Align approval registrations to the tenant:platform decision
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 33s

Operator decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6 accepts tenant:platform
as the platform management tenant for the Glas approval chain, requiring exact
spelling across the approval store, the service-client JWT claim and the
lifecycle CheckRequest.

Changes the tenant field on secrets-engine-approval and approval-engine-operator
only, in the registration fixture and the provisioning packet. Unrelated clients
and the human directory default keep tenant:coulomb, and no audience, scope,
subject, role, lifetime or MFA grant changes.

Adds issuance evidence that the approval shape emits tenant:platform exactly and
never an alias the caller requests, that the OpenBao client gains no
cross-tenant reach, and a fixture guard pinning every reviewed client's tenant.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
This commit is contained in:
tegwick 2026-09-06 22:30:32 +02:00
parent 519e4d8ef1
commit 7a6666d1f9
8 changed files with 199 additions and 28 deletions

View file

@ -36,3 +36,36 @@ func TestServiceRegistrationAudienceAndScopeIsolation(t *testing.T) {
t.Fatal("OpenBao audience default changed")
}
}
// The Glas approval chain requires exact tenant spelling across the approval
// store, these JWT claims and the lifecycle CheckRequest (decision
// 5ed3fb35-eca9-413a-82b9-95171ba85bf6). Aliases to "platform" or
// "tenant:coulomb" are rejected, and unrelated clients keep their own tenant.
func TestServiceRegistrationTenantsAreExactPerDecision(t *testing.T) {
cfg, err := config.Load("../../../config/service-clients.example.yaml")
if err != nil {
t.Fatal(err)
}
want := map[string]string{
"secrets-engine-approval": "tenant:platform",
"approval-engine-operator": "tenant:platform",
"codex-railiance-platform": "tenant:coulomb",
"secrets-engine-openbao": "tenant:coulomb",
}
seen := map[string]bool{}
for _, c := range cfg.Clients {
expected, ok := want[c.ClientID]
if !ok {
t.Fatalf("unreviewed client %s has tenant %q", c.ClientID, c.Tenant)
}
if c.Tenant != expected {
t.Fatalf("%s: tenant %q, want exactly %q", c.ClientID, c.Tenant, expected)
}
seen[c.ClientID] = true
}
for id := range want {
if !seen[id] {
t.Fatalf("missing reviewed registration %s", id)
}
}
}