docs: define full-token Windows fixture provisioner
This commit is contained in:
+12
-7
@@ -167,18 +167,23 @@ guest deletion.
|
||||
therefore launches it at medium integrity and it must never be used to create
|
||||
or modify machine-wide SCM state. The reset snapshot has no RVBox installation.
|
||||
|
||||
To automate the real install path, provision one separate **fixture-only**
|
||||
full-token local administrator and retain its username/password solely in the
|
||||
Helium secret store. It must be a genuinely high-integrity Guest Control token;
|
||||
do not globally disable UAC or change `rvboxtest` into an always-elevated user.
|
||||
The normal harness receives it only through these environment variables:
|
||||
To automate the real install path, use the Windows built-in `Administrator`
|
||||
account as a separate **fixture-only** provisioning identity. Enable it only on
|
||||
this disposable VM, keep `FilterAdministratorToken=0` (the normal Windows 10
|
||||
default), and verify that Guest Control gives it a High Mandatory Level. This
|
||||
is the per-account exception that preserves UAC for `rvboxtest`; do **not**
|
||||
globally disable Admin Approval Mode or change `rvboxtest` into an
|
||||
always-elevated user. Store its username/password solely in the Helium secret
|
||||
store. The normal harness receives it only through these environment variables:
|
||||
|
||||
```sh
|
||||
export RVBOX_TEST_PROVISIONER_USER=FIXTURE_ONLY_FULL_ADMIN
|
||||
export RVBOX_TEST_PROVISIONER_USER=Administrator
|
||||
export RVBOX_TEST_PROVISIONER_PASSWORD_FILE=/home/cabbage/.local/share/rvbox-secrets/rvbox-win10-test-provisioner.password
|
||||
```
|
||||
|
||||
Both files remain mode `0600` on Helium and neither value is recorded in run
|
||||
If a policy or hardening configuration makes this account medium-integrity, the
|
||||
harness fails closed; do not replace it with a UAC-bypass mechanism. Both files
|
||||
remain mode `0600` on Helium and neither value is recorded in run
|
||||
reports or artifacts. `test-host install` first verifies that the reset guest
|
||||
has no `RVBoxClient`, checks the provisioner's High Mandatory Level, invokes
|
||||
the actual staged `rvbox.exe --install-service --config ...`, and polls SCM for
|
||||
|
||||
Reference in New Issue
Block a user