# secrets-engine example Policy package, manifests, and fixtures for `secrets-engine`'s gated catalog-lane operations. Opened by `FLEX-DEC-2026-005`, carried by `FLEX-WP-0021`. | File | What it is | | --- | --- | | `policy_package.md` | `secrets-engine.catalog-lane.lifecycle` v2, `allow_ttl: 15m` | | `protected_system_manifest.yaml` | the `secret-catalog-lane` resource type and twelve actions | | `subject_manifest.yaml` | the single `secrets-engine` service identity | | `registry_snapshot.json` | loadable snapshot combining both manifests | | `policy_fixtures.yaml` | 32 fixtures — 11 allows, dual control both ways, and every denial branch | | `check_request_*.json` | standalone requests for `POST /v1/check` | The action vocabulary is **secrets-engine's**, delivered under `FLEX-WP-0021-T01` and recorded in [`../../docs/secrets-engine-action-vocabulary.md`](../../docs/secrets-engine-action-vocabulary.md). Read that before changing any action string here. ## Verify ```bash go run ./cmd/flex-auth validate -kind policy -file examples/secrets-engine/policy_package.md go run ./cmd/flex-auth load-registry -file examples/secrets-engine/registry_snapshot.json ``` 28 Rego tests and 32 fixtures. ## Deployed, and the version to pin `FLEX-WP-0021-T04` deployed the `flex-auth-secrets-engine` pin on 2026-09-06: ```text Service: http://flex-auth-secrets-engine.flex-auth.svc.cluster.local:8080 Package: secrets-engine.catalog-lane.lifecycle Version: v2 callerAuth.mode: warn (not enforced caller authentication) ``` Ingress admits namespace `secrets-engine` with pod label `app.kubernetes.io/name=secrets-engine` and default-denies everything else. A workstation CLI process is not that, and Service DNS is not workstation connectivity — an operator-run consumer needs a decided access path before it can call this pin at all (`FLEX-WP-0021-T04`'s three shapes). **Pin `_VERSION` to `v2`, never `v1`.** `v1` is deployed and superseded: it had no tenant rule and allowed a foreign tenant. See the correction section in `policy_package.md`. The pin still serves `v1` until the redeploy lands, which is why the version is stated here rather than left to be read off the running service. `SECRETS_ENGINE_AUTHORIZATION_POLICY_PACKAGE` / `_VERSION` remain fallback-free and fail-closed by design; nothing here changes that.