Installer review: secrets are staged privately, and a bundle is 0600 whether or not it existed

From review: the store and broker passwords genesis makes were carried into
the controller through a world-readable file in /tmp, a bundle left at 0644 by
an earlier installer kept that mode while now holding them, a mesh raised by
the old installer would have been handed new passwords its servers do not have,
and the broker-admin action's marker did not depend on the value. Secrets now
stage in a 0700 directory owned by the controller's account; the bundle is
chmod'd; an existing store or broker volume with no credential file is refused
by name; the marker holds the password's fingerprint. Also: one install path
for the store, broker and vault, no error-string matching for the operator
key, and no unreachable fallback for the superuser.
This commit is contained in:
2026-09-21 01:26:35 +02:00
parent 036af3cfdc
commit 70d0f36896
8 changed files with 175 additions and 155 deletions
+5
View File
@@ -332,5 +332,10 @@ func writeBundleFile(path string, content []byte) error {
"applying something nobody can read afterwards is how a machine becomes a mystery",
path, err)
}
// The mode above applies only when the file is created. A bundle an earlier installer left at
// 0644 would keep that while now carrying real credentials, with this function saying 0600.
if err := os.Chmod(path, 0o600); err != nil {
return fmt.Errorf("cannot make the produced bundle %s readable by root alone: %w", path, err)
}
return nil
}