467 lines
29 KiB
XML
Executable File
467 lines
29 KiB
XML
Executable File
<?xml version="1.0" encoding="UTF-8"?>
|
|
<!--
|
|
SysDeck - PolKit Policy
|
|
Author: Jeremy Anderson (https://dcos.net)
|
|
|
|
Cockpit-bridge runs as the logged-in user. When a bridge helper needs to
|
|
perform a privileged operation (modify the firewall, install a package,
|
|
flash firmware, manage LUKS volumes), it goes through pkexec + polkit.
|
|
This file defines the actions that SysDeck's bridge helpers can request.
|
|
|
|
Without this file, privileged bridge operations fail with "Not authorized:
|
|
The user does not have permission to perform this action." Cockpit-ws
|
|
grants proper auth context only to registered applications — see
|
|
packaging/sysdeck.metainfo.xml for the AppStream registration.
|
|
|
|
Install this file to /usr/share/polkit-1/actions/org.sysdeck.policy so
|
|
that polkit picks it up at install time. The user will be prompted to
|
|
authenticate (via cockpit's auth dialog or the system's polkit agent)
|
|
the first time a privileged operation is requested in a session.
|
|
|
|
Coarse-grained by design: one action per privilege domain. Refine to
|
|
per-operation actions (org.sysdeck.firewall.add-rule, etc.) once the
|
|
bridge helpers grow more sophisticated.
|
|
-->
|
|
<!DOCTYPE policyconfig PUBLIC
|
|
"-//freedesktop//DTD PolicyKit Policy configuration 1.0//EN"
|
|
"http://www.freedesktop.org/standards/PolicyKit/1/policyconfig.dtd">
|
|
<policyconfig>
|
|
|
|
<vendor>SysDeck</vendor>
|
|
<vendor_url>https://dcos.net</vendor_url>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- System management: systemctl start/stop/enable/disable, -->
|
|
<!-- hostnamectl, timedatectl, localectl, machinectl. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.system.manage">
|
|
<description>Manage system services and configuration</description>
|
|
<description xml:lang="en">Manage system services and configuration</description>
|
|
<message>System policy prevents SysDeck from managing system services and configuration.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from managing system services and configuration.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/hostnamectl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/timedatectl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/localectl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/loginctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/machinectl</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Firewall: nftables rule management (nft add/insert/delete/ -->
|
|
<!-- flush). Read-only operations (nft list) do not need this. -->
|
|
<!-- -->
|
|
<!-- v0.0.36: extended to authorize the Cilium eBPF backend. -->
|
|
<!-- Per user directive: "next we will add cilium support as a -->
|
|
<!-- drop down option in the fw area, the user can select custom -->
|
|
<!-- which is default with the templates that are basic. or they -->
|
|
<!-- can select celium, or smoothwall or ipfire or other firewall -->
|
|
<!-- scripts that install cleanly with value for ebpf era and -->
|
|
<!-- nftables." The cilium backend uses the cilium CLI + cilium- -->
|
|
<!-- agent binary + (optionally) helm for K8s-based install. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.firewall.modify">
|
|
<description>Modify firewall rules (nftables + Cilium eBPF)</description>
|
|
<description xml:lang="en">Modify firewall rules (nftables + Cilium eBPF)</description>
|
|
<message>System policy prevents SysDeck from modifying firewall rules.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from modifying firewall rules.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<!-- nftables (nftables-native backends: custom, smoothwall, ipfire) -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/nft</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/nft</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/iptables</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/ip6tables</annotate>
|
|
<!-- v0.0.36: Cilium eBPF backend -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/cilium</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/cilium</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/cilium-agent</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/cilium-agent</annotate>
|
|
<!-- v0.0.36: helm for K8s-based Cilium install -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/helm</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/helm</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Package management: pacman, emerge, lunar, sorcery, xbps, -->
|
|
<!-- apk, zypper, dnf/yum, apt install/remove/upgrade. -->
|
|
<!-- Read-only operations (list, search, info) do not need this. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.packages.modify">
|
|
<description>Install, remove, and upgrade system packages</description>
|
|
<description xml:lang="en">Install, remove, and upgrade system packages</description>
|
|
<message>System policy prevents SysDeck from modifying installed packages.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from modifying installed packages.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/pacman</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/emerge</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/lunar</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/sorcery</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/xbps-install</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/sbin/apk</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/zypper</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/apt</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/dnf</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/yum</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Firmware: fwupdmgr update/install, tpm2-tools operations. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.firmware.modify">
|
|
<description>Update firmware and manage TPM 2.0 state</description>
|
|
<description xml:lang="en">Update firmware and manage TPM 2.0 state</description>
|
|
<message>System policy prevents SysDeck from modifying firmware or TPM state.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from modifying firmware or TPM state.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/fwupdmgr</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/tpm2</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Encryption vaults: cryptsetup luksFormat/open/close, -->
|
|
<!-- LUKS key management. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.vault.modify">
|
|
<description>Manage LUKS encryption volumes</description>
|
|
<description xml:lang="en">Manage LUKS encryption volumes</description>
|
|
<message>System policy prevents SysDeck from managing LUKS volumes.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from managing LUKS volumes.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/cryptsetup</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Image builder (v0.0.30+): mkosi + archiso on Arch; vmdb2 + -->
|
|
<!-- live-build on Debian. osbuild / livemedia-creator (Fedora- -->
|
|
<!-- only) removed — the suite no longer targets Fedora/RHEL for -->
|
|
<!-- the Builder panel. -->
|
|
<!-- v0.0.31+: the build/profile-create/profile-delete subcommands -->
|
|
<!-- also need write access to /etc/mkosi/, /etc/vmdb2/ and -->
|
|
<!-- /var/lib/sysdeck/builder/. The bridge runs the backend via -->
|
|
<!-- subprocess; the cockpit superuser channel handles root priv. -->
|
|
<!-- v0.1.0: profile-import-packages also queries the host's -->
|
|
<!-- package manager (pacman -Qqe / apt-mark showmanual / the dnf -->
|
|
<!-- repoquery userinstalled filter) to capture the operator's -->
|
|
<!-- explicitly-installed package set. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.builder.modify">
|
|
<description>Build system images and ISOs</description>
|
|
<description xml:lang="en">Build system images and ISOs</description>
|
|
<message>System policy prevents SysDeck from building system images.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from building system images.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/mkosi</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/mkarchiso</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/vmdb2</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/lb</annotate>
|
|
<!-- v0.1.0: host package-list query for profile-import-packages. -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/pacman</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/apt-mark</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/dnf</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/emerge</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/lvu</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/gaze</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/xbps-query</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/sbin/apk</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/zypper</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- SysDeck Fester (v0.0.31+): DAG-driven build orchestration. -->
|
|
<!-- The v0.0.31 fester bridge helper still runs `systemctl list- -->
|
|
<!-- units` in read-only mode (no polkit needed). This action -->
|
|
<!-- covers the future DAG-orchestration path that will start/ -->
|
|
<!-- stop build-farm services and read journal logs. The action -->
|
|
<!-- is unused in v0.0.31 but ships now so admins can set up -->
|
|
<!-- polkit rules before the orchestrator lands. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.fester.modify">
|
|
<description>Manage SysDeck Fester build-farm orchestration</description>
|
|
<description xml:lang="en">Manage SysDeck Fester build-farm orchestration</description>
|
|
<message>System policy prevents SysDeck Fester from managing build-farm services.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck Fester from managing build-farm services.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/journalctl</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Policy & Permissions (v0.0.32+): ACLs, cgroups, VLANs, -->
|
|
<!-- eBPF namespace separation, AppArmor (optional). -->
|
|
<!-- v0.0.33+: extends to Smack, TOMOYO, Yama, LoadPin, Lockdown, -->
|
|
<!-- BPF-LSM, Landlock, and file capabilities (setcap/getcap). -->
|
|
<!-- -->
|
|
<!-- Per user directive: "modern policy management and -->
|
|
<!-- permissions manager for groups. such as acl, cgroups, -->
|
|
<!-- vlans, ebpf namespace separation and related policies. -->
|
|
<!-- we can skip selinux its native. we can implement apparmor -->
|
|
<!-- but its not default on my machine so make it optional." -->
|
|
<!-- -->
|
|
<!-- v0.0.33 directive: "lets now add smack, tomoyo, yama and -->
|
|
<!-- others as well to the same policy module." -->
|
|
<!-- -->
|
|
<!-- SELinux is skipped (native to host distro). AppArmor is -->
|
|
<!-- optional — the bridge auto-detects whether it is compiled -->
|
|
<!-- into the kernel; if absent, the panel renders an install -->
|
|
<!-- hint instead of an empty table. Smack, TOMOYO, Yama, -->
|
|
<!-- LoadPin, Lockdown, BPF-LSM, and Landlock follow the same -->
|
|
<!-- pattern. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.policy.modify">
|
|
<description>Manage policy and permissions (ACLs, cgroups, VLANs, eBPF, file capabilities, LSM stack: AppArmor/Smack/TOMOYO/Yama/LoadPin/Lockdown/BPF-LSM/Landlock)</description>
|
|
<description xml:lang="en">Manage policy and permissions (ACLs, cgroups, VLANs, eBPF, file capabilities, LSM stack: AppArmor/Smack/TOMOYO/Yama/LoadPin/Lockdown/BPF-LSM/Landlock)</description>
|
|
<message>System policy prevents SysDeck from modifying ACLs, cgroups, VLANs, eBPF programs, file capabilities, or LSM state.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from modifying ACLs, cgroups, VLANs, eBPF programs, file capabilities, or LSM state.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<!-- ACLs -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/setfacl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/setfacl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/getfacl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/getfacl</annotate>
|
|
<!-- cgroups (mkdir is the only required binary) -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/mkdir</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/mkdir</annotate>
|
|
<!-- bpffs / eBPF pin -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/mount</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/mount</annotate>
|
|
<!-- VLANs -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/ip</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/ip</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/vconfig</annotate>
|
|
<!-- eBPF -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/bpftool</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/bpftool</annotate>
|
|
<!-- namespaces (read-only enumerate, but polkit annotation is harmless) -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/lsns</annotate>
|
|
<!-- AppArmor (optional) -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/aa-enforce</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/aa-enforce</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/aa-complain</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/aa-complain</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/aa-status</annotate>
|
|
<!-- v0.0.33: Smack userspace tools -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/smackload</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/smackcipsos</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/smackcipso</annotate>
|
|
<!-- v0.0.33: TOMOYO userspace tools -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/tomoyo-setprofile</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/tomoyo-set-profile</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/tomoyo-savepolicy</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/tomoyo-init</annotate>
|
|
<!-- v0.0.33: File capabilities (setcap / getcap) -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/setcap</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/setcap</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/getcap</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/getcap</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- DB Control (v0.0.32): start/stop/restart database engines. -->
|
|
<!-- The bridge helper runs `systemctl start/stop/restart -->
|
|
<!-- <engine>.service` directly (the v0.0.15-era `sudo systemctl` -->
|
|
<!-- shell-out was the bug the user complained about in v0.0.31 — -->
|
|
<!-- "the update needs sudo so the command fails" — same root -->
|
|
<!-- cause). The cockpit way (v0.0.31+ pattern): the JS panel -->
|
|
<!-- passes { superuser: 'try' } to cockpit.spawn so the cockpit -->
|
|
<!-- bridge prompts the operator via polkit for this action. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.db.modify">
|
|
<description>Start, stop, and restart database engines</description>
|
|
<description xml:lang="en">Start, stop, and restart database engines</description>
|
|
<message>System policy prevents SysDeck from managing database engine services.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from managing database engine services.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/systemctl</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Jellyfin Media Server (v0.0.35): start/stop/restart -->
|
|
<!-- jellyfin.service. Per user directive: "next we will -->
|
|
<!-- integrate a jellyfin management module where it starts, -->
|
|
<!-- stops, and loads the admin panel in the module." The -->
|
|
<!-- bridge runs `systemctl start/stop/restart jellyfin.service` -->
|
|
<!-- directly; the JS panel passes { superuser: 'try' } so -->
|
|
<!-- polkit prompts the operator. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.jellyfin.modify">
|
|
<description>Start, stop, and restart the Jellyfin media server</description>
|
|
<description xml:lang="en">Start, stop, and restart the Jellyfin media server</description>
|
|
<message>System policy prevents SysDeck from managing the Jellyfin media server.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from managing the Jellyfin media server.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/jellyfin</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Photo Manager (v0.0.35): start/stop/restart photo backend -->
|
|
<!-- services. Per user directive: "as well as a photo manager -->
|
|
<!-- of equal quality. with its own module." Multi-backend: -->
|
|
<!-- PhotoPrism, Piwigo, Lychee, Nextcloud-Memories, LibrePhotos. -->
|
|
<!-- The bridge runs `systemctl start/stop/restart <service>` -->
|
|
<!-- directly; the JS panel passes { superuser: 'try' } so -->
|
|
<!-- polkit prompts the operator. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.photos.modify">
|
|
<description>Start, stop, and restart photo management backends</description>
|
|
<description xml:lang="en">Start, stop, and restart photo management backends</description>
|
|
<message>System policy prevents SysDeck from managing photo management backend services.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from managing photo management backend services.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/photoprism</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Remote FS Manager (v0.0.35): start/stop/restart remote -->
|
|
<!-- filesystem backend services + cluster status queries. -->
|
|
<!-- Per user directive: "then a remote fs manager such as -->
|
|
<!-- ceph, and others but not nfs or amanada fs." Backends: -->
|
|
<!-- Ceph, GlusterFS, MooseFS, BeeGFS, OrangeFS. The bridge -->
|
|
<!-- runs `systemctl start/stop/restart <service>` directly; the -->
|
|
<!-- JS panel passes { superuser: 'try' } so polkit prompts the -->
|
|
<!-- operator. Cluster-info subcommand also calls ceph, gluster, -->
|
|
<!-- moosefs-cli, beegfs-ctl, pvfs2-server — annotated here so -->
|
|
<!-- polkit allows them under the same action. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.remotefs.modify">
|
|
<description>Start, stop, and restart remote filesystem backends (Ceph, GlusterFS, MooseFS, BeeGFS, OrangeFS)</description>
|
|
<description xml:lang="en">Start, stop, and restart remote filesystem backends (Ceph, GlusterFS, MooseFS, BeeGFS, OrangeFS)</description>
|
|
<message>System policy prevents SysDeck from managing remote filesystem backend services.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from managing remote filesystem backend services.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/systemctl</annotate>
|
|
<!-- Ceph -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/ceph</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/ceph</annotate>
|
|
<!-- GlusterFS -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/gluster</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/gluster</annotate>
|
|
<!-- MooseFS -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/moosefs-cli</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/moosefs-cli</annotate>
|
|
<!-- BeeGFS -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/beegfs-ctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/opt/beegfs/sbin/beegfs-ctl</annotate>
|
|
<!-- OrangeFS / PVFS2 -->
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/pvfs2-server</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/pvfs2-server</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Kata Containers (v0.0.38): kata-runtime, kata-monitor, ctr, -->
|
|
<!-- crictl, and the QCrows kernel-bundle tools. The v0.0.38 -->
|
|
<!-- rewrite replaced the mock React bundle with a real bridge -->
|
|
<!-- that calls these binaries. Most kata subcommands are read- -->
|
|
<!-- only (list, inspect, metrics, summary, version, check, -->
|
|
<!-- pxe-status, qcrows-list) and do NOT need this action. The -->
|
|
<!-- action ships now so future mutating verbs (sandbox create / -->
|
|
<!-- stop / remove, qcrows-export, qcrows-initrd-regen) are -->
|
|
<!-- authorized when they land. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.kata.modify">
|
|
<description>Manage Kata Containers sandboxes and QCrows kernel bundles</description>
|
|
<description xml:lang="en">Manage Kata Containers sandboxes and QCrows kernel bundles</description>
|
|
<message>System policy prevents SysDeck from managing Kata Containers.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from managing Kata Containers.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/kata-runtime</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/kata-runtime</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/kata-monitor</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/kata-monitor</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/ctr</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/crictl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/qcrows-export</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/qcrows-initrd-regen</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/systemctl</annotate>
|
|
</action>
|
|
|
|
<!-- ============================================================= -->
|
|
<!-- Monitoring (v0.0.39): Prometheus + Grafana service control. -->
|
|
<!-- The shared SysDeck Monitoring panel has two tabs (Prometheus -->
|
|
<!-- + Grafana). Read-only queries (summary, targets, alerts, -->
|
|
<!-- dashboards, datasources, health, etc.) hit the HTTP APIs -->
|
|
<!-- directly and need no polkit. Mutating verbs (restart, reload) -->
|
|
<!-- invoke systemctl — this action authorizes that. -->
|
|
<!-- Prometheus is Apache-2.0; Grafana is AGPL-3.0. Neither is -->
|
|
<!-- bundled — the bridge talks to their HTTP APIs. -->
|
|
<!-- ============================================================= -->
|
|
<action id="org.sysdeck.monitoring.modify">
|
|
<description>Manage Prometheus and Grafana monitoring services</description>
|
|
<description xml:lang="en">Manage Prometheus and Grafana monitoring services</description>
|
|
<message>System policy prevents SysDeck from managing monitoring services.</message>
|
|
<message xml:lang="en">System policy prevents SysDeck from managing monitoring services.</message>
|
|
<defaults>
|
|
<allow_any>no</allow_any>
|
|
<allow_inactive>auth_admin_keep</allow_inactive>
|
|
<allow_active>auth_admin_keep</allow_active>
|
|
</defaults>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/bin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/usr/sbin/systemctl</annotate>
|
|
<annotate key="org.freedesktop.policykit.exec.path">/bin/systemctl</annotate>
|
|
</action>
|
|
|
|
</policyconfig>
|