`swarm-bao-forwarder-oidc` fetches the store container's collector secret, one path, and was the last reader still logging in with `deploy.bao.clientCertFile`: the hive's own leaf, whose policy reads every agent's credentials, the hive's tree and every service's OIDC secret. The four-way split gave grafana's and the swarm collector's readers leaves of their own and left this one behind. It now holds `forwarder-oidc.pem`, minted by `swarm-bao-pki`, and logs in under the `swarm-forwarder-oidc` cert-auth role, whose policy reads `secret/data/swarm/services/<store forwarder client id>/oidc/client` and nothing else. The role is written by `swarm-bao-forwarder-oidc-policy` from the bootstrap token, which gains the two grants that unit calls, and the reader is ordered after it. The subject is reserved as a hive name. A store host whose pair is null is refused at eval rather than falling back to the hive's leaf. The hive's own role and `client.pem` are untouched; nothing is revoked.
159 lines
3.9 KiB
HCL
159 lines
3.9 KiB
HCL
# The `swarm-bootstrap` policy: what the 24h bootstrap token may do, and
|
|
# nothing else. ../../docs/getting-started/setup.md has the operator write it
|
|
# with the root token; ./swarm-bao.nix's granting units then act with it.
|
|
#
|
|
# Each stanza was derived with `bao <cmd> -output-policy`, which prints what a
|
|
# command requires without sending it. ../module-eval/bao-grants.nix reads
|
|
# this file and fails when a unit that uses the token calls a path it does not
|
|
# grant. The pki paths assume the default `servicesPkiMountPath` (`pki`),
|
|
# `servicesPkiRoleName` (`swarm-services`) and `natsPkiRoleName` (`swarm-nats`).
|
|
|
|
# swarm-bao-controller-policy: the controller's own policy and role.
|
|
path "sys/policies/acl/swarm-controller" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-controller" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# The auth mounts it creates. Reading `sys/auth` is how the unit checks, and
|
|
# `sudo` is what enabling one costs.
|
|
path "sys/auth" {
|
|
capabilities = ["read"]
|
|
}
|
|
|
|
path "sys/auth/cert" {
|
|
capabilities = ["create", "update", "sudo"]
|
|
}
|
|
|
|
path "sys/auth/approle" {
|
|
capabilities = ["create", "update", "sudo"]
|
|
}
|
|
|
|
# The KV and PKI engines, checked the same way. Enabling a secrets engine does
|
|
# not ask for `sudo`.
|
|
path "sys/mounts" {
|
|
capabilities = ["read"]
|
|
}
|
|
|
|
path "sys/mounts/secret" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "sys/mounts/pki" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "sys/mounts/pki/tune" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# The services root: generated once, read back on every run, and replaced
|
|
# only when it can no longer outlive a leaf.
|
|
path "pki/issuers" {
|
|
capabilities = ["list"]
|
|
}
|
|
|
|
path "pki/cert/ca" {
|
|
capabilities = ["read"]
|
|
}
|
|
|
|
path "pki/root" {
|
|
capabilities = ["delete", "sudo"]
|
|
}
|
|
|
|
path "pki/root/generate/internal" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "pki/roles/swarm-services" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-secret-publisher-policy
|
|
path "sys/policies/acl/swarm-secret-publisher" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-secret-publisher" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-matrix-ctl-policy
|
|
path "sys/policies/acl/swarm-matrix-ctl" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-matrix-ctl" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-services-issuer-policy
|
|
path "sys/policies/acl/swarm-services-issuer" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-services-issuer" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-grafana-oidc-policy
|
|
path "sys/policies/acl/swarm-grafana-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-grafana-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-otel-oidc-policy
|
|
path "sys/policies/acl/swarm-otel-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-otel-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-forwarder-oidc-policy
|
|
path "sys/policies/acl/swarm-forwarder-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-forwarder-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-nats-tls-policy: the queue's own pki role, beside
|
|
# `swarm-services` above, and its policy and login role.
|
|
path "pki/roles/swarm-nats" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "sys/policies/acl/swarm-nats" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-nats" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-matrix-token-policy and swarm-bao-queue-agent-policy write one
|
|
# policy and role per hive, `<prefix>-<hive>`, so these two are globs. Each
|
|
# stops at its own prefix.
|
|
path "sys/policies/acl/swarm-matrix-token-*" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-matrix-token-*" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "sys/policies/acl/swarm-queue-agent-*" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-queue-agent-*" {
|
|
capabilities = ["create", "update"]
|
|
}
|