
|
||||||
The second role derives rather than switches:
|
The second role derives rather than switches:
|
||||||
`services.hyperhive.swarm.authelia.oidc.clients` being non-empty turns it
|
`services.hyperhive.swarm.authelia.oidc.clients` being non-empty turns it
|
||||||
|
|
@ -28,7 +28,7 @@ error reading the authentication database: could not validate the schema:
|
||||||
users: non zero value required
|
users: non zero value required
|
||||||
```
|
```
|
||||||
|
|
||||||
It then exits 1 and systemd restarts it, so a swarm that has been
|
It then exits 1 and systemd restarts it, so a swarm the operator has
|
||||||
enabled but not bootstrapped shows a **crash-looping unit** and `502 Bad
|
enabled but not bootstrapped shows a **crash-looping unit** and `502 Bad
|
||||||
Gateway` from the vhost — not a login page with nobody able to use it.
|
Gateway` from the vhost — not a login page with nobody able to use it.
|
||||||
The gateway is working in that state; the upstream isn't up.
|
The gateway is working in that state; the upstream isn't up.
|
||||||
|
|
@ -95,8 +95,8 @@ an attribute edit can invalidate a login by accident.
|
||||||
|
|
||||||
## What secrets exist, and where each one lives
|
## What secrets exist, and where each one lives
|
||||||
|
|
||||||
Every secret in the swarm, with its generator and its path, is tabulated
|
[`secrets.md`](secrets.md) tabulates every secret in the swarm, with its
|
||||||
in one place: [`secrets.md`](secrets.md), including authelia's own keys
|
generator and its path, in one place — including authelia's own keys
|
||||||
(session, JWT, storage-encryption, OIDC HMAC, OIDC issuer) and the two
|
(session, JWT, storage-encryption, OIDC HMAC, OIDC issuer) and the two
|
||||||
halves of each client secret. That page's two rules — a secret is always
|
halves of each client secret. That page's two rules — a secret is always
|
||||||
a path, never a value, and the generator and the reader typically live in
|
a path, never a value, and the generator and the reader typically live in
|
||||||
|
|
@ -115,9 +115,11 @@ authelia's first boot to mint that client's secret and copies it into the
|
||||||
service's container, and the service's own module contributes its client
|
service's container, and the service's own module contributes its client
|
||||||
entry — callback URL included — to authelia's client list.
|
entry — callback URL included — to authelia's client list.
|
||||||
|
|
||||||
The callback is built once and read twice, so the redirect URI authelia
|
Each relying service's own glue module builds its callback once, and
|
||||||
accepts and the one the service actually sends can't drift apart. A
|
both authelia's client list and the service's own OIDC client config
|
||||||
mismatch there is a rejected login with no error text worth reading.
|
read that same value, so the redirect URI authelia accepts and the one
|
||||||
|
the service actually sends can't drift apart. A mismatch there is a
|
||||||
|
rejected login with no error text worth reading.
|
||||||
|
|
||||||
⚠️ The delivery is a copy, not a `bindMounts` entry, and deliberately so:
|
⚠️ The delivery is a copy, not a `bindMounts` entry, and deliberately so:
|
||||||
nixos-container refuses to start a container whose bind source is
|
nixos-container refuses to start a container whose bind source is
|
||||||
|
|
@ -238,7 +240,7 @@ upstream and compare three requests, not one:
|
||||||
|
|
||||||
All three matter. A change that silently deleted the browser page would
|
All three matter. A change that silently deleted the browser page would
|
||||||
pass a deny-only check, and one that quietly stopped denying would pass a
|
pass a deny-only check, and one that quietly stopped denying would pass a
|
||||||
page-only check. This was verified that way when the split was introduced.
|
page-only check. The person who introduced the split verified it this way.
|
||||||
|
|
||||||
## What this doesn't do
|
## What this doesn't do
|
||||||
|
|
||||||
|
|
@ -254,6 +256,6 @@ page-only check. This was verified that way when the split was introduced.
|
||||||
door, and a dead provider locks everyone out, the built-in admin
|
door, and a dead provider locks everyone out, the built-in admin
|
||||||
included. That's why `swarm.grafana.oidc.role` defaults to `Admin`; see
|
included. That's why `swarm.grafana.oidc.role` defaults to `Admin`; see
|
||||||
[`services.md`](services.md#metrics-victoriametrics--grafana).
|
[`services.md`](services.md#metrics-victoriametrics--grafana).
|
||||||
- **It doesn't provision users.** Agents are created and destroyed
|
- **It doesn't provision users.** `swarmctl` creates and destroys agents
|
||||||
continuously, so the subject set belongs to a program rather than to a
|
continuously today, so the subject set belongs to a program rather
|
||||||
config file; today that program is `swarmctl`.
|
than to a config file.
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue