Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/host-modules/glue-bao-ui-oidc-client.nix
atlas b14ff2796c
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
bao: OIDC login to the browser UI via authelia, as a metadata-only viewer
The bao UI at bao-ui.<swarm> took a raw store token and nothing else.
It now offers an OIDC tab: authelia's `admins` group logs in and lands
on `swarm-operator-viewer`, which is list+read on `secret/metadata/*`
and nothing under `secret/data/` or `sys/`.

- authelia registers an interactive client `swarm-bao-ui`
  (glue-bao-ui-oidc-client.nix) with redirect
  `https://bao-ui.<swarm>/ui/vault/auth/oidc/oidc/callback`; the secret
  publisher carries its secret to
  `secret/swarm/services/swarm-bao-ui/oidc/client`.
- `swarm-bao-granter-role` (bootstrap token) enables the `oidc` auth
  mount with listing visibility `unauth`, asked before attempted like
  cert/approle; `bao-bootstrap-policy.hcl` gains `sys/auth/oidc`.
- The granter's policy gains `auth/oidc/config`, `auth/oidc/role/swarm-*`
  and read on that one secret leaf. It still holds no `sys/auth`.
- New granting unit `swarm-bao-operator-viewer-policy` writes the viewer
  policy, and once the granter may configure `auth/oidc/config` (checked
  through `sys/capabilities-self`), writes the mount's config from the
  published secret and the role binding `groups=admins` to the viewer.
  Before the bootstrap step re-runs it writes the policy, logs the step
  and exits 0.

Route (a) per mara on #4775: enabling the auth method stays a
bootstrap-token step, re-run once on the live store.

module-eval pins the viewer policy's single metadata stanza, that the
granter's policy has no sys/auth path, the oidc enable in the bootstrap
unit, the exit-0 path, the config/role contents, and the client
registration + publish.
2026-09-28 19:56:38 +02:00

35 lines
1.1 KiB
Nix

# Glue: register the secret store's browser UI as an OIDC client wherever
# authelia runs.
#
# ONE PAIRING PER FILE — the store's `oidc` auth method ← authelia, and nothing
# else. Deleting this leaves a UI whose OIDC button sends the browser to a
# client authelia has never heard of, and nothing mints the secret
# `swarm-bao-operator-viewer-policy` waits for.
#
# ⚠️ Gated on authelia being HERE, and deliberately NOT on this host running
# the store, for the reason ./glue-grafana-oidc-client.nix gives: a client is a
# row in THIS host's provider config.
{
lib,
config,
...
}:
let
hyperhiveCfg = config.services.hyperhive;
deployCfg = hyperhiveCfg.deploy;
uiCfg = hyperhiveCfg.swarm.bao.ui;
in
{
config = lib.mkIf deployCfg.authelia.enable {
# `kind` is left at its `interactive` default: a person logs in here, and
# that kind is what permits the `profile` and `groups` scopes the store's
# role asks for.
services.hyperhive.swarm.authelia.oidc.clients = [
{
id = uiCfg.oidc.clientId;
description = "HyperHive secret store UI";
redirectUris = [ uiCfg.oidc.redirectUri ];
}
];
};
}