Files
bootc-images/images/fedora-cosmic/files/kanidm-unixd
T
Misthios a5c6170ac0
Build containers / fedora-cosmic (rawhide) (push) Failing after 48s
Build containers / fedora-cosmic (44) (push) Successful in 10m50s
fedora-cosmic: pass Kanidm token via systemd credential
kanidm-unixd runs with DynamicUser=yes, so it cannot read the root-only
/etc/kanidm/unixd_token. With service_account_token_path set in
/etc/kanidm/unixd the daemon failed with PermissionDenied and no Kanidm user
resolved. Drop that setting and inject the token with LoadCredential +
KANIDM_SERVICE_ACCOUNT_TOKEN_PATH through a generated drop-in.

Verified in a QEMU VM: kanidm-unixd active, 'kanidm-unix status' online,
'getent passwd job' resolves.
2026-09-27 17:59:36 +02:00

22 lines
664 B
Plaintext

version = "2"
# Bind cached credentials to the local TPM when one is available.
hsm_type = "tpm_if_possible"
default_shell = "/bin/bash"
home_prefix = "/home/"
home_attr = "uuid"
home_alias = "name"
use_etc_skel = true
selinux = true
[kanidm]
# Members of this Kanidm POSIX group are allowed to log in via PAM.
pam_allowed_login_groups = ["unix_users"]
# NOTE: kanidm-unixd runs with DynamicUser=yes and cannot read a root-only file,
# so the service account token (when seeded) is passed as a systemd credential
# via the build.sh-generated drop-in
# /usr/lib/systemd/system/kanidm-unixd.service.d/10-token.conf.
# Do not set service_account_token_path here.