docs(auth): document runtime projection operations
This commit is contained in:
@@ -251,6 +251,14 @@ Use `profile: server`, the exact new source root/env/auth root, workspace remote
|
||||
access, Project A override, and exactly one Git transport override. Do not include the public
|
||||
session-server overlay in Project A.
|
||||
|
||||
For the projected local-auth descriptor, keep `authentication.configDirectory` as the canonical
|
||||
root and add `runtimeProjection` with a distinct absolute runtime directory plus numeric `uid: 10001`
|
||||
and `gid: 10001`. The descriptor loader includes the automatic runtime-projection override; do
|
||||
not list it manually under `overrides`. The canonical root stays `root:root 0700/0600`; the
|
||||
publisher owns the projection numerically as `10001:10001 0700/0600`. Only the projection is
|
||||
mounted read-only into core. Do not create a host user/group, edit `CURRENT` or `generations`, or
|
||||
apply these paths before the separately authorized start gate.
|
||||
|
||||
**Step 4: Validate permissions and render**
|
||||
|
||||
```bash
|
||||
@@ -274,6 +282,11 @@ Create a temporary mode-0600 password file using an echo-free prompt, then run:
|
||||
Remove the temporary input file after success and record that removal. Do not delete generated
|
||||
`auth.yaml` or `users.yaml`.
|
||||
|
||||
Before the later start gate, run the redacted projected status command and require `ready` plus
|
||||
`equal: true`. A blocked result prevents start. `auth publish` is the only repair path: it rebuilds
|
||||
from canonical authentication, including after a candidate or recovery restore outcome; it never
|
||||
promotes a retained runtime generation on its own.
|
||||
|
||||
### Task 6: Build and start the clean stack
|
||||
|
||||
**Files:**
|
||||
|
||||
Reference in New Issue
Block a user