#!/bin/sh # ACTIVITY-WP-0039-T03 (option b): mint fresh ops_run worker tokens into OpenBao. # # Founder-attended only, through the silent admin lane (orientation section 5): # # BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 \ # WP0039_STATUS=$HOME/.local/state/wp0039-seed.status \ # warden access openbao-platform-admin-login --exec -- \ # sh scripts/wp0039-seed-worker-tokens.sh # # Silent by design: warden fails closed on any child output. The value is # generated inside a pipe and sent to bao on stdin, so it never appears in # argv, output, Git, or the hub. Idempotent: an existing path is never # overwritten. Rerunning after success is a no-op that re-verifies. # # WP0039_STATUS (optional, absolute path outside warden's temporary HOME) # receives a non-secret trace: step, exit code, and bao's error text for # metadata/put calls. The token-read step records only its stderr and length; # its stdout (the value) is never written anywhere. # # Exit codes: 0 both paths present and verified · 3 a path exists without a # usable token field (left untouched) · 4 write failed · 5 verification failed # · 6 a required tool is missing. exec >/dev/null 2>&1 set -u MOUNT=platform BASE=workloads/activity-core/ops-run-workers PATHS="rein-aharness-railiance01 rein-aharness-metered-railiance01" STATUS="${WP0039_STATUS:-/dev/null}" ERR="$(mktemp)" trap 'rm -f "$ERR"' EXIT : >"$STATUS" note() { printf '%s\n' "$*" >>"$STATUS"; } fail() { note "exit $1 at $2"; sed 's/^/ bao: /' "$ERR" >>"$STATUS"; exit "$1"; } for tool in bao openssl; do command -v "$tool" || { note "missing tool: $tool"; exit 6; } done note "BAO_ADDR=${BAO_ADDR:-unset}" token_len() { bao kv get -mount="$MOUNT" -field=token "$BASE/$1" 2>"$ERR" | tr -d '\n' | wc -c | tr -d ' ' } for slug in $PATHS; do if bao kv metadata get -mount="$MOUNT" "$BASE/$slug" 2>"$ERR"; then note "$slug: exists" [ "$(token_len "$slug")" -eq 64 ] || fail 3 "verify-existing $slug" continue fi note "$slug: metadata lookup failed (treated as absent):" sed 's/^/ bao: /' "$ERR" >>"$STATUS" openssl rand -hex 32 | tr -d '\n' \ | bao kv put -mount="$MOUNT" "$BASE/$slug" token=- 2>"$ERR" || fail 4 "put $slug" note "$slug: written" done for slug in $PATHS; do [ "$(token_len "$slug")" -eq 64 ] || fail 5 "verify $slug" note "$slug: verified" done note "exit 0" exit 0