docs/setup: point at the bootstrap policy file instead of inlining a copy (#4698)

This commit is contained in:
atlas 2026-09-24 15:54:38 +02:00
commit d048fee698

View file

@ -78,40 +78,12 @@ to grant itself anything. Cert auth answers a _role_, so nothing can
authenticate until some role exists — this token is what breaks that cycle, authenticate until some role exists — this token is what breaks that cycle,
and it's the only step that needs the root token. and it's the only step that needs the root token.
The policy is `nix/host-modules/swarm-bao-bootstrap-policy.hcl` in this
repository, and CI fails when a unit using the token needs a path it lacks.
```bash ```bash
# Exactly the six grants the bootstrap unit needs, and nothing else. Each was # The policy file, copied to wherever you run `bao`.
# derived with `bao <cmd> -output-policy`, which prints what a command requires bao policy write swarm-bootstrap swarm-bao-bootstrap-policy.hcl
# without running it.
bao policy write swarm-bootstrap - <<'EOF'
path "sys/policies/acl/swarm-controller" {
capabilities = ["create", "update"]
}
# Cert auth is a mount, and nothing has created it yet: reading `sys/auth` is
# how the unit checks, and `sudo` is what enabling one costs.
path "sys/auth" {
capabilities = ["read"]
}
path "sys/auth/cert" {
capabilities = ["create", "update", "sudo"]
}
path "auth/cert/certs/swarm-controller" {
capabilities = ["create", "update"]
}
# The KV engine the controller writes agent credentials through — also absent
# on a fresh store, and checked the same way. No `sudo` here, unlike the auth
# mount above: enabling a secrets engine does not ask for it.
path "sys/mounts" {
capabilities = ["read"]
}
path "sys/mounts/secret" {
capabilities = ["create", "update"]
}
EOF
# A token holding it. `-orphan` so it outlives the session that made it. # A token holding it. `-orphan` so it outlives the session that made it.
bao token create -policy=swarm-bootstrap -ttl=24h -orphan -display-name=swarm-bootstrap bao token create -policy=swarm-bootstrap -ttl=24h -orphan -display-name=swarm-bootstrap