From a5c6170ac020ffdfe55a3cedfd0b1beec2c28194 Mon Sep 17 00:00:00 2001 From: Wesley van Tilburg Date: Sun, 27 Sep 2026 17:59:36 +0200 Subject: [PATCH] fedora-cosmic: pass Kanidm token via systemd credential kanidm-unixd runs with DynamicUser=yes, so it cannot read the root-only /etc/kanidm/unixd_token. With service_account_token_path set in /etc/kanidm/unixd the daemon failed with PermissionDenied and no Kanidm user resolved. Drop that setting and inject the token with LoadCredential + KANIDM_SERVICE_ACCOUNT_TOKEN_PATH through a generated drop-in. Verified in a QEMU VM: kanidm-unixd active, 'kanidm-unix status' online, 'getent passwd job' resolves. --- build.sh | 8 ++++++++ images/fedora-cosmic/files/kanidm-unixd | 9 +++++---- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/build.sh b/build.sh index de6e042..50393c8 100755 --- a/build.sh +++ b/build.sh @@ -137,10 +137,18 @@ seed_kanidm_token() { if [[ -n "${KANIDM_UNIXD_TOKEN:-}" ]]; then printf '%s\n' "${KANIDM_UNIXD_TOKEN}" > "${dir}/kanidm-unixd-token" chmod 0600 "${dir}/kanidm-unixd-token" + # kanidm-unixd is DynamicUser=yes, so it cannot read the root-only token + # file directly; hand it over as a systemd credential instead. + cat > "${dir}/kanidm-unixd-token.conf" <<'EOF' +[Service] +LoadCredential=unixd_token:/etc/kanidm/unixd_token +Environment=KANIDM_SERVICE_ACCOUNT_TOKEN_PATH=%d/unixd_token +EOF cat > "${out}" <<'EOF' # Generated by build.sh from the KANIDM_UNIXD_TOKEN secret. add-files: - ["kanidm-unixd-token", "/etc/kanidm/unixd_token"] + - ["kanidm-unixd-token.conf", "/usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf"] EOF else cat > "${out}" <<'EOF' diff --git a/images/fedora-cosmic/files/kanidm-unixd b/images/fedora-cosmic/files/kanidm-unixd index 70608fa..910fabd 100644 --- a/images/fedora-cosmic/files/kanidm-unixd +++ b/images/fedora-cosmic/files/kanidm-unixd @@ -14,7 +14,8 @@ selinux = true # Members of this Kanidm POSIX group are allowed to log in via PAM. pam_allowed_login_groups = ["unix_users"] -# Token for the Kanidm service account used to resolve identities. Provision it -# at /etc/kanidm/unixd_token (a single line) after install, or remove this line -# if the server permits anonymous reads. -service_account_token_path = "/etc/kanidm/unixd_token" +# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file, +# so the service account token (when seeded) is passed as a systemd credential +# via the build.sh-generated drop-in +# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf. +# Do not set service_account_token_path here.