docs/setup: point at the bootstrap policy file instead of inlining a copy (#4698)
This commit is contained in:
parent
e3c595857e
commit
d048fee698
1 changed files with 5 additions and 33 deletions
|
|
@ -78,40 +78,12 @@ to grant itself anything. Cert auth answers a _role_, so nothing can
|
||||||
authenticate until some role exists — this token is what breaks that cycle,
|
authenticate until some role exists — this token is what breaks that cycle,
|
||||||
and it's the only step that needs the root token.
|
and it's the only step that needs the root token.
|
||||||
|
|
||||||
|
The policy is `nix/host-modules/swarm-bao-bootstrap-policy.hcl` in this
|
||||||
|
repository, and CI fails when a unit using the token needs a path it lacks.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Exactly the six grants the bootstrap unit needs, and nothing else. Each was
|
# The policy file, copied to wherever you run `bao`.
|
||||||
# derived with `bao <cmd> -output-policy`, which prints what a command requires
|
bao policy write swarm-bootstrap swarm-bao-bootstrap-policy.hcl
|
||||||
# without running it.
|
|
||||||
bao policy write swarm-bootstrap - <<'EOF'
|
|
||||||
path "sys/policies/acl/swarm-controller" {
|
|
||||||
capabilities = ["create", "update"]
|
|
||||||
}
|
|
||||||
|
|
||||||
# Cert auth is a mount, and nothing has created it yet: reading `sys/auth` is
|
|
||||||
# how the unit checks, and `sudo` is what enabling one costs.
|
|
||||||
path "sys/auth" {
|
|
||||||
capabilities = ["read"]
|
|
||||||
}
|
|
||||||
|
|
||||||
path "sys/auth/cert" {
|
|
||||||
capabilities = ["create", "update", "sudo"]
|
|
||||||
}
|
|
||||||
|
|
||||||
path "auth/cert/certs/swarm-controller" {
|
|
||||||
capabilities = ["create", "update"]
|
|
||||||
}
|
|
||||||
|
|
||||||
# The KV engine the controller writes agent credentials through — also absent
|
|
||||||
# on a fresh store, and checked the same way. No `sudo` here, unlike the auth
|
|
||||||
# mount above: enabling a secrets engine does not ask for it.
|
|
||||||
path "sys/mounts" {
|
|
||||||
capabilities = ["read"]
|
|
||||||
}
|
|
||||||
|
|
||||||
path "sys/mounts/secret" {
|
|
||||||
capabilities = ["create", "update"]
|
|
||||||
}
|
|
||||||
EOF
|
|
||||||
|
|
||||||
# A token holding it. `-orphan` so it outlives the session that made it.
|
# A token holding it. `-orphan` so it outlives the session that made it.
|
||||||
bao token create -policy=swarm-bootstrap -ttl=24h -orphan -display-name=swarm-bootstrap
|
bao token create -policy=swarm-bootstrap -ttl=24h -orphan -display-name=swarm-bootstrap
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue