feat(policy): add admin:SetRootAccess for disabling the root credential - #271
Conversation
Disabling root is stored as the api root_access config key, so today it is reachable by anyone holding admin:ConfigUpdate - an action that carries the whole configuration surface with it. This action lets a deployment require a second, narrower grant for that one decision, on top of ConfigUpdate, so taking root out of service is not bundled with every other config right. Not added to a canned policy: iamAdmin and infraAdmin each hold only one half of the pair, so the grant would be inert there. consoleAdmin picks it up through admin:*.
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe policy package adds ChangesRoot Access Admin Action
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit finds a root key bright, Comment |
Description
Adds
admin:SetRootAccess, and a test covering validity,admin:*matching, and which canned policies allow it.Motivation
Disabling the root credential is the
api root_accessconfig key, so today it is reachable by anyone holdingadmin:ConfigUpdate— an action that carries the whole configuration surface with it. This action lets the serverrequire a second, narrower grant for that one decision on top of
ConfigUpdate, so taking root out of service is notbundled with every other config right.
Not added to a canned policy:
iamAdminandinfraAdmineach hold only one half of the pair, so the grant would beinert there.
consoleAdminpicks it up throughadmin:*.How to test
go test ./policy/—TestSetRootAccessAdminActioncovers it. Verified by mutation: granting the action to a cannedpolicy that should not have it fails the test.
Types of changes
New feature (non-breaking). No existing action or policy changes behaviour.
Checklist
go build ./...andgo test ./policy/passThe AIStor side that enforces this action is a separate change and lands after a version bump here.
Summary by CodeRabbit