No Rust ever minted a secret_id; approle was dead attack surface. The bootstrap step's check-then-enable case becomes check-then-disable: if approle is mounted, `bao auth disable approle`; otherwise a no-op. Disabling costs `delete`+`sudo` on `sys/auth/approle`, not `create`/`update` — verified against `bao auth disable -output-policy` on a live dev store. The bootstrap policy grant is narrowed to match. nix/module-eval/bao-grants.nix pins the new shape: the bootstrap policy may disable approle, and the granter's role unit never enables it.
44 lines
1.5 KiB
HCL
44 lines
1.5 KiB
HCL
# The `bao-bootstrap` policy: what the 24h bootstrap token may do, and nothing
|
|
# else. ../../docs/getting-started/setup.md has the operator write it with the
|
|
# root token, from the copy ./swarm-bao.nix ships at
|
|
# /etc/hyperhive/bao-bootstrap-policy.hcl; `swarm-bao-granter-role` then acts
|
|
# with it. Every other grant is written by the `bao-granter` principal this
|
|
# creates.
|
|
#
|
|
# Named outside `swarm-*`, so the granter cannot rewrite the policy the next
|
|
# bootstrap token carries.
|
|
#
|
|
# Each stanza was derived with `bao <cmd> -output-policy`, which prints what a
|
|
# command requires without sending it. ../module-eval/bao-grants.nix reads
|
|
# this file and fails when the unit that uses the token calls a path it does
|
|
# not grant.
|
|
|
|
# The auth mounts. Reading `sys/auth` is how the unit checks, and `sudo` is
|
|
# what enabling or disabling one costs.
|
|
path "sys/auth" {
|
|
capabilities = ["read"]
|
|
}
|
|
|
|
path "sys/auth/cert" {
|
|
capabilities = ["create", "update", "sudo"]
|
|
}
|
|
|
|
# Nothing mints an approle secret_id; the bootstrap step disables the mount
|
|
# rather than enabling it. `delete` is what `bao auth disable` costs, not
|
|
# `create`/`update` (verified with `bao auth disable -output-policy`).
|
|
path "sys/auth/approle" {
|
|
capabilities = ["delete", "sudo"]
|
|
}
|
|
|
|
path "sys/auth/oidc" {
|
|
capabilities = ["create", "update", "sudo"]
|
|
}
|
|
|
|
# The granter's own policy and role, and nothing it may write.
|
|
path "sys/policies/acl/bao-granter" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/bao-granter" {
|
|
capabilities = ["create", "update"]
|
|
}
|