flex-auth/examples/secrets-engine
tegwick 127f83da4d
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 53s
Sign decision envelopes and close FLEX-WP-0024.
Detached Ed25519 over the canonical envelope with signature omitted.
Unsigned is stated, not implied. Testdata fixtures prove verify and
tamper failure without minting a production key. FLEX-WP-0025 is
finished with the validate check from the previous commit.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-14 09:57:50 +02:00
..
replay Sign decision envelopes and close FLEX-WP-0024. 2026-09-14 09:57:50 +02:00
check_request_allow_destroy_dual_control.json Publish approval_binding_digest: a claim cannot name the request carrying it 2026-09-06 14:52:33 +02:00
check_request_allow_rotate.json Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02) 2026-09-06 08:02:52 +02:00
check_request_deny_destroy_without_claim.json Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02) 2026-09-06 08:02:52 +02:00
check_request_deny_revoke_not_an_action.json Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02) 2026-09-06 08:02:52 +02:00
check_request_deny_unknown_subject.json Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02) 2026-09-06 08:02:52 +02:00
check_request_deny_wrong_tenant.json fix(secrets-engine): v2 adds the tenant rule v1 never had 2026-09-06 20:38:45 +02:00
policy_fixtures.yaml fix(secrets-engine): v2 adds the tenant rule v1 never had 2026-09-06 20:38:45 +02:00
policy_package.md fix(secrets-engine): v2 adds the tenant rule v1 never had 2026-09-06 20:38:45 +02:00
protected_system_manifest.yaml Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02) 2026-09-06 08:02:52 +02:00
README.md fix: the address we published was a misdirection, and the channel is unauthenticated 2026-09-06 22:44:45 +02:00
registry_snapshot.json Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02) 2026-09-06 08:02:52 +02:00
subject_manifest.yaml Publish secrets-engine.catalog-lane.lifecycle v1 (FLEX-WP-0021 T01, T02) 2026-09-06 08:02:52 +02:00

secrets-engine example

Policy package, manifests, and fixtures for secrets-engine's gated catalog-lane operations. Opened by FLEX-DEC-2026-005, carried by FLEX-WP-0021.

File What it is
policy_package.md secrets-engine.catalog-lane.lifecycle v2, allow_ttl: 15m
protected_system_manifest.yaml the secret-catalog-lane resource type and twelve actions
subject_manifest.yaml the single secrets-engine service identity
registry_snapshot.json loadable snapshot combining both manifests
policy_fixtures.yaml 32 fixtures — 11 allows, dual control both ways, and every denial branch
check_request_*.json standalone requests for POST /v1/check

The action vocabulary is secrets-engine's, delivered under FLEX-WP-0021-T01 and recorded in ../../docs/secrets-engine-action-vocabulary.md. Read that before changing any action string here.

Verify

go run ./cmd/flex-auth validate -kind policy -file examples/secrets-engine/policy_package.md
go run ./cmd/flex-auth load-registry -file examples/secrets-engine/registry_snapshot.json

28 Rego tests and 32 fixtures.

Deployed, and the version to pin

FLEX-WP-0021-T04 deployed the flex-auth-secrets-engine pin on 2026-09-06:

Service:  http://flex-auth-secrets-engine.flex-auth.svc.cluster.local.:8080
                                                                    ^ trailing dot, required
Package:  secrets-engine.catalog-lane.lifecycle
Version:  v2
callerAuth.mode: warn   (not enforced caller authentication)

The trailing dot is not cosmetic, and this address is in-cluster only. secrets-engine reported and flex-auth reproduced that on the workstation a bare *.svc.cluster.local name resolves through search ad.binect.de to one unrelated public host — a name for a service that does not exist resolves to the same address, which proves it is suffix expansion rather than a record. The trailing-dot form correctly fails to resolve instead. A bare Service name in a handover is therefore not merely unreachable from a workstation, it is a live misdirection. See ../../docs/operator-caller-access-path.md.

Ingress admits namespace secrets-engine with pod label app.kubernetes.io/name=secrets-engine and default-denies everything else. A workstation CLI process is not that, and Service DNS is not workstation connectivity — an operator-run consumer needs a decided access path before it can call this pin at all (FLEX-WP-0021-T04's three shapes).

Pin _VERSION to v2, never v1. v1 is deployed and superseded: it had no tenant rule and allowed a foreign tenant. See the correction section in policy_package.md. The pin still serves v1 until the redeploy lands, which is why the version is stated here rather than left to be read off the running service.

SECRETS_ENGINE_AUTHORIZATION_POLICY_PACKAGE / _VERSION remain fallback-free and fail-closed by design; nothing here changes that.