swarm-bao-nats-tls-policy acts with the bootstrap token, and main's module-eval-bao-grants now fails any such unit whose calls the policy file does not grant. Adds its three paths and counts it among the units the check must see.
150 lines
3.7 KiB
HCL
150 lines
3.7 KiB
HCL
# The `swarm-bootstrap` policy: what the 24h bootstrap token may do, and
|
|
# nothing else. ../../docs/getting-started/setup.md has the operator write it
|
|
# with the root token; ./swarm-bao.nix's granting units then act with it.
|
|
#
|
|
# Each stanza was derived with `bao <cmd> -output-policy`, which prints what a
|
|
# command requires without sending it. ../module-eval/bao-grants.nix reads
|
|
# this file and fails when a unit that uses the token calls a path it does not
|
|
# grant. The pki paths assume the default `servicesPkiMountPath` (`pki`),
|
|
# `servicesPkiRoleName` (`swarm-services`) and `natsPkiRoleName` (`swarm-nats`).
|
|
|
|
# swarm-bao-controller-policy: the controller's own policy and role.
|
|
path "sys/policies/acl/swarm-controller" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-controller" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# The auth mounts it creates. Reading `sys/auth` is how the unit checks, and
|
|
# `sudo` is what enabling one costs.
|
|
path "sys/auth" {
|
|
capabilities = ["read"]
|
|
}
|
|
|
|
path "sys/auth/cert" {
|
|
capabilities = ["create", "update", "sudo"]
|
|
}
|
|
|
|
path "sys/auth/approle" {
|
|
capabilities = ["create", "update", "sudo"]
|
|
}
|
|
|
|
# The KV and PKI engines, checked the same way. Enabling a secrets engine does
|
|
# not ask for `sudo`.
|
|
path "sys/mounts" {
|
|
capabilities = ["read"]
|
|
}
|
|
|
|
path "sys/mounts/secret" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "sys/mounts/pki" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "sys/mounts/pki/tune" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# The services root: generated once, read back on every run, and replaced
|
|
# only when it can no longer outlive a leaf.
|
|
path "pki/issuers" {
|
|
capabilities = ["list"]
|
|
}
|
|
|
|
path "pki/cert/ca" {
|
|
capabilities = ["read"]
|
|
}
|
|
|
|
path "pki/root" {
|
|
capabilities = ["delete", "sudo"]
|
|
}
|
|
|
|
path "pki/root/generate/internal" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "pki/roles/swarm-services" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-secret-publisher-policy
|
|
path "sys/policies/acl/swarm-secret-publisher" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-secret-publisher" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-matrix-ctl-policy
|
|
path "sys/policies/acl/swarm-matrix-ctl" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-matrix-ctl" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-services-issuer-policy
|
|
path "sys/policies/acl/swarm-services-issuer" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-services-issuer" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-grafana-oidc-policy
|
|
path "sys/policies/acl/swarm-grafana-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-grafana-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-otel-oidc-policy
|
|
path "sys/policies/acl/swarm-otel-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-otel-oidc" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-nats-tls-policy: the queue's own pki role, beside
|
|
# `swarm-services` above, and its policy and login role.
|
|
path "pki/roles/swarm-nats" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "sys/policies/acl/swarm-nats" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-nats" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
# swarm-bao-matrix-token-policy and swarm-bao-queue-agent-policy write one
|
|
# policy and role per hive, `<prefix>-<hive>`, so these two are globs. Each
|
|
# stops at its own prefix.
|
|
path "sys/policies/acl/swarm-matrix-token-*" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-matrix-token-*" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "sys/policies/acl/swarm-queue-agent-*" {
|
|
capabilities = ["create", "update"]
|
|
}
|
|
|
|
path "auth/cert/certs/swarm-queue-agent-*" {
|
|
capabilities = ["create", "update"]
|
|
}
|