Page MenuHomePhabricator

Add a query/policy layer on top of SSH keys for Almanac
ClosedPublic

Authored by epriestley on Nov 5 2014, 8:14 PM.
Tags
None
Referenced Files
F14448266: D10790.id25912.diff
Thu, Dec 26, 4:16 PM
Unknown Object (File)
Thu, Dec 26, 2:33 AM
Unknown Object (File)
Sat, Dec 21, 8:44 PM
Unknown Object (File)
Thu, Dec 19, 4:21 PM
Unknown Object (File)
Thu, Dec 19, 1:39 PM
Unknown Object (File)
Thu, Dec 19, 1:39 PM
Unknown Object (File)
Wed, Dec 18, 7:49 AM
Unknown Object (File)
Mon, Dec 16, 7:43 AM
Subscribers

Details

Summary

Ref T5833. Currently, SSH keys are associated only with users, and are a bit un-modern. I want to let Almanac Devices have SSH keys so devices in a cluster can identify to one another.

For example, with hosted installs, initialization will go something like this:

  • A request comes in for company.phacility.com.
  • A SiteSource (from D10787) makes a Conduit call to Almanac on the master install to check if company is a valid install and pull config if it is.
  • This call can be signed with an SSH key which identifies a trusted Almanac Device.

In the cluster case, a web host can make an authenticated call to a repository host with similar key signing.

To move toward this, put a proper Query class on top of SSH key access (this diff). In following diffs, I'll:

  • Rename userPHID to objectPHID.
  • Move this to the auth database.
  • Provide UI for device/key association.

An alternative approach would be to build some kind of special token layer in Conduit, but I think that would be a lot harder to manage in the hosting case. This gives us a more direct attack on trusting requests from machines and recognizing machines as first (well, sort of second-class) actors without needing things like fake user accounts.

Test Plan
  • Added and removed SSH keys.
  • Added and removed SSH keys from a bot account.
  • Tried to edit an unonwned SSH key (denied).
  • Ran bin/ssh-auth, got sensible output.
  • Ran bin/ssh-auth-key, got sensible output.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley retitled this revision from to Add a query/policy layer on top of SSH keys for Almanac.
epriestley updated this object.
epriestley edited the test plan for this revision. (Show Details)
epriestley added a reviewer: btrahan.
btrahan edited edge metadata.
This revision is now accepted and ready to land.Nov 5 2014, 10:05 PM
This revision was automatically updated to reflect the committed changes.