From 0dd7bc56b8d614740ee82392efbe8b2aa1bde30f Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sat, 19 Sep 2026 12:51:47 +1000 Subject: [PATCH] Point the SSH host sign policy at the role that exists The sshca mount only defines the signhost role, so the policy grant for sshca/sign/host never matched a real path and every host-key signing request from the Puppet compilers was denied. The role also excluded unkin.net, rejecting the git.unkin.net and grafana.unkin.net principals the manifest sends. - Grant sshca/sign/signhost instead of sshca/sign/host - Add unkin.net to the signhost role's allowed_domains --- config/ssh_secret_backend_role/sshca/signhost.yaml | 2 +- policies/sshca/sign/host.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/config/ssh_secret_backend_role/sshca/signhost.yaml b/config/ssh_secret_backend_role/sshca/signhost.yaml index e3b71b4..fc8c1e5 100644 --- a/config/ssh_secret_backend_role/sshca/signhost.yaml +++ b/config/ssh_secret_backend_role/sshca/signhost.yaml @@ -3,6 +3,6 @@ algorithm_signer: rsa-sha2-256 ttl: 315360000 # 87600 * 3600 allow_host_certificates: true allow_user_certificates: false -allowed_domains: "main.unkin.net,consul" +allowed_domains: "unkin.net,main.unkin.net,consul" allow_subdomains: true allow_bare_domains: false diff --git a/policies/sshca/sign/host.yaml b/policies/sshca/sign/host.yaml index 5f99869..4a5b474 100644 --- a/policies/sshca/sign/host.yaml +++ b/policies/sshca/sign/host.yaml @@ -1,7 +1,7 @@ # Allow signing SSH host certificates --- rules: - - path: "sshca/sign/host" + - path: "sshca/sign/signhost" capabilities: - create - update