feat: agent enrollment, per-host SSO redirect URIs, seed hierarchy (v1.42.0)
Rolls up sso-manager-node v1.29.0, theta-agent v1.4.0, proxy v1.34.0 and jump-host v1.19.0. Per-host SSO returned "400 redirect_uri is not registered for this client". The bootstrap registered only the proxy's own management callback, but per-host SSO calls back to https://<protected-host>/__proxy_auth/callback -- a different URL per proxied host, all against that one OAuth client. Now registers the wildcard + apex patterns, and backfills them onto existing clients so upgraded stacks are fixed too. theta-proxy and theta-jump were seeded as hosts and then left childless while their services hung off the stack host. Services now parent to the host that runs them; reparent() corrects existing installs, but only when the current parent is the one the old code set. The proxy gets a read-only SSO API token (minted before the OpenBao snapshot so the running proxy receives it) backing the per-host SSO group autocomplete, and the sso-broker policy grants secret/agent/* for the SSO's persistent theta-agent signing key. BREAKING: theta-agents must be re-enrolled, and ./setup.sh must be re-run for the new OpenBao grant. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -398,6 +398,12 @@ module.exports = {
|
||||
groupsClaim: 'groups',
|
||||
usernameClaim: 'preferred_username',
|
||||
},
|
||||
// Read-only SSO management API access, used to list directory groups for the
|
||||
// per-host SSO allow-list autocomplete. apiToken is minted by the bootstrap.
|
||||
sso: {
|
||||
url: 'http://sso-manager:3001',
|
||||
apiToken: '',
|
||||
},
|
||||
ldap: {
|
||||
url: 'ldaps://sso-manager:636',
|
||||
bindDN: $(js_str "cn=ldapclient,ou=people,${dn}"),
|
||||
@@ -889,6 +895,11 @@ path "secret/data/apps/*" { capabilities = ["create", "read", "update", "delete"
|
||||
path "secret/metadata/apps/*" { capabilities = ["list", "read", "delete"] }
|
||||
path "secret/data/plugins/*" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||
path "secret/metadata/plugins/*" { capabilities = ["list", "read", "delete"] }
|
||||
# The Ed25519 key the SSO signs high-risk theta-agent commands with. It must
|
||||
# persist across restarts: agents pin the matching public key in agent.yml, so
|
||||
# a key that changes on every boot makes signature verification meaningless.
|
||||
path "secret/data/agent/*" { capabilities = ["create", "read", "update", "delete", "list"] }
|
||||
path "secret/metadata/agent/*" { capabilities = ["list", "read", "delete"] }
|
||||
path "auth/token/create/sso-broker" { capabilities = ["update"] }
|
||||
path "auth/token/create/sso-app" { capabilities = ["update"] }
|
||||
path "auth/token/renew-accessor" { capabilities = ["update"] }
|
||||
|
||||
Reference in New Issue
Block a user