Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1 |
||
|---|---|---|
| .. | ||
| check_request_allow_adm.json | ||
| check_request_allow_agt.json | ||
| check_request_allow_atm.json | ||
| check_request_deny_actor_type_mismatch.json | ||
| check_request_deny_disallowed_principal.json | ||
| check_request_deny_missing_fingerprint.json | ||
| check_request_deny_ttl_above_max.json | ||
| check_request_deny_unknown_subject.json | ||
| policy_fixtures.yaml | ||
| policy_package.md | ||
| production_registry_snapshot.json | ||
| protected_system_manifest.yaml | ||
| README.md | ||
| registry_snapshot.json | ||
| resource_manifest.yaml | ||
| subject_manifest.yaml | ||
Ops-Warden SSH Signing Policy Gate
This example is the flex-auth side of ops-warden's opt-in pre-sign gate.
When policy.enabled: true, ops-warden calls POST /v1/check before signing
or issuing an SSH certificate.
Files:
protected_system_manifest.yamldeclares theops-wardenprotected system,ssh-certificateresource type, andsignaction.resource_manifest.yamldeclares fixture SSH certificate actor resources and non-secret policy attributes such as allowed principals and TTL maxima.subject_manifest.yamldeclares non-secret fixture actors foradm,agt, andatmsigning paths.registry_snapshot.jsonis the combined local registry used by the CLI and service examples.policy_package.mdis the Rego-in-Markdown policy package.policy_fixtures.yamlcontains allow and deny expectations for package validation.check_request_*.jsonfiles are ops-warden-shaped/v1/checkrequests.
Run locally:
flex-auth validate --kind protected-system --file examples/ops-warden/protected_system_manifest.yaml
flex-auth validate --kind resource-manifest --file examples/ops-warden/resource_manifest.yaml
flex-auth validate --kind subject-manifest --file examples/ops-warden/subject_manifest.yaml
flex-auth load-registry --file examples/ops-warden/registry_snapshot.json
flex-auth test-policy --file examples/ops-warden/policy_package.md
flex-auth check --registry examples/ops-warden/registry_snapshot.json --policy examples/ops-warden/policy_package.md --request examples/ops-warden/check_request_allow_adm.json
The fixture public-key fingerprints are examples only. Do not put real keys, OpenBao tokens, or private signing material in these files.
Production Registry Fixture
production_registry_snapshot.json is a non-secret fixture generated by ops-warden for FLEX-WP-0007 coverage. It mirrors the current production actor names used by ops-warden inventory and should be refreshed when that inventory changes.
Validate both registries locally:
flex-auth load-registry --file examples/ops-warden/registry_snapshot.json
flex-auth load-registry --file examples/ops-warden/production_registry_snapshot.json
The production sync contract is documented in docs/ops-warden-registry-sync.md.