security: one OS user and one OpenStack credential for every service #465

Öppen
öppnade 2026-09-08 23:04:27 +00:00 av supernaut · 3 kommentarer
Ägare

Every container on the services host runs under the same rootless user, on one flat podman network, and that user also holds the OpenStack application credential used by the runner controller. A single container escape reaches every podman secret, Postgres, Kanidm, and a credential that can delete every VM and volume including the backup volume.

Options, in rising effort: move the OpenStack credential to its own user (the controller is the only consumer); split the podman network into trust tiers (edge, app, data); per-service rootless users.

Decide the target shape and record it as an ADR before implementing.

Every container on the services host runs under the same rootless user, on one flat podman network, and that user also holds the OpenStack application credential used by the runner controller. A single container escape reaches every podman secret, Postgres, Kanidm, and a credential that can delete every VM and volume including the backup volume. Options, in rising effort: move the OpenStack credential to its own user (the controller is the only consumer); split the podman network into trust tiers (edge, app, data); per-service rootless users. Decide the target shape and record it as an ADR before implementing.
Upphovsperson
Ägare
Epic: bitborg/bitborg-docs#107
Upphovsperson
Ägare

Hetzner destination moved to an object-locked bucket, 2026-10-02.

  • Bucket created with mc mb --with-lock, default retention COMPLIANCE 14 days, lifecycle expire-archives (prefix bitborg-) and drop-noncurrent-and-markers.
  • Switched after the archive rename (#518) was applied, so it only ever holds bitborg-* archives. Vault change in #520, applied, second --check changed=0.
  • Manual backup: bitborg-20261002T135512Z.tar.age uploaded to the new bucket.
  • Negative control: mc rm --version-id on that archive returned AccessDenied.

Remaining for this issue: Glesys (probe first; it also holds the restic repos, which this protection does not cover), the optional Hetzner delete-deny policy (step 7), retiring the old Hetzner bucket on or after 2026-10-30, dropping gitborg from backup_archive_prefixes after 2026-10-31, and the rest of the plan above (ADR, restic writer without delete rights, credential split).

Hetzner destination moved to an object-locked bucket, 2026-10-02. - Bucket created with `mc mb --with-lock`, default retention COMPLIANCE 14 days, lifecycle `expire-archives` (prefix `bitborg-`) and `drop-noncurrent-and-markers`. - Switched after the archive rename (#518) was applied, so it only ever holds `bitborg-*` archives. Vault change in #520, applied, second `--check` changed=0. - Manual backup: `bitborg-20261002T135512Z.tar.age` uploaded to the new bucket. - Negative control: `mc rm --version-id` on that archive returned `AccessDenied`. Remaining for this issue: Glesys (probe first; it also holds the restic repos, which this protection does not cover), the optional Hetzner delete-deny policy (step 7), retiring the old Hetzner bucket on or after 2026-10-30, dropping `gitborg` from `backup_archive_prefixes` after 2026-10-31, and the rest of the plan above (ADR, restic writer without delete rights, credential split).
Upphovsperson
Ägare

Confirmed: mc retention info on the archive shows COMPLIANCE, expiring in 13 days (14 days from upload, rounded down). The AccessDenied is the lock, not a key permission.

Confirmed: `mc retention info` on the archive shows `COMPLIANCE, expiring in 13 days` (14 days from upload, rounded down). The `AccessDenied` is the lock, not a key permission.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#465
Ingen beskrivning angiven.