77 lines
3.1 KiB
Markdown
77 lines
3.1 KiB
Markdown
|
|
# OpenBao: consume, attend, recover
|
||
|
|
|
||
|
|
Exercise status: unexercised
|
||
|
|
Workplan task: NK-WP-0009-T03
|
||
|
|
Pattern(s): platform-root custody (`docs/platform-root-custody.md`); credential routing
|
||
|
|
|
||
|
|
## Outcome
|
||
|
|
|
||
|
|
You can reach the already-deployed private OpenBao, read a secret you are
|
||
|
|
entitled to, know which unseal custody model governs it, and follow the
|
||
|
|
attended recovery path without exposing shares or tokens.
|
||
|
|
|
||
|
|
## Prerequisites
|
||
|
|
|
||
|
|
- **[owner: ops-bridge]** `bridge` CLI and the named `openbao-ui-railiance01`
|
||
|
|
tunnel; an SSH certificate (see the SSH tutorial).
|
||
|
|
- **[owner: ops-warden]** `warden` CLI for credential routing.
|
||
|
|
- **[owner: railiance-platform]** OpenBao is already deployed and private.
|
||
|
|
Greenfield deployment is a lab exercise only, never against the live estate.
|
||
|
|
|
||
|
|
## Architecture context
|
||
|
|
|
||
|
|
OpenBao is the runtime secret authority. railiance-platform deploys and
|
||
|
|
operates it; net-kingdom owns the custody canon and the guarded bootstrap
|
||
|
|
console, which refuses live `bao operator init`. Three unseal custody models
|
||
|
|
exist (`docs/openbao-unseal-custody-models.md`); production blocks the
|
||
|
|
`sops-held-automation` lab model.
|
||
|
|
|
||
|
|
## Steps
|
||
|
|
|
||
|
|
1. **[owner: ops-warden]** Find the owner of your need:
|
||
|
|
`warden route find "read a database password" --json`.
|
||
|
|
2. **[owner: ops-bridge]** Check and, if needed, restore the tunnel:
|
||
|
|
`bridge status`, then `bridge up openbao-ui-railiance01`.
|
||
|
|
3. **[owner: railiance-platform]** Authenticate with your own identity and read
|
||
|
|
only the path the routing result names. Use the owner's
|
||
|
|
`railiance-platform/docs/openbao.md` for exact commands.
|
||
|
|
4. **[owner: net-kingdom]** Know your custody model:
|
||
|
|
`python3 tools/security-bootstrap-console/security_bootstrap_console.py openbao-unseal-custody-models`.
|
||
|
|
5. **[owner: net-kingdom + railiance-platform]** Recovery after a seal event
|
||
|
|
follows `docs/openbao-attended-ceremony-runbook.md`: operator and witness
|
||
|
|
present, shares escrowed out of band, root token revoked after handoff.
|
||
|
|
Record the ceremony in a non-secret record and run
|
||
|
|
`make security-bootstrap-validate-openbao-ceremony-record`.
|
||
|
|
|
||
|
|
## Verification
|
||
|
|
|
||
|
|
Done when:
|
||
|
|
|
||
|
|
- `bridge status` shows `openbao-ui-railiance01` up.
|
||
|
|
- `make security-bootstrap-console` reports no unmet custody gate for the
|
||
|
|
selected model.
|
||
|
|
- `make security-bootstrap-validate-openbao-ceremony-record` passes on a
|
||
|
|
ceremony record, and fails on one containing a token-shaped marker.
|
||
|
|
|
||
|
|
## Rollback
|
||
|
|
|
||
|
|
- Close the tunnel: `bridge down openbao-ui-railiance01`.
|
||
|
|
- Read-only steps need no rollback. A ceremony cannot be undone; a mistaken
|
||
|
|
share transcription is corrected by re-escrow per the custody roster.
|
||
|
|
|
||
|
|
## Threat checks
|
||
|
|
|
||
|
|
- Init output, shares and tokens go to the operator's screen only: never to
|
||
|
|
chat, State Hub, logs, or a Git checkout.
|
||
|
|
- Never use a public Bao URL; `bao.coulomb.social` is retired.
|
||
|
|
- Never place root token and unseal shares in one artifact outside lab.
|
||
|
|
|
||
|
|
## Ownership notes
|
||
|
|
|
||
|
|
| Concern | Owner |
|
||
|
|
| --- | --- |
|
||
|
|
| OpenBao deployment, config, unseal execution | railiance-platform |
|
||
|
|
| Custody canon, ceremony record validator | net-kingdom |
|
||
|
|
| Tunnel | ops-bridge |
|
||
|
|
| Credential routing | ops-warden |
|