secrets-engine.catalog-lane.lifecycle v1 contained no reference to input.tenant — not in well_formed, not in the denial ladder, not in a test. A rotate on lane:glas-primary under tenant:coulomb returned allow against the deployed package (decision:066e629bbf0c0924). Found while answering glas-harness's tenant-alignment request, which had asked for wrong-tenant denial evidence. There was none to return. Three covers failed the same way: every one of the 29 fixtures carried tenant:platform, so the suite could not report on the field; T02's own gate named "wrong-tenant deny" and was recorded done unmet; and the engine hashes tenant into request_digest but never compares it. Four other published packages carry the branch — this one was the outlier. v2 adds wrong_tenant above wrong_system, three Rego tests and three fixtures (28/28, 32/32). The absent-tenant test caught a second defect in the first draft: a bare input.tenant != comparison is undefined on a missing key, so the branch dropped and the ladder reported the wrong rung. request_tenant := object.get(input, "tenant", "") fixes it. v2 supersedes rather than amends v1 because the defect failed open: a consumer pinned to _VERSION=v1 would keep receiving allows with no signal the rule beneath the version string had changed. The earlier dual-control correction stayed at v1 because it denied everything. Replay envelopes regenerated at v2; both request_digest values are byte-identical, so secrets-engine's digest join needs no re-pinning. The sweep this prompted found tenant-engine unscoped on tenant as well — deployed, and verified allowing tenant:coulomb. Not the same fix: its request tenant names the target rather than the caller, so a constant would break it. Recorded and carried by FLEX-WP-0022 rather than patched unilaterally. FLEX-WP-0021 closes at T05; the pin still serves v1 until a redeploy. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014aQMM1dPXaPiXVn6DwwtLd Assistant: claude-code Assistant-Model: opus Assistant-Process: 715613@bnt-lap001 Assistant-Session: fabd95c1-4c9e-4080-8849-8707ae025f80
110 lines
3.5 KiB
JSON
110 lines
3.5 KiB
JSON
{
|
|
"id": "decision:414734bb30381ff7",
|
|
"contract_version": "flex-auth.decision-record.v1",
|
|
"request_id": "check:secrets-engine-rotate",
|
|
"effect": "allow",
|
|
"reason": "catalog_lane_policy_matched",
|
|
"matched_policy_version": "v2",
|
|
"matched_rule": "catalog_lane_policy_matched",
|
|
"resource": {
|
|
"id": "lane:glas-primary",
|
|
"type": "secret-catalog-lane",
|
|
"system": "secrets-engine",
|
|
"tenant": "tenant:platform",
|
|
"attributes": {
|
|
"auth_targets": [],
|
|
"fields": [
|
|
"password"
|
|
],
|
|
"policy_targets": [],
|
|
"stage": "prod"
|
|
}
|
|
},
|
|
"subject": {
|
|
"id": "secrets-engine",
|
|
"type": "service",
|
|
"tenant": "tenant:platform",
|
|
"attributes": {
|
|
"description": "secrets-engine's own service identity, the single calling identity for the twelve gated catalog-lane actions it sends to POST /v1/check. Because it is the only subject, the package has no action_not_granted branch (FLEX-WP-0021-T02); registering a second identity is the revisit trigger.",
|
|
"display_name": "secrets-engine service principal",
|
|
"groups": [
|
|
"group:secrets-engine-lane-operators"
|
|
],
|
|
"organization_relation": "ServiceProvider",
|
|
"roles": [
|
|
"Operator"
|
|
]
|
|
}
|
|
},
|
|
"binding": {
|
|
"tenant": "tenant:platform",
|
|
"subject": {
|
|
"id": "secrets-engine",
|
|
"type": "service",
|
|
"tenant": "tenant:platform",
|
|
"attributes": {
|
|
"description": "secrets-engine's own service identity, the single calling identity for the twelve gated catalog-lane actions it sends to POST /v1/check. Because it is the only subject, the package has no action_not_granted branch (FLEX-WP-0021-T02); registering a second identity is the revisit trigger.",
|
|
"display_name": "secrets-engine service principal",
|
|
"groups": [
|
|
"group:secrets-engine-lane-operators"
|
|
],
|
|
"organization_relation": "ServiceProvider",
|
|
"roles": [
|
|
"Operator"
|
|
]
|
|
}
|
|
},
|
|
"action": "rotate",
|
|
"resource": {
|
|
"id": "lane:glas-primary",
|
|
"type": "secret-catalog-lane",
|
|
"system": "secrets-engine",
|
|
"tenant": "tenant:platform",
|
|
"attributes": {
|
|
"auth_targets": [],
|
|
"fields": [
|
|
"password"
|
|
],
|
|
"policy_targets": [],
|
|
"stage": "prod"
|
|
}
|
|
},
|
|
"request_digest": "sha256:de67324f54187055307a833235f83ced9fcd3a20952a27b3d19493ed39734345"
|
|
},
|
|
"lifetime": {
|
|
"kind": "ttl",
|
|
"ttl": "15m",
|
|
"not_before": "2026-09-06T18:35:18Z",
|
|
"expires_at": "2026-09-06T18:50:18Z"
|
|
},
|
|
"diagnostics": {
|
|
"action": "rotate",
|
|
"matched_relationship": "",
|
|
"policy_package": "secrets-engine.catalog-lane.lifecycle",
|
|
"policy_status": "ready",
|
|
"registry_resource": false,
|
|
"registry_subject": true
|
|
},
|
|
"provenance": {
|
|
"evaluator": "flex-auth/local",
|
|
"mode": "standalone",
|
|
"policy_package": "secrets-engine.catalog-lane.lifecycle",
|
|
"policy_version": "v2",
|
|
"policy_package_digest": "sha256:bd11c5fe77ce6439c65fea225ad6b71d2110efc5e7b5bc9b499c59cd0a53b8b4",
|
|
"registry_snapshot_digest": "sha256:f5a309bc0b36721fd6d9ad7f53eb21222162bc2eac62a0ab0802a9a1d51340bb",
|
|
"decision_time": "2026-09-06T18:35:18Z"
|
|
},
|
|
"caring": {
|
|
"profile": "caring-0.4.0-rc2",
|
|
"conformance_findings": [
|
|
{
|
|
"code": "CARING-DESCRIPTOR-MISSING",
|
|
"severity": "warning",
|
|
"message": "no CARING descriptor matched the request",
|
|
"fields": [
|
|
"caring_context"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|