66 lines
2.3 KiB
Markdown
66 lines
2.3 KiB
Markdown
|
|
# Short-lived SSH credentials for admins, agents and automations
|
||
|
|
|
||
|
|
Exercise status: unexercised
|
||
|
|
Workplan task: NK-WP-0009-T04
|
||
|
|
Pattern(s): credential routing; ops-warden `AccessManagementDirective`
|
||
|
|
|
||
|
|
## Outcome
|
||
|
|
|
||
|
|
An actor obtains a short-lived CA-signed SSH certificate and uses it through
|
||
|
|
an ops-bridge tunnel, with no static key doing the work.
|
||
|
|
|
||
|
|
## Prerequisites
|
||
|
|
|
||
|
|
- **[owner: ops-warden]** `warden` CLI installed; actor registered in the
|
||
|
|
principals inventory.
|
||
|
|
- **[owner: ops-bridge]** `bridge` CLI and a tunnel definition.
|
||
|
|
- **[owner: railiance-infra]** Target hosts trust the SSH CA and carry the
|
||
|
|
actor's principal.
|
||
|
|
|
||
|
|
## Architecture context
|
||
|
|
|
||
|
|
ops-warden issues SSH certificates only (`warden sign`). ops-bridge runs the
|
||
|
|
tunnel and calls the `cert_command` before each connect. Max TTLs: `adm` 48 h,
|
||
|
|
`agt` 24 h, `atm` 8 h; the caller refreshes about 5 minutes before expiry.
|
||
|
|
See `ops-warden/wiki/CertCommandInterface.md`.
|
||
|
|
|
||
|
|
## Steps
|
||
|
|
|
||
|
|
1. **[owner: ops-warden]** Sign a public key for the actor:
|
||
|
|
`warden sign <actor> --pubkey ~/.ssh/<actor>_ed25519.pub`.
|
||
|
|
2. **[owner: ops-bridge]** Set `cert_command` to that command in the tunnel
|
||
|
|
definition. Leave static-key mode unused.
|
||
|
|
3. **[owner: ops-bridge]** `bridge up <tunnel>` then `bridge status`.
|
||
|
|
4. **[owner: ops-warden]** Inspect the cert: `warden status`; audit history via
|
||
|
|
`warden log`.
|
||
|
|
|
||
|
|
## Verification
|
||
|
|
|
||
|
|
Done when:
|
||
|
|
|
||
|
|
- `ssh-keygen -L -f ~/.local/state/warden/<actor>-cert.pub` shows the expected
|
||
|
|
principal and a `Valid before` within the actor-type TTL.
|
||
|
|
- `warden status` exits 0 (it exits 1 if any cert is expired).
|
||
|
|
- After expiry, the tunnel reconnects only after `cert_command` succeeds.
|
||
|
|
|
||
|
|
## Rollback
|
||
|
|
|
||
|
|
- `bridge down <tunnel>`; `warden cleanup` removes stale certificates.
|
||
|
|
- Certificates expire on their own; there is no long-lived credential to
|
||
|
|
revoke. Remove the actor from the inventory to stop future signing.
|
||
|
|
|
||
|
|
## Threat checks
|
||
|
|
|
||
|
|
- Cert files must be mode 600; never reuse a cert across reconnects.
|
||
|
|
- A non-zero `cert_command` exit is a failure and must trigger backoff.
|
||
|
|
- ops-warden never vends API keys or passwords; route them with
|
||
|
|
`warden route find`.
|
||
|
|
|
||
|
|
## Ownership notes
|
||
|
|
|
||
|
|
| Concern | Owner |
|
||
|
|
| --- | --- |
|
||
|
|
| Certificate issuance and TTL policy | ops-warden |
|
||
|
|
| Tunnel lifecycle and refresh | ops-bridge |
|
||
|
|
| Host CA trust and principals | railiance-infra |
|