agent-substrate / agent-substrate/substrate

Define least-privilege role design for Postgres

未關閉
#997 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
area/security kind/feature
主要語言
Go
星號
1.8k
分支
316
平均合併
2 天 43 分鐘
30 天內合併 PR
287

描述

ateapi currently connects to PostgreSQL as the `postgres` superuser. The HBA rule accepts any database and requested role from any client holding a certificate issued by the pod-identity CA. ateapi also applies its embedded schema during startup, coupling normal runtime access with DDL privileges.

https://github.com/agent-substrate/substrate/blob/517e48eef436f0a1454e7ae1c3c5db531209e4a9/manifests/ate-install/postgres.yaml#L34

We should move to least-privilege application roles, but the correct role split depends on the PostgreSQL migration design (tracked separately in #901) which has not yet been established. For example, migrations may need a separate owner / migrator role while the running API server only receives DML privileges. HBA rules also should be restricted appropriately.

https://github.com/agent-substrate/substrate/pull/940#discussion_r3793222156

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。