Detached Ed25519 over the canonical envelope with signature omitted. Unsigned is stated, not implied. Testdata fixtures prove verify and tamper failure without minting a production key. FLEX-WP-0025 is finished with the validate check from the previous commit. Assistant: grok Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267 |
||
|---|---|---|
| .. | ||
| replay | ||
| check_request_allow_destroy_dual_control.json | ||
| check_request_allow_rotate.json | ||
| check_request_deny_destroy_without_claim.json | ||
| check_request_deny_revoke_not_an_action.json | ||
| check_request_deny_unknown_subject.json | ||
| check_request_deny_wrong_tenant.json | ||
| policy_fixtures.yaml | ||
| policy_package.md | ||
| protected_system_manifest.yaml | ||
| README.md | ||
| registry_snapshot.json | ||
| subject_manifest.yaml | ||
secrets-engine example
Policy package, manifests, and fixtures for secrets-engine's gated
catalog-lane operations. Opened by FLEX-DEC-2026-005, carried by
FLEX-WP-0021.
| File | What it is |
|---|---|
policy_package.md |
secrets-engine.catalog-lane.lifecycle v2, allow_ttl: 15m |
protected_system_manifest.yaml |
the secret-catalog-lane resource type and twelve actions |
subject_manifest.yaml |
the single secrets-engine service identity |
registry_snapshot.json |
loadable snapshot combining both manifests |
policy_fixtures.yaml |
32 fixtures — 11 allows, dual control both ways, and every denial branch |
check_request_*.json |
standalone requests for POST /v1/check |
The action vocabulary is secrets-engine's, delivered under
FLEX-WP-0021-T01 and recorded in
../../docs/secrets-engine-action-vocabulary.md.
Read that before changing any action string here.
Verify
go run ./cmd/flex-auth validate -kind policy -file examples/secrets-engine/policy_package.md
go run ./cmd/flex-auth load-registry -file examples/secrets-engine/registry_snapshot.json
28 Rego tests and 32 fixtures.
Deployed, and the version to pin
FLEX-WP-0021-T04 deployed the flex-auth-secrets-engine pin on 2026-09-06:
Service: http://flex-auth-secrets-engine.flex-auth.svc.cluster.local.:8080
^ trailing dot, required
Package: secrets-engine.catalog-lane.lifecycle
Version: v2
callerAuth.mode: warn (not enforced caller authentication)
The trailing dot is not cosmetic, and this address is in-cluster only.
secrets-engine reported and flex-auth reproduced that on the workstation a
bare *.svc.cluster.local name resolves through search ad.binect.de to one
unrelated public host — a name for a service that does not exist resolves to the
same address, which proves it is suffix expansion rather than a record. The
trailing-dot form correctly fails to resolve instead. A bare Service name in a
handover is therefore not merely unreachable from a workstation, it is a live
misdirection. See ../../docs/operator-caller-access-path.md.
Ingress admits namespace secrets-engine with pod label
app.kubernetes.io/name=secrets-engine and default-denies everything else. A
workstation CLI process is not that, and Service DNS is not workstation
connectivity — an operator-run consumer needs a decided access path before it
can call this pin at all (FLEX-WP-0021-T04's three shapes).
Pin _VERSION to v2, never v1. v1 is deployed and superseded: it had
no tenant rule and allowed a foreign tenant. See the correction section in
policy_package.md. The pin still serves v1 until the redeploy lands, which
is why the version is stated here rather than left to be read off the running
service.
SECRETS_ENGINE_AUTHORIZATION_POLICY_PACKAGE / _VERSION remain fallback-free
and fail-closed by design; nothing here changes that.