Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/docs/getting-started
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 433429ebfd bao: disable the unused approle auth method, declaratively
No Rust ever minted a secret_id; approle was dead attack surface. The
bootstrap step's check-then-enable case becomes check-then-disable: if
approle is mounted, `bao auth disable approle`; otherwise a no-op.

Disabling costs `delete`+`sudo` on `sys/auth/approle`, not
`create`/`update` — verified against `bao auth disable -output-policy`
on a live dev store. The bootstrap policy grant is narrowed to match.

nix/module-eval/bao-grants.nix pins the new shape: the bootstrap policy
may disable approle, and the granter's role unit never enables it.
2026-09-28 22:58:36 +02:00
..
setup.md bao: disable the unused approle auth method, declaratively 2026-09-28 22:58:36 +02:00