160 lines
6.9 KiB
HTML
160 lines
6.9 KiB
HTML
<!DOCTYPE html>
|
|
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8"/>
|
|
<meta content="IE=edge" http-equiv="X-UA-Compatible"/>
|
|
<meta content="width=device-width, initial-scale=1.0" name="viewport"/>
|
|
<link href="https://git.tylconsulting.it/thothii-docs/install/dwh-auth-server/" rel="canonical"/>
|
|
<link href="../../img/favicon.ico" rel="shortcut icon"/>
|
|
<meta content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" name="viewport"/>
|
|
<title>Server - ThothII Docs</title>
|
|
<link href="../../css/bootstrap-3.3.7.min.css" rel="stylesheet"/>
|
|
<link href="../../css/font-awesome-4.7.0.css" rel="stylesheet"/>
|
|
<link href="../../css/base.css" rel="stylesheet"/>
|
|
<link href="../../css/highlight.css" rel="stylesheet"/>
|
|
<link href="../../stylesheets/extra.css" rel="stylesheet"/>
|
|
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries -->
|
|
<!--[if lt IE 9]>
|
|
<script src="https://oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js"></script>
|
|
<script src="https://oss.maxcdn.com/libs/respond.js/1.3.0/respond.min.js"></script>
|
|
<![endif]-->
|
|
<script src="../../js/jquery-3.2.1.min.js"></script>
|
|
<script src="../../js/bootstrap-3.3.7.min.js"></script>
|
|
<script src="../../js/highlight.pack.js"></script>
|
|
<base target="_top"/>
|
|
<script>
|
|
var base_url = '../..';
|
|
var is_top_frame = false;
|
|
|
|
var pageToc = [
|
|
{title: "dwh-auth: server guide", url: "#_top", children: [
|
|
{title: "Security boundaries", url: "#security-boundaries" },
|
|
{title: "Installation", url: "#installation" },
|
|
{title: "Creating and revoking keys", url: "#creating-and-revoking-keys" },
|
|
{title: "Nginx integration", url: "#nginx-integration" },
|
|
]},
|
|
];
|
|
|
|
</script>
|
|
<script src="../../js/base.js"></script>
|
|
<script src="../../javascripts/layout-init.js"></script>
|
|
</head>
|
|
<body>
|
|
<script>
|
|
if (is_top_frame) { $('body').addClass('wm-top-page'); }
|
|
</script>
|
|
<div class="container-fluid wm-page-content">
|
|
<a name="_top"></a>
|
|
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
|
|
<div class="wm-article-nav pull-right">
|
|
<a class="btn btn-xs btn-default pull-right" href="../dwh-auth-client-enrollment/">
|
|
Next
|
|
<i aria-hidden="true" class="fa fa-chevron-right"></i>
|
|
</a>
|
|
<a class="btn btn-xs btn-link" href="../dwh-auth-client-enrollment/">
|
|
Client enrollment
|
|
</a>
|
|
</div>
|
|
<div class="wm-article-nav">
|
|
<a class="btn btn-xs btn-default pull-left" href="../../usage/memory/">
|
|
<i aria-hidden="true" class="fa fa-chevron-left"></i>
|
|
Previous</a><a class="btn btn-xs btn-link" href="../../usage/memory/">
|
|
Memory
|
|
</a>
|
|
</div>
|
|
</div>
|
|
<h1 id="dwh-auth-server-guide"><code>dwh-auth</code>: server guide<a class="headerlink" href="#dwh-auth-server-guide" title="Permanent link">¶</a></h1>
|
|
<p><code>dwh-auth</code> protects the REST <code>/dwh/</code> route with a separate key for each ThothII installation.
|
|
It runs as a separate Linux service, does not read DWH data, and does not connect directly to
|
|
PostgreSQL.</p>
|
|
<div class="mermaid">flowchart LR
|
|
CLIENT["Installazione ThothII"] -->|"X-API-Key"| NGINX["Nginx"]
|
|
NGINX --> AUTH["dwh-auth\nUnix socket"]
|
|
AUTH --> REGISTRY["Registro chiavi\nactive e revoked"]
|
|
AUTH -->|"authorized"| REST["DWH REST"]
|
|
</div>
|
|
<h2 id="security-boundaries">Security boundaries<a class="headerlink" href="#security-boundaries" title="Permanent link">¶</a></h2>
|
|
<ul>
|
|
<li>A key identifies an installation, not a person.</li>
|
|
<li>Keys and backups stay in protected files and never enter Git, logs, arguments, or public JSON.</li>
|
|
<li>The registry stores digests and metadata, never the key in plaintext.</li>
|
|
<li>The REST route must be exposed only through verified TLS.</li>
|
|
</ul>
|
|
<h2 id="installation">Installation<a class="headerlink" href="#installation" title="Permanent link">¶</a></h2>
|
|
<p>Il servizio usa questi percorsi:</p>
|
|
<table>
|
|
<thead>
|
|
<tr>
|
|
<th>Oggetto</th>
|
|
<th>Percorso</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<tr>
|
|
<td>Binario</td>
|
|
<td><code>/usr/local/sbin/dwh-auth</code></td>
|
|
</tr>
|
|
<tr>
|
|
<td>Unit systemd</td>
|
|
<td><code>/etc/systemd/system/dwh-auth.service</code></td>
|
|
</tr>
|
|
<tr>
|
|
<td>Registro</td>
|
|
<td><code>/var/lib/dwh-auth/</code></td>
|
|
</tr>
|
|
<tr>
|
|
<td>Socket</td>
|
|
<td><code>/run/dwh-auth/verify.sock</code></td>
|
|
</tr>
|
|
<tr>
|
|
<td>Consegne protette</td>
|
|
<td><code>/root/dwh-auth-provision/</code></td>
|
|
</tr>
|
|
</tbody>
|
|
</table>
|
|
<p>Install the binary and unit with <code>root</code> ownership, create the <code>dwh-auth</code> service user, and enable
|
|
the unit with <code>systemctl enable --now dwh-auth</code>. The socket must be accessible to Nginx's group.</p>
|
|
<h2 id="creating-and-revoking-keys">Creating and revoking keys<a class="headerlink" href="#creating-and-revoking-keys" title="Permanent link">¶</a></h2>
|
|
<p>Esempio per l'installazione ACME Limited:</p>
|
|
<pre class="highlight"><code class="language-bash">sudo dwh-auth --registry-root /var/lib/dwh-auth key create \
|
|
--installation-id acme-factory-primary \
|
|
--description acme-factory-primary \
|
|
--output /root/dwh-auth-provision/acme-factory-primary.key</code></pre>
|
|
<p>Deliver the file through an enterprise vault or an authenticated channel. To rotate a key, create
|
|
a new one, distribute it, update the client, and revoke the old one using its public ID:</p>
|
|
<pre class="highlight"><code class="language-bash">sudo dwh-auth --registry-root /var/lib/dwh-auth key revoke \
|
|
--key-id PUBLIC_KEY_ID \
|
|
--reason scheduled-rotation</code></pre>
|
|
<p>Revocation is permanent. Keep encrypted registry backups before every mutation.</p>
|
|
<h2 id="nginx-integration">Nginx integration<a class="headerlink" href="#nginx-integration" title="Permanent link">¶</a></h2>
|
|
<p>Nginx forwards the key to the <code>dwh-auth</code> socket. Only an authorized response allows the request
|
|
to reach DWH REST. Missing, unknown, expired, or revoked keys receive <code>401</code>; an unavailable
|
|
service or registry produces <code>503</code>.</p>
|
|
<br/>
|
|
<div aria-label="navigation" class="row wm-article-nav-buttons" role="navigation">
|
|
<div class="wm-article-nav pull-right">
|
|
<a class="btn btn-xs btn-default pull-right" href="../dwh-auth-client-enrollment/">
|
|
Next
|
|
<i aria-hidden="true" class="fa fa-chevron-right"></i>
|
|
</a>
|
|
<a class="btn btn-xs btn-link" href="../dwh-auth-client-enrollment/">
|
|
Client enrollment
|
|
</a>
|
|
</div>
|
|
<div class="wm-article-nav">
|
|
<a class="btn btn-xs btn-default pull-left" href="../../usage/memory/">
|
|
<i aria-hidden="true" class="fa fa-chevron-left"></i>
|
|
Previous</a><a class="btn btn-xs btn-link" href="../../usage/memory/">
|
|
Memory
|
|
</a>
|
|
</div>
|
|
</div>
|
|
<br/>
|
|
</div>
|
|
<footer class="container-fluid wm-page-content">
|
|
<p>Documentation built with <a href="https://www.mkdocs.org/">MkDocs</a> using <a href="https://github.com/gristlabs/mkdocs-windmill">Windmill</a> theme by Grist Labs.</p>
|
|
</footer>
|
|
<script type="module">import mermaid from "https://unpkg.com/mermaid@10.4.0/dist/mermaid.esm.min.mjs";
|
|
mermaid.initialize({});</script></body>
|
|
</html> |