Enforce caller-auth on flex-auth-ops-warden (FLEX-WP-0016-T03)
ops-warden WARDEN-WP-0031 T04 minted audience-flex-auth tokens as system:serviceaccount:ops-warden:ops-warden and held the warn-log count. Helm rev 2 is enforce. Live probe 200/401/403. policy.enabled is theirs.
This commit is contained in:
parent
f51f50ae8d
commit
249ee146ba
5 changed files with 24 additions and 12 deletions
|
|
@ -96,7 +96,7 @@ last-known-good digest below.
|
|||
| `flex-auth-tenant-engine` *(previous)* | `sha256:1bf060e61122693ce98359c167cc5fe8bdafc84e097e090eaa71af94d0f27cbc` | nine-action policy (FLEX-WP-0014), CI-built from `f304688` |
|
||||
| `flex-auth-tenant-engine` *(previous)* | `sha256:9320df394a642eff24da8af4a0ee8886a7bb78b0f14d8ee1deeb30ea8eeeaba7` | seven-action policy, FLEX-WP-0013 restore; guardrail actions deny `unknown_action` |
|
||||
| `flex-auth-tenant-engine` *(rollback)* | `sha256:c25fc34a6cd7e64d955f8723ec70e176a583d5ae71d76280c4e2d89fba0fe0aa` | four-action policy; lifecycle actions deny `unknown_action` |
|
||||
| `flex-auth-ops-warden` | `sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b` | **live isolated warn** — ops-warden production registry (FLEX-WP-0016), CI `main-3de72fe` |
|
||||
| `flex-auth-ops-warden` | `sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b` | **live isolated enforce** — ops-warden production registry (FLEX-WP-0016), CI `main-3de72fe`, A2 probe 2026-08-19 |
|
||||
| `flex-auth-user-engine` | `sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b` | **live** — caller-auth **enforce** (FLEX-WP-0015-T02), CI `main-3de72fe`, A2 probe 2026-08-19 |
|
||||
| `flex-auth-user-engine` *(previous)* | `sha256:1f5290376dc5fcf456dc7a785e394d8b90949dabecd1d3e856f38557149bb5f4` | FLEX-WP-0009-T04, nine fixtures (incl. registration-applicant) verified live 2026-08-16 |
|
||||
| `flex-auth-user-engine` *(previous)* | `sha256:a31961c45215aa6baf3bc748c6741ab703c2c8325e61aa7983a355026195e51b` | FLEX-WP-0009-T03, six fixtures verified live 2026-08-10 |
|
||||
|
|
|
|||
|
|
@ -26,7 +26,7 @@ This document captures the current sequencing view for flex-auth workplans.
|
|||
| `FLEX-WP-0004` | complete | completed | `FLEX-WP-0002`, `FLEX-WP-0005` | Delegated PDP and directory adapter boundary work is complete: Topaz adapter shape, OpenFGA/SpiceDB, OPA/Cedar, Keycloak Authorization Services, Entra/Graph/SCIM, CARING envelope preservation. |
|
||||
| `FLEX-WP-0006` | complete | finished | `FLEX-WP-0002`, `FLEX-WP-0005` | Ops-warden unblocker is complete: flex-auth publishes `ssh-certificate` / `sign` policies, fixtures, and `/v1/check` smoke evidence for the opt-in pre-sign gate shipped in ops-warden `WARDEN-WP-0007` and tracked for production in `WARDEN-WP-0009`. |
|
||||
| `FLEX-WP-0007` | complete | finished | `FLEX-WP-0006` | Production registry fixture, sync contract, runtime command, healthz coverage, real actor/IAM tests, operator tunnel reachability, and vault-backed joint smoke are complete. `policy.enabled` remains off; the in-cluster pin that can actually serve ops-warden is FLEX-WP-0016. |
|
||||
| `FLEX-WP-0016` | P1 | active | `FLEX-WP-0007`, `FLEX-WP-0015` | Isolated in-cluster `flex-auth-ops-warden` warn pin with the production registry. Enforce and `policy.enabled` wait on ops-warden's calling side. |
|
||||
| `FLEX-WP-0016` | complete | finished | `FLEX-WP-0007`, `FLEX-WP-0015` | Isolated in-cluster `flex-auth-ops-warden` enforce pin. Live 200/401/403 2026-08-19. `policy.enabled` is ops-warden's remaining flip. |
|
||||
|
||||
## Dependency Notes
|
||||
|
||||
|
|
|
|||
|
|
@ -26,8 +26,8 @@ echo "$tenant_render" | grep -q 'tenant-engine=system:serviceaccount:tenant-engi
|
|||
|| { echo "tenant-engine render omits its exact binding" >&2; exit 1; }
|
||||
|
||||
ops_render="$(helm template flex-auth-ops-warden charts/flex-auth -f values/ops-warden.yaml --namespace flex-auth)"
|
||||
echo "$ops_render" | grep -A1 -- '--caller-auth-mode' | grep -q warn \
|
||||
|| { echo "ops-warden first pin must be warn" >&2; exit 1; }
|
||||
echo "$ops_render" | grep -A1 -- '--caller-auth-mode' | grep -Eq 'warn|enforce' \
|
||||
|| { echo "ops-warden caller-auth-mode must be warn or enforce" >&2; exit 1; }
|
||||
echo "$ops_render" | grep -q 'ops-warden=system:serviceaccount:ops-warden:ops-warden' \
|
||||
|| { echo "ops-warden render omits its exact binding" >&2; exit 1; }
|
||||
echo "$ops_render" | grep -q production_registry_snapshot.json \
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
# Independently rollable ops-warden signing-policy pin (FLEX-WP-0016).
|
||||
# Isolated: no in-cluster PEP namespace yet. Workstation warden sign is not a
|
||||
# Kubernetes ServiceAccount, so first mode is warn. Do not copy enforce from
|
||||
# the user-engine/tenant-engine pins.
|
||||
# Isolated: workstation reaches it by port-forward/tunnel. Binding matches
|
||||
# ServiceAccount ops-warden/ops-warden (WARDEN-WP-0031). Enforce after their
|
||||
# T04 authenticated gate held the warn-log count at 4.
|
||||
name: flex-auth-ops-warden
|
||||
image:
|
||||
repository: forgejo.coulomb.social/coulomb/flex-auth
|
||||
|
|
@ -15,7 +15,7 @@ args:
|
|||
- --policy
|
||||
- /opt/flex-auth/examples/ops-warden/policy_package.md
|
||||
callerAuth:
|
||||
mode: warn
|
||||
mode: enforce
|
||||
kubernetesURL: https://10.43.0.1
|
||||
binding: ops-warden=system:serviceaccount:ops-warden:ops-warden
|
||||
consumer:
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "In-cluster ops-warden policy pin so policy.enabled can flip"
|
||||
domain: infotech
|
||||
repo: flex-auth
|
||||
status: active
|
||||
status: finished
|
||||
owner: grok
|
||||
topic_slug: netkingdom
|
||||
planning_priority: P1
|
||||
|
|
@ -92,7 +92,7 @@ user-engine and tenant-engine pins were not moved.
|
|||
|
||||
```task
|
||||
id: FLEX-WP-0016-T03
|
||||
status: wait
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
|
|
@ -103,5 +103,17 @@ the calling side; then this pin can enforce; then they set
|
|||
`~/.config/warden/warden.yaml`.
|
||||
|
||||
Asked 2026-08-19. Cluster DNS from a warden workstation is not assumed;
|
||||
they pick tunnel or port-forward. `policy.py` posts JSON with no
|
||||
`Authorization` header.
|
||||
they pick tunnel or port-forward.
|
||||
|
||||
WARDEN-WP-0031 T04 (2026-08-19): ServiceAccount `ops-warden/ops-warden`
|
||||
exists; `policy.caller_auth mode: command` mints `--audience flex-auth`
|
||||
per call; authenticated gate against warn held the warning count at 4
|
||||
(`decision:f3f7c88f9585582a`). They asked for enforce.
|
||||
|
||||
**Enforce live 2026-08-19** Helm rev 2, same digest. Probe via port-forward
|
||||
`:19090` with `kubectl create token ops-warden -n ops-warden --audience flex-auth`:
|
||||
(1) Bearer → 200 `decision:49350f1064f674d7`;
|
||||
(2) no Authorization → **401** `unauthenticated`;
|
||||
(3) `resource.system=user-engine` → **403** `forbidden`.
|
||||
user-engine and tenant-engine pins were not moved. `policy.enabled` remains
|
||||
ops-warden's flip.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue