aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
> The behaviors below are retained from2.1.0rc2. Current candidate2.1.0rc9 targets Core3.3.0rc8/schema5 and adds reports/journal described in REPORTS.md and JOURNAL.md. Credential, read-only inventory and OS-permission boundaries here remain unchanged; old version/no-migration statements describe the earlier slice.
|
||||
|
||||
# Managed permissions - WebGUI 2.1.0rc1
|
||||
|
||||
No permission change from2.0.0rc8. This document describes the existing add-on-owned contract, not instructions to recursively chown AIM.
|
||||
|
||||
| Resource | Owner/group | Mode |
|
||||
|---|---|---|
|
||||
| WebGUI source, virtualenv, units | root-owned | Release-managed |
|
||||
| webgui.toml | root:aim-web |0640|
|
||||
| /var/lib/aim/webgui |aim-web:aim-web|0700|
|
||||
| SQLite database |aim-web:aim-web|0600|
|
||||
| /var/lib/aim-web-executor and .ansible/tmp chain |executor:native primary group|0700|
|
||||
| passwd-home .ansible and .ansible/tmp |executor:native primary group|0700|
|
||||
| /run/aim-web-executor |executor:native primary group|0711|
|
||||
| /run/aim-web-executor/core.sock |executor:aim-web|0660|
|
||||
|
||||
Site executor is svc_bf-ansible. Systemd preserves its native primary group and grants aim-web as a unit-scoped SupplementaryGroups entry; numeric group IDs may appear in systemctl output. Other account memberships are resolved normally, so an empty explicit supplementary setting is not proof of an empty actual group list. The installer does not silently rewrite OS account memberships.
|
||||
|
||||
The0711 runtime directory permits traversal to the known socket path, not directory listing for unrelated users. Socket DAC and peer checks govern access. NoNewPrivileges and empty capability sets remain; no sudo or root worker. ProtectHome remains read-only with a narrow writable passwd-home .ansible/tmp exception for delegated local tasks, plus the separate process-home staging path. The installer waits for socket readiness and checks exact managed owner/mode before starting dependent services.
|
||||
|
||||
## Verification, not manual repair
|
||||
|
||||
```bash
|
||||
systemctl show aim-web-executor.service -p User -p Group -p SupplementaryGroups
|
||||
stat -c '%U:%G %a %n' \
|
||||
/var/lib/aim-web-executor \
|
||||
/var/lib/aim-web-executor/.ansible/tmp \
|
||||
/home/svc_bf-ansible/.ansible/tmp \
|
||||
/run/aim-web-executor \
|
||||
/run/aim-web-executor/core.sock \
|
||||
/etc/ansible/scripts/config/webgui.toml
|
||||
sudo journalctl -u aim-web-executor.service -n 60 --no-pager
|
||||
```
|
||||
|
||||
The release-managed ExecStartPre runs staging checks inside the real executor unit. Interactive sudo -u svc_bf-ansible alone does not reproduce unit-scoped aim-web group access to webgui.toml. Do not make that config world-readable to hide the distinction.
|
||||
|
||||
## Outside add-on ownership
|
||||
|
||||
AIM source/configuration, authorization groups, inventory/Vaults, canonical owner-only0600 private keys, /etc/ssh/ssh_known_hosts, certificates and Nginx remain Core/operator managed. The add-on does not enroll host keys or infer their trust from HOME. Keep independently verified effective SSH trust. Unknown unit drop-ins stop deployment for review; do not silently restore obsolete privilege/capability workarounds.
|
||||
|
||||
The new explorer, activity and insights pages require no new write path, group, service, port or secret permission.
|
||||
Reference in New Issue
Block a user