Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
The bao UI at bao-ui.<swarm> took a raw store token and nothing else. It now offers an OIDC tab: authelia's `admins` group logs in and lands on `swarm-operator-viewer`, which is list+read on `secret/metadata/*` and nothing under `secret/data/` or `sys/`. - authelia registers an interactive client `swarm-bao-ui` (glue-bao-ui-oidc-client.nix) with redirect `https://bao-ui.<swarm>/ui/vault/auth/oidc/oidc/callback`; the secret publisher carries its secret to `secret/swarm/services/swarm-bao-ui/oidc/client`. - `swarm-bao-granter-role` (bootstrap token) enables the `oidc` auth mount with listing visibility `unauth`, asked before attempted like cert/approle; `bao-bootstrap-policy.hcl` gains `sys/auth/oidc`. - The granter's policy gains `auth/oidc/config`, `auth/oidc/role/swarm-*` and read on that one secret leaf. It still holds no `sys/auth`. - New granting unit `swarm-bao-operator-viewer-policy` writes the viewer policy, and once the granter may configure `auth/oidc/config` (checked through `sys/capabilities-self`), writes the mount's config from the published secret and the role binding `groups=admins` to the viewer. Before the bootstrap step re-runs it writes the policy, logs the step and exits 0. Route (a) per mara on #4775: enabling the auth method stays a bootstrap-token step, re-run once on the live store. module-eval pins the viewer policy's single metadata stanza, that the granter's policy has no sys/auth path, the oidc enable in the bootstrap unit, the exit-0 path, the config/role contents, and the client registration + publish.
35 lines
1.1 KiB
Nix
35 lines
1.1 KiB
Nix
# Glue: register the secret store's browser UI as an OIDC client wherever
|
|
# authelia runs.
|
|
#
|
|
# ONE PAIRING PER FILE — the store's `oidc` auth method ← authelia, and nothing
|
|
# else. Deleting this leaves a UI whose OIDC button sends the browser to a
|
|
# client authelia has never heard of, and nothing mints the secret
|
|
# `swarm-bao-operator-viewer-policy` waits for.
|
|
#
|
|
# ⚠️ Gated on authelia being HERE, and deliberately NOT on this host running
|
|
# the store, for the reason ./glue-grafana-oidc-client.nix gives: a client is a
|
|
# row in THIS host's provider config.
|
|
{
|
|
lib,
|
|
config,
|
|
...
|
|
}:
|
|
let
|
|
hyperhiveCfg = config.services.hyperhive;
|
|
deployCfg = hyperhiveCfg.deploy;
|
|
uiCfg = hyperhiveCfg.swarm.bao.ui;
|
|
in
|
|
{
|
|
config = lib.mkIf deployCfg.authelia.enable {
|
|
# `kind` is left at its `interactive` default: a person logs in here, and
|
|
# that kind is what permits the `profile` and `groups` scopes the store's
|
|
# role asks for.
|
|
services.hyperhive.swarm.authelia.oidc.clients = [
|
|
{
|
|
id = uiCfg.oidc.clientId;
|
|
description = "HyperHive secret store UI";
|
|
redirectUris = [ uiCfg.oidc.redirectUri ];
|
|
}
|
|
];
|
|
};
|
|
}
|