swarm-controller: read the queue client secret from the store, drop the file
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
The controller's OIDC client secret (client `swarm-controller`, used for the queue connection, the auth-bridge bearer and the OTLP push) came from an operator-placed file, `deploy.swarm-controller.queue.clientSecretFile`, handed in by `LoadCredential=`. Now `swarm-secret-publish`, which already copies authelia's minted OIDC secrets into the store, also publishes this one, to `swarm/controller/swarm-controller/oidc/client`. That path sits under `controller/`, which no hive's policy reads. The controller reads it once at start with its existing store certificate and holds it in memory, as `swarm_queue_client::ClientSecret::Value`. If the store is down, it retries for about a minute and then fails the start, so `Restart=` tries again. Policy delta: the controller gets `read` on that leaf, and the publisher gets `create`/`update` on that leaf. Removed: the `queue.clientSecretFile` option (both spellings, now removed options with a message), its singleHostSwarm default, the credential and placeholder, and the path watcher plus its restart oneshot. A controller without a store identity is now an eval error, because it has no other way to get the secret.
This commit is contained in:
parent
97c4771514
commit
e94406cdb9
22 changed files with 595 additions and 247 deletions
|
|
@ -3,7 +3,7 @@
|
|||
//! README for why the file cannot be touched from here).
|
||||
//!
|
||||
//! Authenticated with THIS daemon's own queue OIDC identity
|
||||
//! (`SWARM_CONTROLLER_OIDC_*`, the same one `swarm-queue-client` mints for
|
||||
//! ([`crate::queue_identity`], the same one `swarm-queue-client` mints for
|
||||
//! the queue connection) — "one identity per principal" means a second
|
||||
//! op that needs to prove who this process is reuses the identity it
|
||||
//! already has rather than provisioning a new one. A fresh token is
|
||||
|
|
@ -41,7 +41,7 @@ pub struct AuthBridge {
|
|||
impl AuthBridge {
|
||||
/// Read `SWARM_CONTROLLER_AUTH_BRIDGE_URL`; `Ok(None)` when unset.
|
||||
///
|
||||
/// The queue identity (`SWARM_CONTROLLER_OIDC_*`) is not optional once
|
||||
/// The queue identity ([`crate::queue_identity`]) is not optional once
|
||||
/// the bridge URL is set: the nix module sets `queueEnv` unconditionally
|
||||
/// for every controller (the queue is required, not just co-located
|
||||
/// service), so a bridge URL with no queue identity to authenticate
|
||||
|
|
@ -51,15 +51,13 @@ impl AuthBridge {
|
|||
let Ok(base_url) = std::env::var("SWARM_CONTROLLER_AUTH_BRIDGE_URL") else {
|
||||
return Ok(None);
|
||||
};
|
||||
let queue_cfg = swarm_queue_client::QueueConfig::from_env("SWARM_CONTROLLER")
|
||||
.context("reading the queue OIDC identity the auth bridge authenticates with")?
|
||||
.ok_or_else(|| {
|
||||
anyhow::anyhow!(
|
||||
"SWARM_CONTROLLER_AUTH_BRIDGE_URL is set but SWARM_CONTROLLER_OIDC_* is \
|
||||
let queue_cfg = crate::queue_identity::get().cloned().ok_or_else(|| {
|
||||
anyhow::anyhow!(
|
||||
"SWARM_CONTROLLER_AUTH_BRIDGE_URL is set but SWARM_CONTROLLER_OIDC_* is \
|
||||
not — the bridge is authenticated with this daemon's queue identity, so \
|
||||
that identity must exist first"
|
||||
)
|
||||
})?;
|
||||
)
|
||||
})?;
|
||||
let http = reqwest::Client::builder()
|
||||
.connect_timeout(HTTP_CONNECT_TIMEOUT)
|
||||
.timeout(HTTP_TIMEOUT)
|
||||
|
|
|
|||
Loading…
Reference in a new issue