added docs
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
# AIM Sensitive Data and Security Notes
|
||||
|
||||
## Sensitive files
|
||||
|
||||
AIM deliberately keeps secrets outside Git.
|
||||
|
||||
Important locations include:
|
||||
|
||||
``` text
|
||||
/etc/ansible/inventories/<customer>/group_vars/all/vault.yml
|
||||
/etc/ansible/inventories/<customer>/group_vars/linux/.ssh/
|
||||
```
|
||||
|
||||
Vault files may contain Windows and Linux authentication material.
|
||||
`.ssh` directories may contain private keys that cannot be regenerated
|
||||
without coordinating key rotation on managed systems.
|
||||
|
||||
## Backup requirement
|
||||
|
||||
Git is not a backup for ignored secrets.
|
||||
|
||||
System backup procedures must include customer Vaults and SSH key
|
||||
material. Recovery should preserve existing current files and restore
|
||||
only missing data unless an operator explicitly chooses otherwise.
|
||||
|
||||
## Vault handling
|
||||
|
||||
AIM encrypts newly created Vaults with `ansible-vault`. Plaintext
|
||||
populated Vault data should not remain on disk after a failed encryption
|
||||
attempt.
|
||||
|
||||
Semantic Vault comparison must not print secret values. It should
|
||||
compare key existence/state rather than exposing plaintext.
|
||||
|
||||
## SSH key handling
|
||||
|
||||
Private-key passphrases and remote SSH passwords are separate concepts.
|
||||
|
||||
The Linux private key location is:
|
||||
|
||||
``` text
|
||||
group_vars/linux/.ssh/svc_bf-ansible
|
||||
```
|
||||
|
||||
Private keys should have restrictive filesystem permissions.
|
||||
|
||||
## Authorization
|
||||
|
||||
AIM authorization is based on membership in a configured group resolved
|
||||
through NSS/SSSD/winbind/local group services. The configured group name
|
||||
is authoritative; numeric GIDs may differ across hosts.
|
||||
|
||||
Operators should verify effective membership with:
|
||||
|
||||
``` bash
|
||||
getent group '<required-group>'
|
||||
id
|
||||
```
|
||||
Reference in New Issue
Block a user