fix(kanidm): restrict server.toml and the data dir modes #522
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!522
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/519-kanidm-perms"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Restrict Kanidm's config and data dir modes.
server.toml(host file bind-mounted at/data/server.toml): 0644 → 0600. Kanidm runs as container root, which maps to the file's owner./datain the container): 755 → 0750, viafilewith mode only and no owner, so it does not fight podman's uid mapping. The mountpoint comes from a read-onlypodman volume inspect.Live modes before were read with
podman unshare stat(read-only).Apply
Kanidm restarts once (the template change notifies the handler). Later applies report
ok. After the apply, the next backup'skanidmd database backupshould no longer warn about "everyone" permission bits. The "owned by the current uid" warning stays and is expected.Closes #519
336bac83d75084197221