On the control node every agent ran as the operator's account, which has passwordless sudo, so an agent could become root without a person (hq ADR 0266). A node now names an agent account at the controller's terminal only; the agent's module declares it never to become root, the node-engine judges that, and the self-check (DA) raises agent-can-become-root while it does not hold, so ADR 0259's router can rest on it.
14 lines
905 B
SQL
14 lines
905 B
SQL
-- A node names the account its agents run as (novox/hq ADR 0266).
|
|
--
|
|
-- On the control node every agent session ran as the operator's account, which may become root without
|
|
-- a password: any agent there could become root without a person. The decision is an account of the
|
|
-- agents' own, without sudo, beside the operator's, who keeps theirs. Stated by the operator at the
|
|
-- controller's terminal, like the operator account (migration 0036), and never by a verb or a setting,
|
|
-- so no agent can change which account it is.
|
|
--
|
|
-- Empty rather than null, as the operator account is: empty is a real state, "agents run as the
|
|
-- operator's account here" — a workstation's today. The home is stored only when it is not
|
|
-- /home/<account>; empty means derive it.
|
|
alter table node add column agent_account text not null default '';
|
|
alter table node add column agent_account_home text not null default '';
|