An `auth_token` spelled `swarm-agent.<agent>.<secret>` is no longer sent
to introspection. The responder reads `swarm/agents/<agent>/queue` with
an identity of its own, checks that the stored object names the same
agent, compares the secret in constant time, and grants the subjects
`--agent-token-publish-subject` lists with `{agent}` expanded. Every
other outcome denies: a malformed token, no store identity, nothing
stored, a failed or slow lookup, a different secret. A token without
the prefix takes the OIDC path unchanged.
The journal's `auth request` line names such a caller `agent:<agent>`;
the hive-shared credential keeps `hive-<h>-agent`.
The new principal: a `swarm-nats-auth` cert-auth role and policy with
read on `secret/data/swarm/agents/+/queue` alone, a leaf signed by the
store's PKI glue, and `glue-nats-auth-bao-identity.nix` pairing the two.
The copy unit delivers the identity into the queue's container, and an
absent leaf is delivered empty so the responder still starts and only
agent tokens are refused.
The policy and role are written by `swarm-bao-nats-auth-policy`, logged in
as the bao granter: both names fall under its `swarm-*` globs, so the
deploy writes them with no operator step. module-eval counts it among the
granting units, so every generic granting-unit case covers it.
The secret compare uses `subtle`, already in the lock file through the
TLS stack; no workspace crate offered one directly.
52 lines
2 KiB
TOML
52 lines
2 KiB
TOML
[package]
|
|
name = "swarm-nats-auth"
|
|
version.workspace = true
|
|
readme = "README.md"
|
|
edition.workspace = true
|
|
|
|
[[bin]]
|
|
name = "swarm-nats-auth"
|
|
path = "src/main.rs"
|
|
|
|
[dependencies]
|
|
anyhow.workspace = true
|
|
async-nats.workspace = true
|
|
clap.workspace = true
|
|
# base64url for decoding the inbound request JWT.
|
|
data-encoding.workspace = true
|
|
# StreamExt::next on the subscription: async-nats returns a Stream.
|
|
futures-util.workspace = true
|
|
nkeys.workspace = true
|
|
reqwest.workspace = true
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
# The jti digest: base32hex(sha256(claims)) over every JWT this crate signs.
|
|
sha2.workspace = true
|
|
# Comparing an agent's presented secret with the stored one.
|
|
subtle.workspace = true
|
|
# For `status::BUCKET` and `notices::STREAM` - the subjects a hive may
|
|
# publish to are derived from these names, and every end that touches them
|
|
# must agree on the same one. Deliberately WITHOUT the `kv` feature: this
|
|
# crate derives subject strings, it never opens the bucket. `notices`
|
|
# is name-only too (no `jetstream`/`kv` surface), same reason.
|
|
swarm-queue-client = { workspace = true, features = ["notices"] }
|
|
# The agent-token spelling the agent also uses, and the read of the stored
|
|
# credential it is checked against.
|
|
swarm-secret-client.workspace = true
|
|
tokio.workspace = true
|
|
tracing.workspace = true
|
|
tracing-subscriber.workspace = true
|
|
|
|
[dev-dependencies]
|
|
# A TEST ORACLE, not part of the production path. Neither JWT this crate emits
|
|
# is expressible through it - `Claims` has no `aud`, which the response wrapper
|
|
# needs (the server id) and the user token needs (the account name), and
|
|
# `Token::new_user` always sets `issuer_account`, which a non-operator server
|
|
# rejects outright. So both are hand-built, and this crate is what the encoder
|
|
# is checked *against*: `respond::tests::hand_built_matches_the_reference`
|
|
# builds a user token both ways and requires byte equality, on the one shape
|
|
# nats-jwt does model.
|
|
nats-jwt.workspace = true
|
|
|
|
[lints]
|
|
workspace = true
|