Files
2026-09-15 18:53:28 +02:00

59 lines
1.6 KiB
Markdown

# AIM Sensitive Data and Security Notes
## Sensitive files
AIM deliberately keeps secrets outside Git.
Important locations include:
``` text
/etc/ansible/inventories/<customer>/group_vars/all/vault.yml
/etc/ansible/inventories/<customer>/group_vars/linux/.ssh/
```
Vault files may contain Windows and Linux authentication material.
`.ssh` directories may contain private keys that cannot be regenerated
without coordinating key rotation on managed systems.
## Backup requirement
Git is not a backup for ignored secrets.
System backup procedures must include customer Vaults and SSH key
material. Recovery should preserve existing current files and restore
only missing data unless an operator explicitly chooses otherwise.
## Vault handling
AIM encrypts newly created Vaults with `ansible-vault`. Plaintext
populated Vault data should not remain on disk after a failed encryption
attempt.
Semantic Vault comparison must not print secret values. It should
compare key existence/state rather than exposing plaintext.
## SSH key handling
Private-key passphrases and remote SSH passwords are separate concepts.
The Linux private key location is:
``` text
group_vars/linux/.ssh/svc_bf-ansible
```
Private keys should have restrictive filesystem permissions.
## Authorization
AIM authorization is based on membership in a configured group resolved
through NSS/SSSD/winbind/local group services. The configured group name
is authoritative; numeric GIDs may differ across hosts.
Operators should verify effective membership with:
``` bash
getent group '<required-group>'
id
```