R-180: refuse in pre-flight an archive storage the agent's token will not be granted on

The step-8 restore reads the golden as the agent's token; a storage outside PVE_STORAGES (and not
the backup target, which step 6 grants since R-185) 403'd at step 8/8 — after the token was minted
and root@pam rotated. Pre-flight now refuses it with the two remedies (move the golden, or add the
storage to --acl-storages). scripts/test_hostinstall.py: test_archive_storage_* (4).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-05 21:19:18 +02:00
parent efe76093ce
commit 7f3944eff9
2 changed files with 59 additions and 1 deletions
+18
View File
@@ -667,6 +667,17 @@ eligible_backup_drive() {
return 1
}
# _archive_storage_granted — true when the agent's token will hold the Store role on ARCHIVE_STORAGE by
# step 8 (R-180): it is in PVE_STORAGES (granted in step 4/5), or it is the backup target, which
# configure_backup_target grants in step 6 whenever it exists (R-185) — and it exists, because the
# preflight has just found it. Pure: reads the two variables only. Pinned by scripts/test_hostinstall.py
# (test_archive_storage_*).
_archive_storage_granted() {
local s
for s in "${PVE_STORAGES[@]}"; do [[ "$s" == "$ARCHIVE_STORAGE" ]] && return 0; done
[[ -n "$BACKUP_TARGET_ID" && "$ARCHIVE_STORAGE" == "$BACKUP_TARGET_ID" ]]
}
# configure_backup_target — Case A/B. Idempotent and SCENARIO-F SAFE.
configure_backup_target() {
# SCENARIO F, the hard rule: never touch a box that already has a target. The agent.json write
@@ -1926,6 +1937,13 @@ step_preflight() {
else
die "archive storage '$ARCHIVE_STORAGE' not found (pvesm status). Pass --archive-storage NAME."
fi
# R-180: the agent restores the golden FROM this storage in step 8, as its token — so the token
# must be granted there. Checked HERE, because by step 8 the token is minted, root@pam rotated
# and the agent installed (demo-hp 2026-08-03: HTTP 403 at /storage/felhom-backup at step 8/8).
_archive_storage_granted \
|| die "archive storage '$ARCHIVE_STORAGE' is not one the agent's token will be granted on (${PVE_STORAGES[*]}${BACKUP_TARGET_ID:+, and $BACKUP_TARGET_ID via the backup target}).
The restore in step 8 would fail with HTTP 403 — after the token is minted and (appliance) root@pam is rotated.
Move the golden to one of those storages (default: local), or pass --acl-storages with '$ARCHIVE_STORAGE' added."
fi
# --acl-storages existence (GL-2): the scoped ACL grants Datastore.* at each of these paths — a