swarm-controller: read the queue client secret from the store, drop the file
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
The controller's OIDC client secret (client `swarm-controller`, used for the queue connection, the auth-bridge bearer and the OTLP push) came from an operator-placed file, `deploy.swarm-controller.queue.clientSecretFile`, handed in by `LoadCredential=`. Now `swarm-secret-publish`, which already copies authelia's minted OIDC secrets into the store, also publishes this one, to `swarm/controller/swarm-controller/oidc/client`. That path sits under `controller/`, which no hive's policy reads. The controller reads it once at start with its existing store certificate and holds it in memory, as `swarm_queue_client::ClientSecret::Value`. If the store is down, it retries for about a minute and then fails the start, so `Restart=` tries again. Policy delta: the controller gets `read` on that leaf, and the publisher gets `create`/`update` on that leaf. Removed: the `queue.clientSecretFile` option (both spellings, now removed options with a message), its singleHostSwarm default, the credential and placeholder, and the path watcher plus its restart oneshot. A controller without a store identity is now an eval error, because it has no other way to get the secret.
This commit is contained in:
parent
97c4771514
commit
e94406cdb9
22 changed files with 595 additions and 247 deletions
|
|
@ -95,7 +95,7 @@ pub fn appservice_token_path(hive: &str) -> Result<String, Error> {
|
|||
|
||||
/// The name segment of the controller's own subtree, and the cert-auth role it
|
||||
/// logs in under (`swarm-controller`'s `store::CERT_ROLE`).
|
||||
const CONTROLLER: &str = "swarm-controller";
|
||||
pub(crate) const CONTROLLER: &str = "swarm-controller";
|
||||
|
||||
/// The path holding the **swarm's** appservice token: the one registration
|
||||
/// on the swarm's homeserver that is not a hive's, whose sender is promoted
|
||||
|
|
|
|||
|
|
@ -60,6 +60,33 @@ pub fn agent_queue_path(agent: &str) -> Result<String, Error> {
|
|||
Ok(format!("{prefix}/queue"))
|
||||
}
|
||||
|
||||
/// The path holding `swarm-controller`'s own OIDC client secret: the identity
|
||||
/// it connects to the queue with, and mints its other bearer tokens from.
|
||||
///
|
||||
/// Under [`Kind::Controller`] because no hive's policy reads that kind. The
|
||||
/// client may read every hive's status, so a copy under `services/`, which
|
||||
/// every hive reads, would hand that reach to every hive.
|
||||
///
|
||||
/// The nix half is `swarm-secret-publisher.nix`, which writes it, and
|
||||
/// `swarm-bao.nix`'s `controllerPolicyText`, which grants the read.
|
||||
///
|
||||
/// # Errors
|
||||
/// Never in practice: the name segment is a constant. The `Result` is
|
||||
/// [`principal_prefix`]'s.
|
||||
pub fn controller_client_path() -> Result<String, Error> {
|
||||
let prefix = principal_prefix(Kind::Controller, crate::matrix::CONTROLLER)?;
|
||||
Ok(format!("{prefix}/oidc/client"))
|
||||
}
|
||||
|
||||
/// What [`controller_client_path`] holds. No client id beside the value: the
|
||||
/// controller's id is a swarm-wide option both the writer and the reader
|
||||
/// already have.
|
||||
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
|
||||
pub struct ControllerCredential {
|
||||
/// The secret itself, under the field name every kind here uses.
|
||||
pub value: String,
|
||||
}
|
||||
|
||||
/// What [`agent_queue_path`] holds: the secret, and the agent it proves.
|
||||
///
|
||||
/// No hive: an agent's identity is not tied to one, and the subjects the
|
||||
|
|
@ -149,6 +176,43 @@ mod tests {
|
|||
assert_eq!(json["client_id"], "hive-alpha-agent");
|
||||
}
|
||||
|
||||
/// Spelled out in full because `swarm-secret-publisher.nix` and
|
||||
/// `swarm-bao.nix` write the same string by hand.
|
||||
#[test]
|
||||
fn the_controller_client_lands_under_the_controller() {
|
||||
assert_eq!(
|
||||
controller_client_path().expect("a constant segment"),
|
||||
"swarm/controller/swarm-controller/oidc/client"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn no_hive_policy_reaches_the_controller_client() {
|
||||
let doc = crate::policy::render("alpha").expect("a plain name is legal");
|
||||
// Every stanza is `path "secret/data/<prefix>*" { … }`.
|
||||
let granted: Vec<&str> = doc
|
||||
.lines()
|
||||
.filter_map(|l| l.strip_prefix("path \"secret/data/"))
|
||||
.filter_map(|p| p.strip_suffix("*\" {"))
|
||||
.collect();
|
||||
let reads = |path: &str| granted.iter().any(|g| path.starts_with(g));
|
||||
let path = controller_client_path().expect("a constant segment");
|
||||
assert!(!reads(&path), "{path} is readable under {granted:?}");
|
||||
// The control: the hive's own agent client IS under a hive stanza, so
|
||||
// the assertion above can fail at all.
|
||||
let own = agent_client_path("alpha").expect("legal");
|
||||
assert!(reads(&own), "{own} should be readable under {granted:?}");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_controller_objects_field_name_is_the_one_the_publisher_writes() {
|
||||
let json = serde_json::to_value(ControllerCredential {
|
||||
value: "s3cr3t".to_owned(),
|
||||
})
|
||||
.expect("serialises");
|
||||
assert_eq!(json, serde_json::json!({ "value": "s3cr3t" }));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn an_agent_name_lands_under_its_own_principal_prefix() {
|
||||
assert_eq!(
|
||||
|
|
|
|||
Loading…
Reference in a new issue