kanidm: server.toml and the DB folder are world-readable inside the volume #519
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#519
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Problem
Every
kanidmd database backup(daily and, since #517, hourly) logs three warnings:/data/server.toml has 'everyone' permission bits in the mode/data/server.toml owned by the current uid, which may allow file permission changesDB folder /data has 'everyone' permission bits in the modeSo
server.tomland the DB folder inside the Kanidm volume are world-readable or writable from inside the container. The identity database should not be.Fix
Set
server.tomlto 0640 or 0600 and the/datafolder to 0750 or 0700, as the container user sees them, without fighting podman's ownership mapping (manage the mode, not the owner). Confirm the warnings are gone from the next backup run, and that Kanidm still starts.Done when
A backup run logs none of the three warnings.