HydraIssues

Use a dedicated Perforce super service account instead of hydra_admin for provisioning
closed unclassified Project: hydraperforceprovision Reporter: 15 Aug 2026 21:30

Description

hydraperforceprovision (and the per-org p4d scales it manages) currently authenticate to Perforce as the human super user hydra_admin. A person's password should not live inside a service. Replace it with a dedicated non-human super service account per p4d instance.

Why

  • The provisioning service holds hydra_admin's password in /etc/hydraperforceprovision/config.yaml (mode 600) to create depots/users/protections. If that human's password is rotated, the service breaks; if the service is compromised, the human's credentials leak.
  • Same on the fleet path: ensure-server creates each scale's super as hydra_admin (fleet.super_user). Every org scale should instead get a dedicated super service account.
  • This is the standing recommendation already documented in hydraperforceprovision/docs/runbooks/runbook.md (Security notes) and repeated in #484.

Scope

  1. On the live Gallo-Romeins scale (galloromeinsmuseum on hydraskin-perforce-1, 178.105.185.28): create a dedicated super, e.g. provision_svc, with its own strong password; grant super in the protections table; verify it can create depots/users/protections.
  2. Point hydraperforceprovision config perforce.admin_user/admin_password at provision_svc; restart; re-verify a provision call end to end.
  3. Set fleet.super_user: provision_svc so future ensure-server scales use it (each scale still gets its OWN generated password, stored 0600 in the scale state file).
  4. Keep hydra_admin as the break-glass human super (do not delete); document that services use provision_svc, humans use hydra_admin.
  5. Store the provision_svc password out of band (not in git); consider moving service secrets to Pantheon with only a handle in config (ties into the #484 state-file-security note).

Notes

  • Security Level 4 on the scales: set the password by piping to interactive p4 passwd (never -P), and clear the forced-reset flag for the service account by changing its own password (a service can't do an interactive first-login reset).
  • Least-privilege caveat: the account needs super for depot/protection management, so it is privileged by necessity — the win is decoupling it from a human identity, not reducing its rights.
  • Related: #484 (provisioning automation), #486 (Gallo-Romeins onboarding).

Comments (2)

claude-ops 15 Aug 2026 21:49

Related: iamnim OIDC/SAML IdP support requested on the NimsForest tracker as nimsforest #206. That is the enabler for logging into Perforce as an iamnim identity (Helix Authentication Service / auth-check-sso trigger need an OIDC/SAML IdP to point at). This issue (dedicated service account) stands on its own and does not depend on #206 — the service account uses a p4 password regardless; #206 is about HUMAN super login via iamnim SSO.

claude-ops 15 Aug 2026 21:58

DONE 2026-08-15 on the live Gallo-Romeins scale (galloromeinsmuseum @ hydraskin-perforce-1).

  • Created dedicated super service account provision_svc (standard user, super via super user provision_svc * //... appended to protections — existing lines/koen/watcher untouched). Cleared the Security-Level-4 forced-reset flag by changing its password as itself so it can log in non-interactively. Verified maxaccess=super and it can run admin commands.
  • Repointed hydraperforceprovision config: admin_user/admin_password -> provision_svc; restarted; health ok.
  • Verified END TO END: provisioned a throwaway org through the running service authenticating as provision_svc (created depot + least-privilege user + temp password), then cleaned it up. koen + watcher unaffected.
  • hydra_admin retained as BREAK-GLASS human super (still in protections; not used by any service).
  • fleet.super_user: the deployed config has no fleet block yet (ensure-server not wired on this node), so nothing to set now; the runbook says future ensure-server scales should use provision_svc.

Credentials delivered to cederik out of band (provision_svc password NOT in this issue). Rotate via p4 passwd provision_svc as a super.

LICENSE NOTE: two super seats (hydra_admin break-glass + provision_svc) plus the watcher's read hydraperforce_svc = 3 of the free tier's 5 per-server seats, leaving 2 for creators (koen is 1). If Cyborn adds several devs this scale hits the cap -> paid license or consolidation. Documented in the runbook.

Safe to close. Human super login via iamnim SSO remains separate (nimsforest #206).