Align approval registrations to the tenant:platform decision
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 33s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 33s
Operator decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6 accepts tenant:platform as the platform management tenant for the Glas approval chain, requiring exact spelling across the approval store, the service-client JWT claim and the lifecycle CheckRequest. Changes the tenant field on secrets-engine-approval and approval-engine-operator only, in the registration fixture and the provisioning packet. Unrelated clients and the human directory default keep tenant:coulomb, and no audience, scope, subject, role, lifetime or MFA grant changes. Adds issuance evidence that the approval shape emits tenant:platform exactly and never an alias the caller requests, that the OpenBao client gains no cross-tenant reach, and a fixture guard pinning every reviewed client's tenant. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P Assistant: claude-code Assistant-Model: opus Assistant-Process: 713576@bnt-lap001 Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
This commit is contained in:
parent
519e4d8ef1
commit
7a6666d1f9
8 changed files with 199 additions and 28 deletions
|
|
@ -1,4 +1,8 @@
|
|||
# Proposed non-secret admission packet. This is not executable authorization.
|
||||
# Tenant for both requests is tenant:platform per decision
|
||||
# 5ed3fb35-eca9-413a-82b9-95171ba85bf6 (landlord zone). Exact spelling required
|
||||
# across the approval store, these JWT claims and the lifecycle CheckRequest;
|
||||
# no alias to platform or tenant:coulomb.
|
||||
status: awaiting-custody-admission
|
||||
owner: key-cape
|
||||
resource_audience: approval-engine
|
||||
|
|
@ -7,7 +11,7 @@ registration_source: config/service-clients.example.yaml
|
|||
requests:
|
||||
- client_id: secrets-engine-approval
|
||||
subject: service:secrets-engine
|
||||
tenant: tenant:coulomb
|
||||
tenant: tenant:platform
|
||||
scopes: [approval:read, approval:consume]
|
||||
lifetime: 15m
|
||||
proposed_openbao_path: platform/workloads/secrets-engine/approval-client
|
||||
|
|
@ -19,7 +23,7 @@ requests:
|
|||
consumer: secrets-engine
|
||||
- client_id: approval-engine-operator
|
||||
subject: service:approval-engine-operator
|
||||
tenant: tenant:coulomb
|
||||
tenant: tenant:platform
|
||||
scopes: [approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:observe, approval:emit]
|
||||
lifetime: 15m
|
||||
proposed_openbao_path: platform/workloads/approval-engine/operator-client
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue