agent-substrate / agent-substrate/substrate

Define least-privilege role design for Postgres

Open
#997 0 comments 0 reactions 0 assignees View on GitHub
area/security kind/feature
Dominant language
Go
Stars
1.8k
Forks
316
Avg merge
2d 43m
Merged PRs (30d)
287

Description

ateapi currently connects to PostgreSQL as the `postgres` superuser. The HBA rule accepts any database and requested role from any client holding a certificate issued by the pod-identity CA. ateapi also applies its embedded schema during startup, coupling normal runtime access with DDL privileges.

https://github.com/agent-substrate/substrate/blob/517e48eef436f0a1454e7ae1c3c5db531209e4a9/manifests/ate-install/postgres.yaml#L34

We should move to least-privilege application roles, but the correct role split depends on the PostgreSQL migration design (tracked separately in #901) which has not yet been established. For example, migrations may need a separate owner / migrator role while the running API server only receives DML privileges. HBA rules also should be restricted appropriately.

https://github.com/agent-substrate/substrate/pull/940#discussion_r3793222156

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.