Security

Security #

Pizza ships an API-key based authentication and role model for the data plane and management APIs. It is off by default; the shipped pizza.yml enables it.

Enabling authentication #

security:
  auth_enabled: true
  bootstrap_key: "pz_bootstrap_key"

With auth enabled, every data-plane and management request must carry a valid API key — Authorization: Bearer <key> or X-Api-Key: <key>. Unauthenticated requests are answered with 401 and a deliberately generic body. Anonymous operational-plane reads (console assets, readiness probes) stay open; mutating /_cluster and /_node management requires a key once auth is on.

The bootstrap key #

bootstrap_key is a one-shot platform_admin key minted at startup. When auth_enabled: true and no bootstrap key is configured, the node generates a random login token and prints it to the terminal at startup. Set it to "" to opt out of the bootstrap key entirely. It exists to bootstrap the first admin; prefer minted or config-declared keys for steady state.

Statically declared keys #

Keys can be declared in the config file as SHA-256 hex hashes, surviving restarts by living in pizza.yml:

security:
  auth_enabled: true
  keys:
    - id: ci-runner
      hash: "<lowercase hex sha256 of the raw key>"
      tenant: my-tenant
      user: ci
      role: read_write

Generate a hash with e.g. printf %s 'pz_<key>' | shasum -a 256.

Roles #

RoleScope
platform_adminFull platform administration, including key management.
operatorOps-plane administration (cluster/node management), tenant-less.
monitorRead-only ops plane (monitoring), tenant-less.
namespace_adminAdministers one namespace (tenant): mints only read_write/read_only keys inside its own namespace.
read_writeFull data-plane access to the key’s tenant/namespace.
read_onlyRead-only data-plane access to the key’s tenant/namespace.

Managing keys at runtime #

Keys minted through the API replicate through the catalog Raft — they survive restarts and reach every node; revocations carry tombstones so revoked config/bootstrap keys cannot resurrect on reboot:

# mint a key (the raw key is returned exactly once)
curl -X POST http://127.0.0.1:28000/_security/key \
  -H 'Authorization: Bearer pz_bootstrap_key' \
  -H 'Content-Type: application/json' \
  -d '{"tenant": "my-tenant", "user": "ci", "role": "read_write"}'

# list keys (ids/tenants/roles — never key material)
curl http://127.0.0.1:28000/_security/keys \
  -H 'Authorization: Bearer pz_bootstrap_key'

# revoke
curl -X DELETE http://127.0.0.1:28000/_security/key/<id> \
  -H 'Authorization: Bearer pz_bootstrap_key'

The full API reference — including GET /_security/whoami, expiry handling and the namespace-admin fencing rules — lives in Security APIs. The built-in web console (/_ui/) has a login flow and a Security page built on these endpoints.

Calendar September 24, 2026
Edit Edit this page