state: disable key expiry for nodes with approved advertise-tags
Extends #2971 fix to also cover nodes that authenticate as users but become tagged immediately via --advertise-tags. When RequestTags are approved by policy, the node's expiry is now disabled, consistent with nodes registered via tagged PreAuthKeys.
This commit is contained in:
parent
1d9900273e
commit
00f22a8443
1 changed files with 4 additions and 0 deletions
|
|
@ -1188,6 +1188,10 @@ func (s *State) createAndSaveNewNode(params newNodeParams) (types.NodeView, erro
|
|||
nodeToRegister.Tags = approvedTags
|
||||
slices.Sort(nodeToRegister.Tags)
|
||||
nodeToRegister.Tags = slices.Compact(nodeToRegister.Tags)
|
||||
|
||||
// Tagged nodes have key expiry disabled.
|
||||
nodeToRegister.Expiry = nil
|
||||
|
||||
log.Info().
|
||||
Str("node.name", nodeToRegister.Hostname).
|
||||
Strs("tags", nodeToRegister.Tags).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue