37 lines
1.5 KiB
Markdown
37 lines
1.5 KiB
Markdown
|
|
# secrets-engine example
|
||
|
|
|
||
|
|
Policy package, manifests, and fixtures for `secrets-engine`'s gated
|
||
|
|
catalog-lane operations. Opened by `FLEX-DEC-2026-005`, carried by
|
||
|
|
`FLEX-WP-0021`.
|
||
|
|
|
||
|
|
| File | What it is |
|
||
|
|
| --- | --- |
|
||
|
|
| `policy_package.md` | `secrets-engine.catalog-lane.lifecycle` v1, `allow_ttl: 15m` |
|
||
|
|
| `protected_system_manifest.yaml` | the `secret-catalog-lane` resource type and twelve actions |
|
||
|
|
| `subject_manifest.yaml` | the single `secrets-engine` service identity |
|
||
|
|
| `registry_snapshot.json` | loadable snapshot combining both manifests |
|
||
|
|
| `policy_fixtures.yaml` | 26 fixtures — 11 allows, dual control both ways, and every denial branch |
|
||
|
|
| `check_request_*.json` | standalone requests for `POST /v1/check` |
|
||
|
|
|
||
|
|
The action vocabulary is **secrets-engine's**, delivered under
|
||
|
|
`FLEX-WP-0021-T01` and recorded in
|
||
|
|
[`../../docs/secrets-engine-action-vocabulary.md`](../../docs/secrets-engine-action-vocabulary.md).
|
||
|
|
Read that before changing any action string here.
|
||
|
|
|
||
|
|
## Verify
|
||
|
|
|
||
|
|
```bash
|
||
|
|
go run ./cmd/flex-auth validate -kind policy -file examples/secrets-engine/policy_package.md
|
||
|
|
go run ./cmd/flex-auth load-registry -file examples/secrets-engine/registry_snapshot.json
|
||
|
|
```
|
||
|
|
|
||
|
|
22 Rego tests and 26 fixtures.
|
||
|
|
|
||
|
|
## Not yet deployed
|
||
|
|
|
||
|
|
There is no `flex-auth-secrets-engine` pin yet (`FLEX-WP-0021-T04`), so
|
||
|
|
secrets-engine has no address to call. Their policy pin
|
||
|
|
(`SECRETS_ENGINE_AUTHORIZATION_POLICY_PACKAGE` / `_VERSION`) stays **unset and
|
||
|
|
fail-closed** until `FLEX-WP-0021-T05` hands them the published package and the
|
||
|
|
Service DNS. Do not configure it from this directory.
|