From 092661c7ebb28e1fb24bada803de9b1284c425f0 Mon Sep 17 00:00:00 2001 From: jamesread Date: Thu, 30 Oct 2025 21:10:58 +0000 Subject: [PATCH 1/5] doc: Better default config that includes security examples and more doc links --- config.yaml | 45 ++++++++++++++++++++++++++++++++++++--------- 1 file changed, 36 insertions(+), 9 deletions(-) diff --git a/config.yaml b/config.yaml index 17599a4..ca2da10 100644 --- a/config.yaml +++ b/config.yaml @@ -5,20 +5,16 @@ # Listen on all addresses available, port 1337 listenAddressSingleHTTPFrontend: 0.0.0.0:1337 -bannerMessage: "This is an early alpha version of OliveTin 3000. Many thanks are broken, many things will change." -bannerCss: "background-color: #b2e4b2; color: black; font-size: small; text-align: center; padding: .6em; border-radius: 0.5em;" - -insecureAllowDumpSos: true -insecureAllowDumpVars: true - # Choose from INFO (default), WARN and DEBUG +# Docs: https://docs.olivetin.app/advanced_configuration/logs.html logLevel: "INFO" -# Checking for updates https://docs.olivetin.app/reference/updateChecks.html +# Docs: https://docs.olivetin.app/reference/updateChecks.html checkForUpdates: false -authLocalUsers: - enabled: true +# Docs: https://docs.olivetin.app/security/acl.html +defaultPolicy: + showDiagnostics: false # Actions are commands that are executed by OliveTin, and normally show up as # buttons on the WebUI. @@ -322,3 +318,34 @@ dashboards: - title: 'Start {{ .CurrentEntity.Names }}' - title: 'Stop {{ .CurrentEntity.Names }}' + +# This form of auth is the simplest to setup - just define users and passwords +# in the config. +# Docs: https://docs.olivetin.app/security/local.html +authLocalUsers: + enabled: true +# users: +# - username: alice +# usergroup: admins +# password: "$argon2id$v=19$m=65536,t=4,p=6$LnNW4sw+jZfa5Ex3YjfuHQ$vl8pjUJhxNmBxScV4lI3cgAZPkNB1rSrnX6ibgoAP8k" + +# OliveTin uses access control lists to match up policy and permissions to users. +# Policies affect the whole app (eg: ability to view the log list). +# Permissions affect actions (eg: ability to view a specific log). +# Docs: https://docs.olivetin.app/security/acl.html +accessControlLists: + - name: admin_acl + matchUsergroups: ["admins"] + policy: + showDiagnostics: true + permissions: + view: true + exec: true + logs: true + +# Docs: https://docs.olivetin.app/security/acl.html +defaultPermissions: + view: true + exec: true + logs: true + From 0bf313a3f722ba35036c9958f5b469dc6dca16d3 Mon Sep 17 00:00:00 2001 From: jamesread Date: Thu, 30 Oct 2025 21:14:49 +0000 Subject: [PATCH 2/5] doc: Move defaultPolicy to the end in the config --- config.yaml | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/config.yaml b/config.yaml index ca2da10..e655b36 100644 --- a/config.yaml +++ b/config.yaml @@ -9,13 +9,6 @@ listenAddressSingleHTTPFrontend: 0.0.0.0:1337 # Docs: https://docs.olivetin.app/advanced_configuration/logs.html logLevel: "INFO" -# Docs: https://docs.olivetin.app/reference/updateChecks.html -checkForUpdates: false - -# Docs: https://docs.olivetin.app/security/acl.html -defaultPolicy: - showDiagnostics: false - # Actions are commands that are executed by OliveTin, and normally show up as # buttons on the WebUI. # @@ -349,3 +342,7 @@ defaultPermissions: exec: true logs: true +# Docs: https://docs.olivetin.app/security/acl.html +defaultPolicy: + showDiagnostics: false + From f1250f9caf0b4378266feb88d50894adcb2009ab Mon Sep 17 00:00:00 2001 From: jamesread Date: Thu, 30 Oct 2025 21:24:13 +0000 Subject: [PATCH 3/5] doc: Add more security examples to default config --- config.yaml | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/config.yaml b/config.yaml index e655b36..a04d060 100644 --- a/config.yaml +++ b/config.yaml @@ -312,15 +312,29 @@ dashboards: - title: 'Start {{ .CurrentEntity.Names }}' - title: 'Stop {{ .CurrentEntity.Names }}' + +# Security - Authentication + +# This setting effectively enables or disables guests. +# If set to "true", then users will have to login to do anything. +authRequireGuestsToLogin: false + # This form of auth is the simplest to setup - just define users and passwords -# in the config. +# in the config. OliveTin also supports header-based auth, OAuth2, +# and JWT authentication which are documented separately. +# # Docs: https://docs.olivetin.app/security/local.html +# +# How to get a hashed password: +# Docs: https://docs.olivetin.app/security/local.html#_get_a_argon2id_hashed_password authLocalUsers: enabled: true # users: # - username: alice # usergroup: admins -# password: "$argon2id$v=19$m=65536,t=4,p=6$LnNW4sw+jZfa5Ex3YjfuHQ$vl8pjUJhxNmBxScV4lI3cgAZPkNB1rSrnX6ibgoAP8k" +# password: "$argon2id$v=19$m=65536,t=4,p=2$puyxA0s555TSFx7hnFLCXA$PyhLGpZtvpMMvc2DgMWkM8OJMKO55euwV5gm//1iwx4" + +# Security - Access Control Lists # OliveTin uses access control lists to match up policy and permissions to users. # Policies affect the whole app (eg: ability to view the log list). From 6782156a588e0a0a158a40a26109f3f8537a7ce8 Mon Sep 17 00:00:00 2001 From: jamesread Date: Thu, 30 Oct 2025 21:33:10 +0000 Subject: [PATCH 4/5] doc: Add date id --- config.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/config.yaml b/config.yaml index a04d060..f159bae 100644 --- a/config.yaml +++ b/config.yaml @@ -44,6 +44,7 @@ actions: # You can also rate-limit actions too. - title: date shell: date + id: date timeout: 6 icon: clock popupOnStart: execution-button From 2b1f9a924751b242ed80f5895d55691e60763b1f Mon Sep 17 00:00:00 2001 From: jamesread Date: Fri, 31 Oct 2025 09:18:45 +0000 Subject: [PATCH 5/5] doc: Better layout of default config security section --- config.yaml | 29 ++++++++++++++++------------- 1 file changed, 16 insertions(+), 13 deletions(-) diff --git a/config.yaml b/config.yaml index f159bae..ee4c6ba 100644 --- a/config.yaml +++ b/config.yaml @@ -335,11 +335,22 @@ authLocalUsers: # usergroup: admins # password: "$argon2id$v=19$m=65536,t=4,p=2$puyxA0s555TSFx7hnFLCXA$PyhLGpZtvpMMvc2DgMWkM8OJMKO55euwV5gm//1iwx4" -# Security - Access Control Lists +# Security - Access Control + +# Policies affect the whole app (eg: ability to view the log list). +# Docs: https://docs.olivetin.app/security/acl.html +defaultPolicy: + showDiagnostics: true + showLogList: true + +# Permissions affect actions (eg: ability to view a specific log). +# Docs: https://docs.olivetin.app/security/acl.html +defaultPermissions: + view: true + exec: true + logs: true # OliveTin uses access control lists to match up policy and permissions to users. -# Policies affect the whole app (eg: ability to view the log list). -# Permissions affect actions (eg: ability to view a specific log). # Docs: https://docs.olivetin.app/security/acl.html accessControlLists: - name: admin_acl @@ -351,13 +362,5 @@ accessControlLists: exec: true logs: true -# Docs: https://docs.olivetin.app/security/acl.html -defaultPermissions: - view: true - exec: true - logs: true - -# Docs: https://docs.olivetin.app/security/acl.html -defaultPolicy: - showDiagnostics: false - +# OliveTin contains many more configuration options not in this default config. +# Check out docs.olivetin.app for a setting if you feel like you're missing something.