# secrets-engine example Policy package, manifests, and fixtures for `secrets-engine`'s gated catalog-lane operations. Opened by `FLEX-DEC-2026-005`, carried by `FLEX-WP-0021`. | File | What it is | | --- | --- | | `policy_package.md` | `secrets-engine.catalog-lane.lifecycle` v1, `allow_ttl: 15m` | | `protected_system_manifest.yaml` | the `secret-catalog-lane` resource type and twelve actions | | `subject_manifest.yaml` | the single `secrets-engine` service identity | | `registry_snapshot.json` | loadable snapshot combining both manifests | | `policy_fixtures.yaml` | 29 fixtures — 11 allows, dual control both ways, and every denial branch | | `check_request_*.json` | standalone requests for `POST /v1/check` | The action vocabulary is **secrets-engine's**, delivered under `FLEX-WP-0021-T01` and recorded in [`../../docs/secrets-engine-action-vocabulary.md`](../../docs/secrets-engine-action-vocabulary.md). Read that before changing any action string here. ## Verify ```bash go run ./cmd/flex-auth validate -kind policy -file examples/secrets-engine/policy_package.md go run ./cmd/flex-auth load-registry -file examples/secrets-engine/registry_snapshot.json ``` 25 Rego tests and 29 fixtures. ## Not yet deployed There is no `flex-auth-secrets-engine` pin yet (`FLEX-WP-0021-T04`), so secrets-engine has no address to call. Their policy pin (`SECRETS_ENGINE_AUTHORIZATION_POLICY_PACKAGE` / `_VERSION`) stays **unset and fail-closed** until `FLEX-WP-0021-T05` hands them the published package and the Service DNS. Do not configure it from this directory.