Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 52s

secrets-engine delivered the action vocabulary T01 asked for: twelve
actions read out of cli.py, not the example vocabulary. The gate earned
its keep -- four would have been inferred wrongly, and revoke, the
obvious thirteenth, does not exist as an action at all. It gates as
deactivate, which is also reached from lifecycle deactivate.

docs/secrets-engine-action-vocabulary.md records the list and the four
traps. examples/secrets-engine/ carries the package, both manifests, a
loadable registry snapshot, 26 fixtures, five check requests, and a
README. validate -kind policy is valid with 22/22 Rego tests and 26/26
fixtures.

allow_ttl is 15m, stated in the package rather than inherited from the
engine default: these decisions authorize live secret operations, so the
reliance window belongs where a reviewer sees it. Per FLEX-DEC-2026-004
it is authority to issue, not authority to keep using what the operation
produced.

destroy is the dual-control case, gated on a context.approval claim
marked approved with two distinct approvers, repeated entries counting
once. flex-auth checks what the claim says and deliberately does not
re-derive its temporal validity, signature, or supersession -- those are
approval-engine's to assert and the PEP's to verify against the live
claim, per the split accepted in FLEX-DEC-2026-006. It stays in the
package though its handler raises before the gate, so the rule is
reviewed and fixtured before SECRETS-WP-0007-T04 opens the path.

Following the FLEX-WP-0010-T02 precedent the denial ladder has no
action_not_granted branch: one subject holding all twelve actions could
never reach it, and a rule that cannot fail reads as control that is not
there. Registering a second calling identity is the revisit trigger.

Not deployed. No flex-auth-secrets-engine pin exists yet (T04), so their
policy pin stays unset and fail-closed until T05.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JTbVXpEiXA7mNJVpDnEPcB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 412054@bnt-lap001
Assistant-Session: 3968fae1-8d59-4209-9bd6-c22594b8ab19
This commit is contained in:
tegwick 2026-09-06 08:02:52 +02:00
parent b9e6d2d52b
commit f75db59a8c
13 changed files with 1861 additions and 3 deletions

View file

@ -0,0 +1,105 @@
id: secrets-engine
name: Secrets Engine
resource_types:
- name: secret-catalog-lane
scope_level: Resource
planes:
- Secret
- Policy
- Audit
metadata:
description: >-
A secret catalog lane: one catalog entry's delivery path at a given
stage. The catalog id is resource.id; stage plus sorted fields,
policy_targets, and auth_targets are resource.attributes.
flex-auth never sees secret material, only the lane's coordinates.
actions:
- name: apply
capabilities: [EditAny, Audit]
planes: [Secret, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
note: >-
apply --dry-run never reaches the gate, but the distinction is
invisible here; both would arrive as "apply".
- name: provision
capabilities: [Create, Audit]
planes: [Secret, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
- name: rotate
capabilities: [EditAny, Audit]
planes: [Secret, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
- name: verify
capabilities: [View, Audit]
planes: [Secret, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
- name: handoff
capabilities: [EditAny, Audit]
planes: [Secret, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
- name: wrap
capabilities: [Execute, Audit]
planes: [Secret, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
- name: exec
capabilities: [Execute, Audit]
planes: [Secret, Execution, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
- name: deactivate
capabilities: [Archive, Audit]
planes: [Secret, Policy, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
note: >-
Reached from both the CLI verb "revoke" and "lifecycle deactivate".
There is no "revoke" action value.
- name: suspend
capabilities: [Archive, Audit]
planes: [Secret, Policy, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
- name: destroy
capabilities: [DeleteAny, Audit]
planes: [Secret, Policy, Audit]
exposure_modes: [Metadata]
metadata:
required_context:
- approval
note: >-
Dual control. Defined but not reachable live: the handler raises
before the gate, so only --dry-run renders until SECRETS-WP-0007-T04.
- name: compromise
capabilities: [EditAny, Audit]
planes: [Policy, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
note: Mutates local delivery overlay state only; touches no OpenBao object.
- name: reactivate
capabilities: [Restore, Audit]
planes: [Policy, Audit]
exposure_modes: [Metadata]
metadata:
required_context: []
note: Mutates local delivery overlay state only; touches no OpenBao object.
caring_profiles:
- caring-0.4.0-rc2
metadata:
flex_auth_contract: protected-system-v0
action_vocabulary_source: secrets-engine docs/gated-actions.md (FLEX-WP-0021-T01)