From d048fee69839237b94ce56e43c75c59a0b01c67b Mon Sep 17 00:00:00 2001 From: atlas Date: Thu, 24 Sep 2026 15:54:38 +0200 Subject: [PATCH] docs/setup: point at the bootstrap policy file instead of inlining a copy (#4698) --- docs/getting-started/setup.md | 38 +++++------------------------------ 1 file changed, 5 insertions(+), 33 deletions(-) diff --git a/docs/getting-started/setup.md b/docs/getting-started/setup.md index 2225529e..5a6c685e 100644 --- a/docs/getting-started/setup.md +++ b/docs/getting-started/setup.md @@ -78,40 +78,12 @@ to grant itself anything. Cert auth answers a _role_, so nothing can authenticate until some role exists — this token is what breaks that cycle, and it's the only step that needs the root token. +The policy is `nix/host-modules/swarm-bao-bootstrap-policy.hcl` in this +repository, and CI fails when a unit using the token needs a path it lacks. + ```bash -# Exactly the six grants the bootstrap unit needs, and nothing else. Each was -# derived with `bao -output-policy`, which prints what a command requires -# without running it. -bao policy write swarm-bootstrap - <<'EOF' -path "sys/policies/acl/swarm-controller" { - capabilities = ["create", "update"] -} - -# Cert auth is a mount, and nothing has created it yet: reading `sys/auth` is -# how the unit checks, and `sudo` is what enabling one costs. -path "sys/auth" { - capabilities = ["read"] -} - -path "sys/auth/cert" { - capabilities = ["create", "update", "sudo"] -} - -path "auth/cert/certs/swarm-controller" { - capabilities = ["create", "update"] -} - -# The KV engine the controller writes agent credentials through — also absent -# on a fresh store, and checked the same way. No `sudo` here, unlike the auth -# mount above: enabling a secrets engine does not ask for it. -path "sys/mounts" { - capabilities = ["read"] -} - -path "sys/mounts/secret" { - capabilities = ["create", "update"] -} -EOF +# The policy file, copied to wherever you run `bao`. +bao policy write swarm-bootstrap swarm-bao-bootstrap-policy.hcl # A token holding it. `-orphan` so it outlives the session that made it. bao token create -policy=swarm-bootstrap -ttl=24h -orphan -display-name=swarm-bootstrap