agent-substrate / agent-substrate/substrate
Define least-privilege role design for Postgres
- 主要語言
- Go
- 星號
- 1.8k
- 分支
- 316
- 平均合併
- 2 天 43 分鐘
- 30 天內合併 PR
- 287
描述
ateapi currently connects to PostgreSQL as the `postgres` superuser. The HBA rule accepts any database and requested role from any client holding a certificate issued by the pod-identity CA. ateapi also applies its embedded schema during startup, coupling normal runtime access with DDL privileges.
https://github.com/agent-substrate/substrate/blob/517e48eef436f0a1454e7ae1c3c5db531209e4a9/manifests/ate-install/postgres.yaml#L34
We should move to least-privilege application roles, but the correct role split depends on the PostgreSQL migration design (tracked separately in #901) which has not yet been established. For example, migrations may need a separate owner / migrator role while the running API server only receives DML privileges. HBA rules also should be restricted appropriately.
https://github.com/agent-substrate/substrate/pull/940#discussion_r3793222156
貢獻指南
評估
這個 Issue 還沒有評估資料。