key-cape/config/service-clients.example.yaml
tegwick 1620ce2edd
Some checks failed
Authentication acceptance / acceptance (push) Failing after 1m7s
Authentication acceptance / provider-contract (push) Successful in 15s
Build and Publish Container Image / build-and-push (push) Successful in 40s
Register informed-decision-sitting-requester as create-only.
Pin tenant:platform, approval:create only, and the KeyCape env name.
Live secret custody remains railiance-platform attended apply.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
2026-09-15 20:08:07 +02:00

135 lines
6.4 KiB
YAML

# Non-secret static registration fragments for KeyCape's bounded JWT consumers. Merge these entries into the deployment-owned KeyCape config.
# The named environment variables must be materialized by an approved
# out-of-repository custody path; this file never contains their values.
clients:
- clientId: "codex-railiance-platform"
displayName: "Railiance platform coding agent"
allowedScopes: ["openbao:login"]
grantTypes: ["client_credentials"]
clientType: "confidential"
secretRef: "env:KEYCAPE_CODEX_RAILIANCE_PLATFORM_CLIENT_SECRET"
serviceSubject: "service:codex:railiance-platform"
tenant: "tenant:coulomb"
roles: ["coding-agent"]
tokenLifetime: "15m"
- clientId: "secrets-engine-openbao"
displayName: "secrets-engine OpenBao login"
allowedScopes: ["openbao:login"]
grantTypes: ["client_credentials"]
clientType: "confidential"
secretRef: "env:KEYCAPE_SECRETS_ENGINE_OPENBAO_CLIENT_SECRET"
serviceSubject: "service:secrets-engine"
tenant: "tenant:coulomb"
roles: ["secrets-engine"]
tokenLifetime: "15m"
- clientId: "secrets-engine-approval"
displayName: "secrets-engine approval consume client"
audience: "approval-engine"
allowedScopes: ["approval:read", "approval:consume"]
grantTypes: ["client_credentials"]
clientType: "confidential"
secretRef: "env:KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET"
serviceSubject: "service:secrets-engine"
# Landlord-zone platform tenant, decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6.
# Exact spelling; no alias to tenant:coulomb. See docs/tenant-claim-contract.md.
tenant: "tenant:platform"
roles: ["secrets-engine"]
tokenLifetime: "15m"
# WITHDRAWN BY THE REQUESTING OWNER, 2026-09-09. approval-engine asked that this
# client not be provisioned: nothing in their repository obtains an OAuth token,
# and scope by scope the bundle does not describe a single actor —
# approval:approve now belongs to the informed-decision human client,
# approval:emit is redundant (the server emits its own heartbeat with no token),
# and no requester identity was ever settled for approval:create. It was a
# convenience bundle written when a lifecycle operator was assumed to exist.
#
# Kept rather than deleted at their request: verifier custody CCR-2026-0018
# stands, so the client stays authenticable if a presenter ever appears. It is
# already live from the 2026-09-09 attended rollout, so this annotation does not
# remove it — see KEY-WP-0013-T02.
#
# Do not widen it, and do not treat it as a template. When a presenter is named,
# approval-engine will re-request NARROWED to that presenter's scopes, and
# approval:approve must not travel with the operational scopes.
- clientId: "approval-engine-operator"
displayName: "approval-engine lifecycle operator (withdrawn: no presenter)"
audience: "approval-engine"
allowedScopes: ["approval:create", "approval:read", "approval:approve", "approval:revoke", "approval:supersede", "approval:observe", "approval:emit"]
grantTypes: ["client_credentials"]
clientType: "confidential"
secretRef: "env:KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET"
serviceSubject: "service:approval-engine-operator"
# Landlord-zone platform tenant, decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6.
# Exact spelling; no alias to tenant:coulomb. See docs/tenant-claim-contract.md.
tenant: "tenant:platform"
roles: ["approval-operator"]
tokenLifetime: "15m"
# Human approver browser client. Submitted by informed-decision 2026-09-10
# (INFD-WP-0001-T07) with the origin already live: both / and /auth/callback
# return 200 from 92.205.62.239 on a Let's Encrypt certificate
# CN=decisions.coulomb.social valid 2026-09-10 to 2026-12-09, deployed by
# railiance-apps. The host is decisions.coulomb.social, NOT the
# decide.coulomb.social an earlier draft proposed; register the string verbatim.
#
# The path currently serves an nginx placeholder while their surface is gated on
# APPROVAL-WP-0002-T01. That does not affect this registration: the redirect is
# matched as an exact string at /authorize and never fetched.
#
# No secretRef: this is a public client and authenticates with PKCE alone. No
# serviceSubject or roles either — on a browser client both are silently ignored
# and config validation rejects them (KEY-WP-0028); the subject and roles come
# from the directory user.
- clientId: "informed-decision-approver"
displayName: "informed-decision approver surface"
audience: "approval-engine"
redirectUris:
- "https://decisions.coulomb.social/auth/callback"
allowedScopes: ["openid", "approval:read", "approval:approve"]
grantTypes: ["authorization_code"]
clientType: "public"
# Declared, not inherited. Nothing populates domain.User.Tenant for approver
# users, so this reaches the token by the GH-DEC-2026-013 declared-gap route
# by construction, and the token says so: tenant_source is "registration",
# never "directory". Admissible for approval-engine's store-isolation gate;
# NOT admissible for any doctrine turning on this person's membership of the
# zone. See docs/tenant-claim-contract.md.
tenant: "tenant:platform"
# Approval is a human-in-the-loop control, so MFA is required rather than
# left to the provider default.
mfaRequired: true
# Separate create-only requester; actor matches the existing Flex Auth subject.
- clientId: secrets-engine-requester
displayName: Secrets Engine T03 approval requester
audience: approval-engine
allowedScopes:
- approval:create
grantTypes:
- client_credentials
clientType: confidential
secretRef: env:KEYCAPE_SECRETS_ENGINE_REQUESTER_CLIENT_SECRET
serviceSubject: secrets-engine
tenant: tenant:platform
roles:
- secrets-engine-requester
tokenLifetime: 15m
# Compact sitting presenter; actor is informed-decision, not secrets-engine.
- clientId: informed-decision-sitting-requester
displayName: Informed Decision compact-sitting approval requester
audience: approval-engine
allowedScopes:
- approval:create
grantTypes:
- client_credentials
clientType: confidential
secretRef: env:KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
serviceSubject: informed-decision
tenant: tenant:platform
roles:
- informed-decision-sitting-requester
tokenLifetime: 15m