postgres: the store's query runs as a read-only login, never as the admin (hq #193)

The verb wrapped the caller's text in BEGIN READ ONLY ... ROLLBACK as the superuser, so
'COMMIT; ...' left the transaction and, proven on a throwaway server, COPY TO PROGRAM ran a
shell command on the database host. The statement now runs as mesh_store_reader:
pg_read_all_data, no other grant, read-only transactions by role and session, its password
an own-secret the mesh mints. Without that password the call is refused. -q drops the
command tags that came back as rows keyed by BEGIN.
This commit is contained in:
2026-10-02 00:09:09 +02:00
parent ef44c502db
commit 160b5ad65a
5 changed files with 204 additions and 10 deletions
+6 -3
View File
@@ -53,7 +53,8 @@
},
"own-secrets": {
"superuser": "${dir:state}/superuser.secret",
"broker": "${dir:mesh-state}/broker"
"broker": "${dir:mesh-state}/broker",
"reader": "${dir:state}/reader.secret"
},
"resources": [
{
@@ -105,14 +106,16 @@
"volumes": [
"${dir:mesh-state}/broker:/run/secrets/broker:ro",
"${dir:grants}:${dir:grants}:ro",
"${dir:state}/superuser.secret:/run/secrets/superuser:ro"
"${dir:state}/superuser.secret:/run/secrets/superuser:ro",
"${dir:state}/reader.secret:/run/secrets/reader:ro"
],
"env": {
"MESH_PROVISION_POSTGRES": "postgres://postgres@127.0.0.1:${port:5432}/postgres?sslmode=disable",
"MESH_PROVISION_POSTGRES_PORT": "${seat:mesh-store:5432}",
"MESH_PROVISION_PASSWORD_FILE": "/run/secrets/superuser",
"MESH_BROKER_FILE": "/run/secrets/broker",
"MESH_RECEIVES": "${dir:grants}/mesh.json"
"MESH_RECEIVES": "${dir:grants}/mesh.json",
"MESH_POSTGRES_READER_PASSWORD_FILE": "/run/secrets/reader"
},
"artifact": "runtime"
}