# Proposed non-secret admission packet. This is not executable authorization. # Tenant for both requests is tenant:platform per decision # 5ed3fb35-eca9-413a-82b9-95171ba85bf6 (landlord zone). Exact spelling required # across the approval store, these JWT claims and the lifecycle CheckRequest; # no alias to platform or tenant:coulomb. status: awaiting-custody-admission owner: key-cape resource_audience: approval-engine issuer: https://kc.coulomb.social registration_source: config/service-clients.example.yaml requests: - client_id: secrets-engine-approval subject: service:secrets-engine tenant: tenant:platform scopes: [approval:read, approval:consume] lifetime: 15m proposed_openbao_path: platform/workloads/secrets-engine/approval-client field: client_secret proposed_kubernetes_secret: sso/keycape-secrets-engine-approval-client kubernetes_key: client-secret keycape_environment: KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET custody_owner: railiance-platform consumer: secrets-engine - client_id: approval-engine-operator subject: service:approval-engine-operator tenant: tenant:platform scopes: [approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:observe, approval:emit] lifetime: 15m proposed_openbao_path: platform/workloads/approval-engine/operator-client field: client_secret proposed_kubernetes_secret: sso/keycape-approval-engine-operator-client kubernetes_key: client-secret keycape_environment: KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET custody_owner: railiance-platform consumer: approval-engine-operator human_registration: status: awaiting-exact-callback scopes: [openid, approval:approve] mfa_required: true client_type: public verification: # The first two lines are now one runnable command per client; see # docs/native-authentication.md, "Verifying a live registration". It writes # nothing and prints no value, so it is safe to run against production. - command: | keycape verify-client -issuer https://kc.coulomb.social -client-id secrets-engine-approval -audience approval-engine -scope "approval:read approval:consume" -secret-env KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET -expect-subject service:secrets-engine -expect-tenant tenant:platform -expect-roles secrets-engine -deny-scope "approval:approve approval:revoke approval:supersede" - command: | keycape verify-client -issuer https://kc.coulomb.social -client-id approval-engine-operator -audience approval-engine -scope "approval:create approval:read approval:approve approval:revoke approval:supersede approval:observe approval:emit" -secret-env KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET -expect-subject service:approval-engine-operator -expect-tenant tenant:platform -expect-roles approval-operator -deny-scope "approval:consume" - Check KeyCape and consumer readiness without emitting secrets or tokens. - Preserve existing registrations and signing key; record versions and image digest. - Human consume denial is approval-engine's to verify at its resource; KeyCape proves only that the human client is never issued a consume grant. blockers: - Admit exact custody paths, field delivery, consumer identities and lifecycle authority. - Resolve attended first-provision authority through the custody owner. - Supply exact human client ID and callback URI.