Installer review: secrets are staged privately, and a bundle is 0600 whether or not it existed
From review: the store and broker passwords genesis makes were carried into the controller through a world-readable file in /tmp, a bundle left at 0644 by an earlier installer kept that mode while now holding them, a mesh raised by the old installer would have been handed new passwords its servers do not have, and the broker-admin action's marker did not depend on the value. Secrets now stage in a 0700 directory owned by the controller's account; the bundle is chmod'd; an existing store or broker volume with no credential file is refused by name; the marker holds the password's fingerprint. Also: one install path for the store, broker and vault, no error-string matching for the operator key, and no unreachable fallback for the superuser.
This commit is contained in:
@@ -332,5 +332,10 @@ func writeBundleFile(path string, content []byte) error {
|
||||
"applying something nobody can read afterwards is how a machine becomes a mystery",
|
||||
path, err)
|
||||
}
|
||||
// The mode above applies only when the file is created. A bundle an earlier installer left at
|
||||
// 0644 would keep that while now carrying real credentials, with this function saying 0600.
|
||||
if err := os.Chmod(path, 0o600); err != nil {
|
||||
return fmt.Errorf("cannot make the produced bundle %s readable by root alone: %w", path, err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user