key-cape/docs/approval-engine-provisioning-request.yaml
tegwick dcebd46fa6
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
Require typed issuer refusals in live registration verification
Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-08 16:46:02 +02:00

79 lines
4.1 KiB
YAML

# Proposed non-secret admission packet. This is not executable authorization.
# Tenant for both requests is tenant:platform per decision
# 5ed3fb35-eca9-413a-82b9-95171ba85bf6 (landlord zone). Exact spelling required
# across the approval store, these JWT claims and the lifecycle CheckRequest;
# no alias to platform or tenant:coulomb.
status: awaiting-custody-admission
owner: key-cape
resource_audience: approval-engine
issuer: https://kc.coulomb.social
registration_source: config/service-clients.example.yaml
requests:
- client_id: secrets-engine-approval
subject: service:secrets-engine
tenant: tenant:platform
scopes: [approval:read, approval:consume]
lifetime: 15m
proposed_openbao_path: platform/workloads/secrets-engine/approval-client
field: CLIENT_SECRET
proposed_kubernetes_secret: sso/keycape-secrets-engine-approval-client
kubernetes_key: client-secret
keycape_environment: KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET
custody_owner: railiance-platform
consumer: secrets-engine
- client_id: approval-engine-operator
subject: service:approval-engine-operator
tenant: tenant:platform
scopes: [approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:observe, approval:emit]
lifetime: 15m
proposed_openbao_path: platform/workloads/approval-engine/operator-client
field: CLIENT_SECRET
proposed_kubernetes_secret: sso/keycape-approval-engine-operator-client
kubernetes_key: client-secret
keycape_environment: KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET
custody_owner: railiance-platform
consumer: approval-engine-operator
human_registration:
status: awaiting-exact-callback
blocks_service_client_rollout: false
owner: unassigned-approver-ui
scopes: [openid, approval:approve]
mfa_required: true
client_type: public
verification:
# The first two lines are now one runnable command per client; see
# docs/native-authentication.md, "Verifying a live registration". It writes
# nothing and prints no value, so it is safe to run against production.
- command: |
keycape verify-client -issuer https://kc.coulomb.social
-client-id secrets-engine-approval -audience approval-engine
-scope "approval:read approval:consume"
-secret-env KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET
-expect-subject service:secrets-engine -expect-tenant tenant:platform
-expect-roles secrets-engine
-deny-scope "approval:approve approval:revoke approval:supersede"
- command: |
keycape verify-client -issuer https://kc.coulomb.social
-client-id approval-engine-operator -audience approval-engine
-scope "approval:create approval:read approval:approve approval:revoke approval:supersede approval:observe approval:emit"
-secret-env KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET
-expect-subject service:approval-engine-operator -expect-tenant tenant:platform
-expect-roles approval-operator
-deny-scope "approval:consume"
- Check KeyCape and consumer readiness without emitting secrets or tokens.
- Preserve existing registrations and signing key; record versions and image digest.
- Human consume denial is approval-engine's to verify at its resource; KeyCape
proves only that the human client is never issued a consume grant.
blockers:
- Admit exact custody paths, field delivery, consumer identities and lifecycle authority.
- Resolve attended first-provision authority through the custody owner.
- Verify the actual upstream ID-token issuer before production image rollout.
custody_return:
owner_record: railiance-platform/workplans/RPF-WP-0035-credential-lane-implementation.md#Admit-KeyCape-approval-engine-client-custody-and-delivery
requests: [CCR-2026-0017, CCR-2026-0018]
status: proposed-awaiting-owner-approval
field_correction: CLIENT_SECRET
scope: KeyCape verifier-side copies only; client-side retrieval is not admitted.
human_registration_gate:
- The approver UI owner must supply its real client ID and exact callback.
- This gate blocks human approval entry; it does not block the two independent client_credentials registrations or service startup.