swarm-secret-client: agents may list their own subtree; controller rewrites agent policies
render_agent gains a second stanza: list on secret/metadata/swarm/agents/<agent>/*, next to the existing read on secret/data/swarm/agents/<agent>/*. An agent can now learn which credentials it holds by listing its own subtree. Metadata read, writes and every other principal's paths stay refused. An agent's policy was only written when it was minted, so existing agents would never get the new stanza. swarm-controller now rewrites every agent's policy at start (read_policy::ensure_agent_policies), with the same 30s / 24h retry as ensure_hive_access. The roster is the store's hive-agent-* cert-auth roles, listed with the controller's existing `list` on auth/cert/certs; the writes use its existing grant on sys/policies/acl/hive-*. Only the policy is written: mint_and_verify also reissues the certificate, so the pass does not call it. Refs #4348
This commit is contained in:
parent
4e8225c058
commit
e04616eb70
5 changed files with 204 additions and 43 deletions
|
|
@ -332,7 +332,10 @@ store, and `swarm-controller`, already logged in under its own host leaf, asks
|
|||
that mount's one role for a `hive-agent-<agent>` client certificate at agent
|
||||
creation. Host roles never pin that CA and agent roles pin only it, so an
|
||||
agent's certificate opens that agent's own `swarm/agents/<agent>/*` and
|
||||
nothing else.
|
||||
nothing else: `read` on the values there and `list` on their names.
|
||||
`swarm-controller` writes that policy at agent creation and rewrites every
|
||||
agent's at its own start, so a change to it reaches existing agents with the
|
||||
next controller restart.
|
||||
|
||||
### Per-principal identities
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue