security: one OS user and one OpenStack credential for every service #465
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#465
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Every container on the services host runs under the same rootless user, on one flat podman network, and that user also holds the OpenStack application credential used by the runner controller. A single container escape reaches every podman secret, Postgres, Kanidm, and a credential that can delete every VM and volume including the backup volume.
Options, in rising effort: move the OpenStack credential to its own user (the controller is the only consumer); split the podman network into trust tiers (edge, app, data); per-service rootless users.
Decide the target shape and record it as an ADR before implementing.
Epic: bitborg/bitborg-docs#107
Hetzner destination moved to an object-locked bucket, 2026-10-02.
mc mb --with-lock, default retention COMPLIANCE 14 days, lifecycleexpire-archives(prefixbitborg-) anddrop-noncurrent-and-markers.bitborg-*archives. Vault change in #520, applied, second--checkchanged=0.bitborg-20261002T135512Z.tar.ageuploaded to the new bucket.mc rm --version-idon that archive returnedAccessDenied.Remaining for this issue: Glesys (probe first; it also holds the restic repos, which this protection does not cover), the optional Hetzner delete-deny policy (step 7), retiring the old Hetzner bucket on or after 2026-10-30, dropping
gitborgfrombackup_archive_prefixesafter 2026-10-31, and the rest of the plan above (ADR, restic writer without delete rights, credential split).Confirmed:
mc retention infoon the archive showsCOMPLIANCE, expiring in 13 days(14 days from upload, rounded down). TheAccessDeniedis the lock, not a key permission.