1.6 KiB
AIM Sensitive Data and Security Notes
Sensitive files
AIM deliberately keeps secrets outside Git.
Important locations include:
/etc/ansible/inventories/<customer>/group_vars/all/vault.yml
/etc/ansible/inventories/<customer>/group_vars/linux/.ssh/
Vault files may contain Windows and Linux authentication material.
.ssh directories may contain private keys that cannot be regenerated
without coordinating key rotation on managed systems.
Backup requirement
Git is not a backup for ignored secrets.
System backup procedures must include customer Vaults and SSH key material. Recovery should preserve existing current files and restore only missing data unless an operator explicitly chooses otherwise.
Vault handling
AIM encrypts newly created Vaults with ansible-vault. Plaintext
populated Vault data should not remain on disk after a failed encryption
attempt.
Semantic Vault comparison must not print secret values. It should compare key existence/state rather than exposing plaintext.
SSH key handling
Private-key passphrases and remote SSH passwords are separate concepts.
The Linux private key location is:
group_vars/linux/.ssh/svc_bf-ansible
Private keys should have restrictive filesystem permissions.
Authorization
AIM authorization is based on membership in a configured group resolved through NSS/SSSD/winbind/local group services. The configured group name is authoritative; numeric GIDs may differ across hosts.
Operators should verify effective membership with:
getent group '<required-group>'
id