Files
Ansible/scripts/addons/webgui/docs/PERMISSIONS-ROLLOUT.md
T
2026-09-22 19:23:17 +02:00

3.1 KiB

The behaviors below are retained from2.1.0rc2. Current candidate2.1.0rc9 targets Core3.3.0rc8/schema5 and adds reports/journal described in REPORTS.md and JOURNAL.md. Credential, read-only inventory and OS-permission boundaries here remain unchanged; old version/no-migration statements describe the earlier slice.

Managed permissions - WebGUI 2.1.0rc1

No permission change from2.0.0rc8. This document describes the existing add-on-owned contract, not instructions to recursively chown AIM.

Resource Owner/group Mode
WebGUI source, virtualenv, units root-owned Release-managed
webgui.toml root:aim-web 0640
/var/lib/aim/webgui aim-web:aim-web 0700
SQLite database aim-web:aim-web 0600
/var/lib/aim-web-executor and .ansible/tmp chain executor:native primary group 0700
passwd-home .ansible and .ansible/tmp executor:native primary group 0700
/run/aim-web-executor executor:native primary group 0711
/run/aim-web-executor/core.sock executor:aim-web 0660

Site executor is svc_bf-ansible. Systemd preserves its native primary group and grants aim-web as a unit-scoped SupplementaryGroups entry; numeric group IDs may appear in systemctl output. Other account memberships are resolved normally, so an empty explicit supplementary setting is not proof of an empty actual group list. The installer does not silently rewrite OS account memberships.

The0711 runtime directory permits traversal to the known socket path, not directory listing for unrelated users. Socket DAC and peer checks govern access. NoNewPrivileges and empty capability sets remain; no sudo or root worker. ProtectHome remains read-only with a narrow writable passwd-home .ansible/tmp exception for delegated local tasks, plus the separate process-home staging path. The installer waits for socket readiness and checks exact managed owner/mode before starting dependent services.

Verification, not manual repair

systemctl show aim-web-executor.service -p User -p Group -p SupplementaryGroups
stat -c '%U:%G %a %n' \
  /var/lib/aim-web-executor \
  /var/lib/aim-web-executor/.ansible/tmp \
  /home/svc_bf-ansible/.ansible/tmp \
  /run/aim-web-executor \
  /run/aim-web-executor/core.sock \
  /etc/ansible/scripts/config/webgui.toml
sudo journalctl -u aim-web-executor.service -n 60 --no-pager

The release-managed ExecStartPre runs staging checks inside the real executor unit. Interactive sudo -u svc_bf-ansible alone does not reproduce unit-scoped aim-web group access to webgui.toml. Do not make that config world-readable to hide the distinction.

Outside add-on ownership

AIM source/configuration, authorization groups, inventory/Vaults, canonical owner-only0600 private keys, /etc/ssh/ssh_known_hosts, certificates and Nginx remain Core/operator managed. The add-on does not enroll host keys or infer their trust from HOME. Keep independently verified effective SSH trust. Unknown unit drop-ins stop deployment for review; do not silently restore obsolete privilege/capability workarounds.

The new explorer, activity and insights pages require no new write path, group, service, port or secret permission.