# The `bao-bootstrap` policy: what the 24h bootstrap token may do, and nothing # else. ../../docs/getting-started/setup.md has the operator write it with the # root token, from the copy ./swarm-bao.nix ships at # /etc/hyperhive/bao-bootstrap-policy.hcl; `swarm-bao-granter-role` then acts # with it. Every other grant is written by the `bao-granter` principal this # creates. # # Named outside `swarm-*`, so the granter cannot rewrite the policy the next # bootstrap token carries. # # Each stanza was derived with `bao -output-policy`, which prints what a # command requires without sending it. ../module-eval/bao-grants.nix reads # this file and fails when the unit that uses the token calls a path it does # not grant. # The auth mounts. Reading `sys/auth` is how the unit checks, and `sudo` is # what enabling one costs. path "sys/auth" { capabilities = ["read"] } path "sys/auth/cert" { capabilities = ["create", "update", "sudo"] } path "sys/auth/approle" { capabilities = ["create", "update", "sudo"] } # The granter's own policy and role, and nothing it may write. path "sys/policies/acl/bao-granter" { capabilities = ["create", "update"] } path "auth/cert/certs/bao-granter" { capabilities = ["create", "update"] }