A secret the mesh was given is not one the mesh can reinvent
Two kinds live in module_secret and they behaved identically, which is right for one of them. A made secret is the mesh's: when a node regenerates its sealing key the mesh makes another and nothing is lost, because nothing else ever knew the old one. An accepted secret is not. A broker account's password exists because the broker was told about it. Regenerating one puts 32 random bytes where a working credential was — and the machine applies it, reports success, and the program reading it fails to authenticate somewhere else entirely, with the mesh insisting the secret was delivered, which it was. The row now records where the value came from, and a rejoined machine asking for an accepted one is refused with the remedy named: issue it again. No amount of pushing produces a password the broker has never heard of. Found while making the builder a module, which is the first thing to hold one.
This commit is contained in:
@@ -156,13 +156,24 @@ func (i *Inventory) SecretForModule(ctx context.Context, node, module, name stri
|
||||
return "", err
|
||||
}
|
||||
|
||||
var sealed, against string
|
||||
var sealed, against, origin string
|
||||
err = i.store.Pool().QueryRow(ctx,
|
||||
`select sealed, node_key from module_secret where node = $1 and module = $2 and name = $3`,
|
||||
record.ID, module, name).Scan(&sealed, &against)
|
||||
`select sealed, node_key, origin from module_secret
|
||||
where node = $1 and module = $2 and name = $3`,
|
||||
record.ID, module, name).Scan(&sealed, &against, &origin)
|
||||
if err == nil && against == key {
|
||||
return sealed, nil
|
||||
}
|
||||
if err == nil && origin == "accepted" {
|
||||
// Sealed to a key this node no longer has, and not the mesh's to invent again. Making one
|
||||
// would put 32 random bytes where a working credential was: the machine would apply it,
|
||||
// report success, and whatever reads it would fail to authenticate somewhere else
|
||||
// entirely — with the mesh insisting the secret was delivered, which it was.
|
||||
return "", fmt.Errorf(
|
||||
"%s on %s holds %q, which was given to the mesh rather than made by it, and %s has "+
|
||||
"since generated a new sealing key. The mesh cannot make another; issue it again",
|
||||
module, node, name, node)
|
||||
}
|
||||
|
||||
made, err := secrets.Make(key, key)
|
||||
if err != nil {
|
||||
@@ -171,10 +182,11 @@ func (i *Inventory) SecretForModule(ctx context.Context, node, module, name stri
|
||||
// Sealed once, to one recipient. Make seals to two ends because a provision has two; here
|
||||
// both are the same machine, and only one copy is kept.
|
||||
if _, err := i.store.Pool().Exec(ctx,
|
||||
`insert into module_secret (node, module, name, sealed, node_key)
|
||||
values ($1, $2, $3, $4, $5)
|
||||
`insert into module_secret (node, module, name, sealed, node_key, origin)
|
||||
values ($1, $2, $3, $4, $5, 'made')
|
||||
on conflict (node, module, name) do update set
|
||||
sealed = excluded.sealed, node_key = excluded.node_key, made_at = now()`,
|
||||
sealed = excluded.sealed, node_key = excluded.node_key,
|
||||
origin = excluded.origin, made_at = now()`,
|
||||
record.ID, module, name, made.ForConsumer, key); err != nil {
|
||||
return "", err
|
||||
}
|
||||
@@ -210,10 +222,11 @@ func (i *Inventory) AcceptSecretForModule(ctx context.Context, node, module, nam
|
||||
return err
|
||||
}
|
||||
_, err = i.store.Pool().Exec(ctx,
|
||||
`insert into module_secret (node, module, name, sealed, node_key)
|
||||
values ($1, $2, $3, $4, $5)
|
||||
`insert into module_secret (node, module, name, sealed, node_key, origin)
|
||||
values ($1, $2, $3, $4, $5, 'accepted')
|
||||
on conflict (node, module, name) do update set
|
||||
sealed = excluded.sealed, node_key = excluded.node_key, made_at = now()`,
|
||||
sealed = excluded.sealed, node_key = excluded.node_key,
|
||||
origin = excluded.origin, made_at = now()`,
|
||||
record.ID, module, name, sealed.ForConsumer, key)
|
||||
return err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user