flex-auth/docs
tegwick 6a6464fcc9
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 1s
Answer ops-warden and secrets-engine; open FLEX-WP-0021
Two cross-repo questions arrived in the flex-auth inbox and both are
answered as decision records rather than as prose in a message.

FLEX-DEC-2026-004 answers ops-warden WARDEN-WP-0034-T05. A decision
lifetime shorter than the SSH certificate TTL is meaningful, but only as
authority to issue, never as authority to use an already-issued
certificate. The pre-sign gate is the only consumer of the shorter
lifetime: no replay past expires_at, fresh Check per sign. The lever that
shortens effective access is the requested TTL as a policy input, which
is already deployed as the ttl_out_of_bounds deny. ops-warden's section
9.7.2 window through certificate TTL is correct as written and correctly
owned by the PEP; flex-auth does not want that residue moved to the PDP.

docs/decision-input-freshness.md gains the same boundary as published
contract text, so the ruling is not only in the decision log.

FLEX-DEC-2026-005 answers secrets-engine. A real policy package is
expected and flex-auth authors it here as it does for every consumer; the
reserved coordinate is secrets-engine.catalog-lane.lifecycle v1 and it
does not exist yet. Their choice not to default the pin was correct and
is endorsed explicitly. POST /v1/check is deployed but has no
estate-wide address by design -- per-consumer cluster-local pins with
default-deny ingress -- so their 2026-09-06 probe found the design
working, not an outage.

FLEX-WP-0021 carries that work: obtain the real action vocabulary from
secrets-engine, publish the package with fixtures, confirm the digest
join against a real decision record, then stand up a
flex-auth-secrets-engine pin in warn without moving the other two pins.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JTbVXpEiXA7mNJVpDnEPcB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 412054@bnt-lap001
Assistant-Session: 3968fae1-8d59-4209-9bd6-c22594b8ab19
2026-09-06 01:12:50 +02:00
..
adr Finish FLEX-WP-0015: both pins enforce, live A2 probes, AuthZEN deferred 2026-08-19 14:35:27 +02:00
evidence feat(policy): adopt security zone stances 2026-08-22 15:17:13 +02:00
action-bound-authorization-contract.md Finish FLEX-WP-0019 layer-model v0.7 conformance 2026-09-03 23:48:45 +02:00
canonical-request-digest.md Finish FLEX-WP-0019 layer-model v0.7 conformance 2026-09-03 23:48:45 +02:00
caring-architecture-blueprint.md Refine workplans for CARING profile 2026-05-17 04:15:38 +02:00
decision-input-freshness.md Answer ops-warden and secrets-engine; open FLEX-WP-0021 2026-09-06 01:12:50 +02:00
decision-record-contract.md Finish FLEX-WP-0019 layer-model v0.7 conformance 2026-09-03 23:48:45 +02:00
delegated-mode-operations.md Document delegated mode operations 2026-05-17 07:27:45 +02:00
directory-group-resolver-adapters.md Add directory group resolver adapters 2026-05-17 07:24:50 +02:00
flex-auth-authorization-registry-research.md Established INTENT.md 2026-05-04 17:52:29 +02:00
iam-profile-consumption.md Align IAM Profile consumption with v0.2 2026-05-22 14:35:30 +02:00
keycloak-authz-adapter-path.md Add Keycloak authorization adapter path 2026-05-17 07:18:45 +02:00
markitect-action-vocabulary.md Define Markitect action vocabulary 2026-05-17 06:26:13 +02:00
markitect-integration-flow.md Document Markitect integration flow 2026-05-17 06:41:07 +02:00
markitect-resource-namespace.md Define Markitect resource namespace 2026-05-17 06:14:04 +02:00
ops-warden-policy-gate-handoff.md Close ops-warden policy gate deployment 2026-06-30 00:52:56 +02:00
ops-warden-registry-sync.md FLEX-WP-0007: production registry fixture, tests, and sync runbook 2026-06-24 14:52:35 +02:00
pre-implementation-assessment.md Land foundations: assessment, ADR-001/002/003, FLEX-WP-0005, Go skeleton 2026-05-16 01:54:44 +02:00
ProductRequirementsDocument.md feat(authz): bind decisions to exact actions 2026-08-23 13:18:26 +02:00
railiance-platform-action-vocabulary.md feat(policy): add credential grant authorization package 2026-08-23 13:59:03 +02:00
relationship-pdp-adapter-boundary.md Add relationship PDP adapter boundary 2026-05-17 07:06:14 +02:00
rule-pdp-adapter-boundary.md Add rule PDP adapter boundary 2026-05-17 07:13:27 +02:00
tenancy-posture-review.md Record zone-engine compilation invariant; drop uncommitted policy leftovers 2026-08-19 21:36:22 +02:00
tenant-engine-action-vocabulary.md Authorize tenant-engine guardrail read and set actions 2026-08-16 02:46:25 +02:00
tenant-engine-resource-namespace.md Authorize tenant-engine guardrail read and set actions 2026-08-16 02:46:25 +02:00
topaz-adapter-operations.md Implement Topaz adapter 2026-05-17 06:58:04 +02:00
topaz-mapping-spike.md Topaz alignment spike — mapping doc + green e2e example 2026-05-16 09:04:42 +02:00
workplan-planning-map.md Enforce caller-auth on flex-auth-ops-warden (FLEX-WP-0016-T03) 2026-08-19 20:10:31 +02:00