Add native verified login and service-token commands
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 41s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 41s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06e87-e039-7ed2-b85c-20ad37f8a21b
This commit is contained in:
parent
66df5fcf07
commit
b989de4e90
12 changed files with 928 additions and 14 deletions
45
docs/approval-engine-provisioning-request.yaml
Normal file
45
docs/approval-engine-provisioning-request.yaml
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
# Proposed non-secret admission packet. This is not executable authorization.
|
||||
status: awaiting-custody-admission
|
||||
owner: key-cape
|
||||
resource_audience: approval-engine
|
||||
issuer: https://kc.coulomb.social
|
||||
registration_source: config/service-clients.example.yaml
|
||||
requests:
|
||||
- client_id: secrets-engine-approval
|
||||
subject: service:secrets-engine
|
||||
tenant: tenant:coulomb
|
||||
scopes: [approval:read, approval:consume]
|
||||
lifetime: 15m
|
||||
proposed_openbao_path: platform/workloads/secrets-engine/approval-client
|
||||
field: client_secret
|
||||
proposed_kubernetes_secret: sso/keycape-secrets-engine-approval-client
|
||||
kubernetes_key: client-secret
|
||||
keycape_environment: KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET
|
||||
custody_owner: railiance-platform
|
||||
consumer: secrets-engine
|
||||
- client_id: approval-engine-operator
|
||||
subject: service:approval-engine-operator
|
||||
tenant: tenant:coulomb
|
||||
scopes: [approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:observe, approval:emit]
|
||||
lifetime: 15m
|
||||
proposed_openbao_path: platform/workloads/approval-engine/operator-client
|
||||
field: client_secret
|
||||
proposed_kubernetes_secret: sso/keycape-approval-engine-operator-client
|
||||
kubernetes_key: client-secret
|
||||
keycape_environment: KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET
|
||||
custody_owner: railiance-platform
|
||||
consumer: approval-engine-operator
|
||||
human_registration:
|
||||
status: awaiting-exact-callback
|
||||
scopes: [openid, approval:approve]
|
||||
mfa_required: true
|
||||
client_type: public
|
||||
verification:
|
||||
- Validate the new signature against deployed JWKS and all exact claim bindings.
|
||||
- Reject wrong secrets, operator consume, PEP lifecycle scopes, and human consume.
|
||||
- Check KeyCape and consumer readiness without emitting secrets or tokens.
|
||||
- Preserve existing registrations and signing key; record versions and image digest.
|
||||
blockers:
|
||||
- Admit exact custody paths, field delivery, consumer identities and lifecycle authority.
|
||||
- Resolve attended first-provision authority through the custody owner.
|
||||
- Supply exact human client ID and callback URI.
|
||||
Loading…
Add table
Add a link
Reference in a new issue