Pin tenant:platform, approval:create only, and the KeyCape env name. Live secret custody remains railiance-platform attended apply. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
135 lines
6.4 KiB
YAML
135 lines
6.4 KiB
YAML
# Non-secret static registration fragments for KeyCape's bounded JWT consumers. Merge these entries into the deployment-owned KeyCape config.
|
|
# The named environment variables must be materialized by an approved
|
|
# out-of-repository custody path; this file never contains their values.
|
|
clients:
|
|
- clientId: "codex-railiance-platform"
|
|
displayName: "Railiance platform coding agent"
|
|
allowedScopes: ["openbao:login"]
|
|
grantTypes: ["client_credentials"]
|
|
clientType: "confidential"
|
|
secretRef: "env:KEYCAPE_CODEX_RAILIANCE_PLATFORM_CLIENT_SECRET"
|
|
serviceSubject: "service:codex:railiance-platform"
|
|
tenant: "tenant:coulomb"
|
|
roles: ["coding-agent"]
|
|
tokenLifetime: "15m"
|
|
|
|
- clientId: "secrets-engine-openbao"
|
|
displayName: "secrets-engine OpenBao login"
|
|
allowedScopes: ["openbao:login"]
|
|
grantTypes: ["client_credentials"]
|
|
clientType: "confidential"
|
|
secretRef: "env:KEYCAPE_SECRETS_ENGINE_OPENBAO_CLIENT_SECRET"
|
|
serviceSubject: "service:secrets-engine"
|
|
tenant: "tenant:coulomb"
|
|
roles: ["secrets-engine"]
|
|
tokenLifetime: "15m"
|
|
|
|
- clientId: "secrets-engine-approval"
|
|
displayName: "secrets-engine approval consume client"
|
|
audience: "approval-engine"
|
|
allowedScopes: ["approval:read", "approval:consume"]
|
|
grantTypes: ["client_credentials"]
|
|
clientType: "confidential"
|
|
secretRef: "env:KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET"
|
|
serviceSubject: "service:secrets-engine"
|
|
# Landlord-zone platform tenant, decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6.
|
|
# Exact spelling; no alias to tenant:coulomb. See docs/tenant-claim-contract.md.
|
|
tenant: "tenant:platform"
|
|
roles: ["secrets-engine"]
|
|
tokenLifetime: "15m"
|
|
|
|
# WITHDRAWN BY THE REQUESTING OWNER, 2026-09-09. approval-engine asked that this
|
|
# client not be provisioned: nothing in their repository obtains an OAuth token,
|
|
# and scope by scope the bundle does not describe a single actor —
|
|
# approval:approve now belongs to the informed-decision human client,
|
|
# approval:emit is redundant (the server emits its own heartbeat with no token),
|
|
# and no requester identity was ever settled for approval:create. It was a
|
|
# convenience bundle written when a lifecycle operator was assumed to exist.
|
|
#
|
|
# Kept rather than deleted at their request: verifier custody CCR-2026-0018
|
|
# stands, so the client stays authenticable if a presenter ever appears. It is
|
|
# already live from the 2026-09-09 attended rollout, so this annotation does not
|
|
# remove it — see KEY-WP-0013-T02.
|
|
#
|
|
# Do not widen it, and do not treat it as a template. When a presenter is named,
|
|
# approval-engine will re-request NARROWED to that presenter's scopes, and
|
|
# approval:approve must not travel with the operational scopes.
|
|
- clientId: "approval-engine-operator"
|
|
displayName: "approval-engine lifecycle operator (withdrawn: no presenter)"
|
|
audience: "approval-engine"
|
|
allowedScopes: ["approval:create", "approval:read", "approval:approve", "approval:revoke", "approval:supersede", "approval:observe", "approval:emit"]
|
|
grantTypes: ["client_credentials"]
|
|
clientType: "confidential"
|
|
secretRef: "env:KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET"
|
|
serviceSubject: "service:approval-engine-operator"
|
|
# Landlord-zone platform tenant, decision 5ed3fb35-eca9-413a-82b9-95171ba85bf6.
|
|
# Exact spelling; no alias to tenant:coulomb. See docs/tenant-claim-contract.md.
|
|
tenant: "tenant:platform"
|
|
roles: ["approval-operator"]
|
|
tokenLifetime: "15m"
|
|
|
|
# Human approver browser client. Submitted by informed-decision 2026-09-10
|
|
# (INFD-WP-0001-T07) with the origin already live: both / and /auth/callback
|
|
# return 200 from 92.205.62.239 on a Let's Encrypt certificate
|
|
# CN=decisions.coulomb.social valid 2026-09-10 to 2026-12-09, deployed by
|
|
# railiance-apps. The host is decisions.coulomb.social, NOT the
|
|
# decide.coulomb.social an earlier draft proposed; register the string verbatim.
|
|
#
|
|
# The path currently serves an nginx placeholder while their surface is gated on
|
|
# APPROVAL-WP-0002-T01. That does not affect this registration: the redirect is
|
|
# matched as an exact string at /authorize and never fetched.
|
|
#
|
|
# No secretRef: this is a public client and authenticates with PKCE alone. No
|
|
# serviceSubject or roles either — on a browser client both are silently ignored
|
|
# and config validation rejects them (KEY-WP-0028); the subject and roles come
|
|
# from the directory user.
|
|
- clientId: "informed-decision-approver"
|
|
displayName: "informed-decision approver surface"
|
|
audience: "approval-engine"
|
|
redirectUris:
|
|
- "https://decisions.coulomb.social/auth/callback"
|
|
allowedScopes: ["openid", "approval:read", "approval:approve"]
|
|
grantTypes: ["authorization_code"]
|
|
clientType: "public"
|
|
# Declared, not inherited. Nothing populates domain.User.Tenant for approver
|
|
# users, so this reaches the token by the GH-DEC-2026-013 declared-gap route
|
|
# by construction, and the token says so: tenant_source is "registration",
|
|
# never "directory". Admissible for approval-engine's store-isolation gate;
|
|
# NOT admissible for any doctrine turning on this person's membership of the
|
|
# zone. See docs/tenant-claim-contract.md.
|
|
tenant: "tenant:platform"
|
|
# Approval is a human-in-the-loop control, so MFA is required rather than
|
|
# left to the provider default.
|
|
mfaRequired: true
|
|
|
|
# Separate create-only requester; actor matches the existing Flex Auth subject.
|
|
- clientId: secrets-engine-requester
|
|
displayName: Secrets Engine T03 approval requester
|
|
audience: approval-engine
|
|
allowedScopes:
|
|
- approval:create
|
|
grantTypes:
|
|
- client_credentials
|
|
clientType: confidential
|
|
secretRef: env:KEYCAPE_SECRETS_ENGINE_REQUESTER_CLIENT_SECRET
|
|
serviceSubject: secrets-engine
|
|
tenant: tenant:platform
|
|
roles:
|
|
- secrets-engine-requester
|
|
tokenLifetime: 15m
|
|
|
|
# Compact sitting presenter; actor is informed-decision, not secrets-engine.
|
|
- clientId: informed-decision-sitting-requester
|
|
displayName: Informed Decision compact-sitting approval requester
|
|
audience: approval-engine
|
|
allowedScopes:
|
|
- approval:create
|
|
grantTypes:
|
|
- client_credentials
|
|
clientType: confidential
|
|
secretRef: env:KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
|
|
serviceSubject: informed-decision
|
|
tenant: tenant:platform
|
|
roles:
|
|
- informed-decision-sitting-requester
|
|
tokenLifetime: 15m
|