Genesis makes the root secrets, the operator key, and installs the vault
The template raises the store with the password 'bootstrap' and the broker with its image's default administrator, and the installer carried both into the mesh as accepted secrets — permanent, and not secret (novox/hq issue 071). Now the installer makes both credentials, once, at the paths the postgres and lavinmq modules declare as their own secrets, rewrites the produced bundle to use them (the store reads its password from a file; the broker's default account is given the new password by an action before anything dials it), and writes the bundle at 0600 since it now carries them. Before the first secret is accepted it makes the operator's sealing key beside the bundle and gives the mesh the public half, so everything minted from there is sealed to it too (ADR 0085, amended). Phase three adopts the broker as the lavinmq module beside the store and installs mesh-vault as a foundation module; the run ends by writing the operator-sealed export beside the key.
This commit is contained in:
@@ -316,17 +316,17 @@ func sortStrings(values []string) {
|
||||
// writeBundleFile puts the produced bundle where a person can read it, creating the directory it
|
||||
// lives in.
|
||||
//
|
||||
// 0644, and that is deliberate: this file names an image and describes a foundation, and it holds
|
||||
// the bootstrap credentials the template happens to carry — which are the same ones anybody can
|
||||
// read in the template itself. It is meant to be read. What must not be world-readable is the
|
||||
// node's identity, and that lives elsewhere and is written elsewhere (`internal/identity`).
|
||||
// 0600: the produced bundle carries the credentials genesis made — the store's and the broker's,
|
||||
// inside the temporary control plane's connection strings (novox/hq issue 071). It used to be
|
||||
// 0644 and say so was fine because the template's credentials were the same ones anybody could
|
||||
// read in the template; they are not any more. Still meant to be read, by root.
|
||||
func writeBundleFile(path string, content []byte) error {
|
||||
if dir := filepath.Dir(path); dir != "" && dir != "." {
|
||||
if err := os.MkdirAll(dir, 0o755); err != nil {
|
||||
return fmt.Errorf("cannot make %s to write the produced bundle into: %w", dir, err)
|
||||
}
|
||||
}
|
||||
if err := os.WriteFile(path, content, 0o644); err != nil {
|
||||
if err := os.WriteFile(path, content, 0o600); err != nil {
|
||||
return fmt.Errorf(
|
||||
"cannot write the produced bundle to %s: %w\nIt is what is about to be applied, and "+
|
||||
"applying something nobody can read afterwards is how a machine becomes a mystery",
|
||||
|
||||
Reference in New Issue
Block a user