14144584e3
ci/woodpecker/push/apply Pipeline was successful
Host signing returns 403 even though login succeeds: the policy grants the literal path sshca/sign/host, but the only role on the sshca mount is signhost, so the grant matches nothing. Hosts named directly under unkin.net also fall outside the role's allowed domains. - Rename the policy to sshca/sign/signhost and grant that path - Allow unkin.net alongside main.unkin.net and consul on the signhost role Reviewed-on: #153 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
14 lines
201 B
YAML
14 lines
201 B
YAML
# Allow signing SSH host certificates
|
|
---
|
|
rules:
|
|
- path: "sshca/sign/signhost"
|
|
capabilities:
|
|
- create
|
|
- update
|
|
|
|
auth:
|
|
approle:
|
|
- sshsigner
|
|
k8s/au/syd1:
|
|
- puppet_sshsigner
|