fedora-cosmic: pass Kanidm token via systemd credential
Build containers / fedora-cosmic (rawhide) (push) Failing after 48s
Build containers / fedora-cosmic (44) (push) Successful in 10m50s

kanidm-unixd runs with DynamicUser=yes, so it cannot read the root-only
/etc/kanidm/unixd_token. With service_account_token_path set in
/etc/kanidm/unixd the daemon failed with PermissionDenied and no Kanidm user
resolved. Drop that setting and inject the token with LoadCredential +
KANIDM_SERVICE_ACCOUNT_TOKEN_PATH through a generated drop-in.

Verified in a QEMU VM: kanidm-unixd active, 'kanidm-unix status' online,
'getent passwd job' resolves.
This commit is contained in:
2026-09-27 17:59:36 +02:00
parent 7693e22b08
commit a5c6170ac0
2 changed files with 13 additions and 4 deletions
+8
View File
@@ -137,10 +137,18 @@ seed_kanidm_token() {
if [[ -n "${KANIDM_UNIXD_TOKEN:-}" ]]; then
printf '%s\n' "${KANIDM_UNIXD_TOKEN}" > "${dir}/kanidm-unixd-token"
chmod 0600 "${dir}/kanidm-unixd-token"
# kanidm-unixd is DynamicUser=yes, so it cannot read the root-only token
# file directly; hand it over as a systemd credential instead.
cat > "${dir}/kanidm-unixd-token.conf" <<'EOF'
[Service]
LoadCredential=unixd_token:/etc/kanidm/unixd_token
Environment=KANIDM_SERVICE_ACCOUNT_TOKEN_PATH=%d/unixd_token
EOF
cat > "${out}" <<'EOF'
# Generated by build.sh from the KANIDM_UNIXD_TOKEN secret.
add-files:
- ["kanidm-unixd-token", "/etc/kanidm/unixd_token"]
- ["kanidm-unixd-token.conf", "/usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf"]
EOF
else
cat > "${out}" <<'EOF'
+5 -4
View File
@@ -14,7 +14,8 @@ selinux = true
# Members of this Kanidm POSIX group are allowed to log in via PAM.
pam_allowed_login_groups = ["unix_users"]
# Token for the Kanidm service account used to resolve identities. Provision it
# at /etc/kanidm/unixd_token (a single line) after install, or remove this line
# if the server permits anonymous reads.
service_account_token_path = "/etc/kanidm/unixd_token"
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
# so the service account token (when seeded) is passed as a systemd credential
# via the build.sh-generated drop-in
# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf.
# Do not set service_account_token_path here.