secrets-engine probed the Service DNS name handed over in FLEX-WP-0021-T05 and found it resolves, from the workstation, to an unrelated public host. Reproduced here: search ad.binect.de answers wildcard, so flex-auth-secrets-engine.flex-auth.svc.cluster.local and this-service-does-not-exist.flex-auth.svc.cluster.local both resolve to 80.158.43.29, while the trailing-dot FQDN correctly fails. A bare Service name in a handover is not merely unreachable from there, it is a live misdirection, and the handover was ours. Had a deployment pointed at it, the CheckRequest body would have gone to that host: subject, tenant, lane and resource ids, stage, field names, purpose, plus the caller's bearer token. Trailing-dot FQDN and "in-cluster only" now replace the bare name in the example README, SCOPE.md, and the T05 note. Their real question was how the response channel is authenticated, and they declined to answer it locally because choosing a transport control for our service is not a consumer's call. Right boundary, so the answer is recorded here as FLEX-DEC-2026-010: it is not authenticated. Pins serve plain HTTP, the envelope carries no signature, and a responder that knows the package id and version can return a well-formed allow that passes every check a consumer performs. The part worth stating in the contract is that the digests do not help and look like they do. Every input to request_digest, policy_package_digest and registry_snapshot_digest is either sent by the caller or published in this repo, so a forger reproduces all three exactly. They establish integrity of the binding, never authenticity of the source — and publishing more digests makes a forged envelope look more authenticated, not less. For secrets-engine specifically: fail-closed protects against a PDP that is absent, not against one that lies. An unreachable PDP denies; a lying PDP allows. Third instance of one seam in three decisions. 008: a tenant carried into the digest and never compared — visible, not enforced. 009: a caller authenticated and never recorded — enforced, not visible. 010: a record verifiable and unauthentic — checkable, but not evidence. One nuance that changes the operator recommendation: kubectl port-forward does authenticate the responder, transitively — no DNS name, one named pod, API-server TLS. That is the exact reverse of the caller direction, where it bypasses the NetworkPolicy. Independent properties pointing opposite ways, so neither can be summarised as "the network protects it". FLEX-WP-0024 carries signing; key custody routes through warden/OpenBao rather than minting a key here. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014aQMM1dPXaPiXVn6DwwtLd Assistant: claude-code Assistant-Model: opus Assistant-Process: 715613@bnt-lap001 Assistant-Session: fabd95c1-4c9e-4080-8849-8707ae025f80
64 lines
3 KiB
Markdown
64 lines
3 KiB
Markdown
# secrets-engine example
|
|
|
|
Policy package, manifests, and fixtures for `secrets-engine`'s gated
|
|
catalog-lane operations. Opened by `FLEX-DEC-2026-005`, carried by
|
|
`FLEX-WP-0021`.
|
|
|
|
| File | What it is |
|
|
| --- | --- |
|
|
| `policy_package.md` | `secrets-engine.catalog-lane.lifecycle` v2, `allow_ttl: 15m` |
|
|
| `protected_system_manifest.yaml` | the `secret-catalog-lane` resource type and twelve actions |
|
|
| `subject_manifest.yaml` | the single `secrets-engine` service identity |
|
|
| `registry_snapshot.json` | loadable snapshot combining both manifests |
|
|
| `policy_fixtures.yaml` | 32 fixtures — 11 allows, dual control both ways, and every denial branch |
|
|
| `check_request_*.json` | standalone requests for `POST /v1/check` |
|
|
|
|
The action vocabulary is **secrets-engine's**, delivered under
|
|
`FLEX-WP-0021-T01` and recorded in
|
|
[`../../docs/secrets-engine-action-vocabulary.md`](../../docs/secrets-engine-action-vocabulary.md).
|
|
Read that before changing any action string here.
|
|
|
|
## Verify
|
|
|
|
```bash
|
|
go run ./cmd/flex-auth validate -kind policy -file examples/secrets-engine/policy_package.md
|
|
go run ./cmd/flex-auth load-registry -file examples/secrets-engine/registry_snapshot.json
|
|
```
|
|
|
|
28 Rego tests and 32 fixtures.
|
|
|
|
## Deployed, and the version to pin
|
|
|
|
`FLEX-WP-0021-T04` deployed the `flex-auth-secrets-engine` pin on 2026-09-06:
|
|
|
|
```text
|
|
Service: http://flex-auth-secrets-engine.flex-auth.svc.cluster.local.:8080
|
|
^ trailing dot, required
|
|
Package: secrets-engine.catalog-lane.lifecycle
|
|
Version: v2
|
|
callerAuth.mode: warn (not enforced caller authentication)
|
|
```
|
|
|
|
**The trailing dot is not cosmetic, and this address is in-cluster only.**
|
|
`secrets-engine` reported and flex-auth reproduced that on the workstation a
|
|
bare `*.svc.cluster.local` name resolves through `search ad.binect.de` to one
|
|
unrelated public host — a name for a service that does not exist resolves to the
|
|
same address, which proves it is suffix expansion rather than a record. The
|
|
trailing-dot form correctly fails to resolve instead. A bare Service name in a
|
|
handover is therefore not merely unreachable from a workstation, it is a live
|
|
misdirection. See `../../docs/operator-caller-access-path.md`.
|
|
|
|
Ingress admits namespace `secrets-engine` with pod label
|
|
`app.kubernetes.io/name=secrets-engine` and default-denies everything else. A
|
|
workstation CLI process is not that, and Service DNS is not workstation
|
|
connectivity — an operator-run consumer needs a decided access path before it
|
|
can call this pin at all (`FLEX-WP-0021-T04`'s three shapes).
|
|
|
|
**Pin `_VERSION` to `v2`, never `v1`.** `v1` is deployed and superseded: it had
|
|
no tenant rule and allowed a foreign tenant. See the correction section in
|
|
`policy_package.md`. The pin still serves `v1` until the redeploy lands, which
|
|
is why the version is stated here rather than left to be read off the running
|
|
service.
|
|
|
|
`SECRETS_ENGINE_AUTHORIZATION_POLICY_PACKAGE` / `_VERSION` remain fallback-free
|
|
and fail-closed by design; nothing here changes that.
|