Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02)
secrets-engine delivered the action vocabulary T01 asked for: twelve actions read out of cli.py, not the example vocabulary. The gate earned its keep -- four would have been inferred wrongly, and revoke, the obvious thirteenth, does not exist as an action at all. It gates as deactivate, which is also reached from lifecycle deactivate. docs/secrets-engine-action-vocabulary.md records the list and the four traps. examples/secrets-engine/ carries the package, both manifests, a loadable registry snapshot, 26 fixtures, five check requests, and a README. validate -kind policy is valid with 22/22 Rego tests and 26/26 fixtures. allow_ttl is 15m, stated in the package rather than inherited from the engine default: these decisions authorize live secret operations, so the reliance window belongs where a reviewer sees it. Per FLEX-DEC-2026-004 it is authority to issue, not authority to keep using what the operation produced. destroy is the dual-control case, gated on a context.approval claim marked approved with two distinct approvers, repeated entries counting once. flex-auth checks what the claim says and deliberately does not re-derive its temporal validity, signature, or supersession -- those are approval-engine's to assert and the PEP's to verify against the live claim, per the split accepted in FLEX-DEC-2026-006. It stays in the package though its handler raises before the gate, so the rule is reviewed and fixtured before SECRETS-WP-0007-T04 opens the path. Following the FLEX-WP-0010-T02 precedent the denial ladder has no action_not_granted branch: one subject holding all twelve actions could never reach it, and a rule that cannot fail reads as control that is not there. Registering a second calling identity is the revisit trigger. Not deployed. No flex-auth-secrets-engine pin exists yet (T04), so their policy pin stays unset and fail-closed until T05. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JTbVXpEiXA7mNJVpDnEPcB Assistant: claude-code Assistant-Model: opus Assistant-Process: 412054@bnt-lap001 Assistant-Session: 3968fae1-8d59-4209-9bd6-c22594b8ab19
This commit is contained in:
parent
b9e6d2d52b
commit
f75db59a8c
13 changed files with 1861 additions and 3 deletions
36
examples/secrets-engine/README.md
Normal file
36
examples/secrets-engine/README.md
Normal file
|
|
@ -0,0 +1,36 @@
|
|||
# secrets-engine example
|
||||
|
||||
Policy package, manifests, and fixtures for `secrets-engine`'s gated
|
||||
catalog-lane operations. Opened by `FLEX-DEC-2026-005`, carried by
|
||||
`FLEX-WP-0021`.
|
||||
|
||||
| File | What it is |
|
||||
| --- | --- |
|
||||
| `policy_package.md` | `secrets-engine.catalog-lane.lifecycle` v1, `allow_ttl: 15m` |
|
||||
| `protected_system_manifest.yaml` | the `secret-catalog-lane` resource type and twelve actions |
|
||||
| `subject_manifest.yaml` | the single `secrets-engine` service identity |
|
||||
| `registry_snapshot.json` | loadable snapshot combining both manifests |
|
||||
| `policy_fixtures.yaml` | 26 fixtures — 11 allows, dual control both ways, and every denial branch |
|
||||
| `check_request_*.json` | standalone requests for `POST /v1/check` |
|
||||
|
||||
The action vocabulary is **secrets-engine's**, delivered under
|
||||
`FLEX-WP-0021-T01` and recorded in
|
||||
[`../../docs/secrets-engine-action-vocabulary.md`](../../docs/secrets-engine-action-vocabulary.md).
|
||||
Read that before changing any action string here.
|
||||
|
||||
## Verify
|
||||
|
||||
```bash
|
||||
go run ./cmd/flex-auth validate -kind policy -file examples/secrets-engine/policy_package.md
|
||||
go run ./cmd/flex-auth load-registry -file examples/secrets-engine/registry_snapshot.json
|
||||
```
|
||||
|
||||
22 Rego tests and 26 fixtures.
|
||||
|
||||
## Not yet deployed
|
||||
|
||||
There is no `flex-auth-secrets-engine` pin yet (`FLEX-WP-0021-T04`), so
|
||||
secrets-engine has no address to call. Their policy pin
|
||||
(`SECRETS_ENGINE_AUTHORIZATION_POLICY_PACKAGE` / `_VERSION`) stays **unset and
|
||||
fail-closed** until `FLEX-WP-0021-T05` hands them the published package and the
|
||||
Service DNS. Do not configure it from this directory.
|
||||
Loading…
Add table
Add a link
Reference in a new issue