docs/setup: point at the bootstrap policy file instead of inlining a copy (#4698)
This commit is contained in:
parent
e3c595857e
commit
d048fee698
1 changed files with 5 additions and 33 deletions
|
|
@ -78,40 +78,12 @@ to grant itself anything. Cert auth answers a _role_, so nothing can
|
|||
authenticate until some role exists — this token is what breaks that cycle,
|
||||
and it's the only step that needs the root token.
|
||||
|
||||
The policy is `nix/host-modules/swarm-bao-bootstrap-policy.hcl` in this
|
||||
repository, and CI fails when a unit using the token needs a path it lacks.
|
||||
|
||||
```bash
|
||||
# Exactly the six grants the bootstrap unit needs, and nothing else. Each was
|
||||
# derived with `bao <cmd> -output-policy`, which prints what a command requires
|
||||
# without running it.
|
||||
bao policy write swarm-bootstrap - <<'EOF'
|
||||
path "sys/policies/acl/swarm-controller" {
|
||||
capabilities = ["create", "update"]
|
||||
}
|
||||
|
||||
# Cert auth is a mount, and nothing has created it yet: reading `sys/auth` is
|
||||
# how the unit checks, and `sudo` is what enabling one costs.
|
||||
path "sys/auth" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "sys/auth/cert" {
|
||||
capabilities = ["create", "update", "sudo"]
|
||||
}
|
||||
|
||||
path "auth/cert/certs/swarm-controller" {
|
||||
capabilities = ["create", "update"]
|
||||
}
|
||||
|
||||
# The KV engine the controller writes agent credentials through — also absent
|
||||
# on a fresh store, and checked the same way. No `sudo` here, unlike the auth
|
||||
# mount above: enabling a secrets engine does not ask for it.
|
||||
path "sys/mounts" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
|
||||
path "sys/mounts/secret" {
|
||||
capabilities = ["create", "update"]
|
||||
}
|
||||
EOF
|
||||
# The policy file, copied to wherever you run `bao`.
|
||||
bao policy write swarm-bootstrap swarm-bao-bootstrap-policy.hcl
|
||||
|
||||
# A token holding it. `-orphan` so it outlives the session that made it.
|
||||
bao token create -policy=swarm-bootstrap -ttl=24h -orphan -display-name=swarm-bootstrap
|
||||
|
|
|
|||
Loading…
Reference in a new issue