62 lines
2.9 KiB
YAML
62 lines
2.9 KiB
YAML
|
|
spec: runbook-pack/v0.1
|
||
|
|
id: nk.ssh-certificates
|
||
|
|
title: Short-lived SSH credentials for admins, agents and automations
|
||
|
|
owner: net-kingdom
|
||
|
|
outcome: An actor obtains a short-lived CA-signed SSH certificate and uses it through an ops-bridge tunnel, with no static key doing the work.
|
||
|
|
exercise_status: unexercised
|
||
|
|
engine: native
|
||
|
|
parameters:
|
||
|
|
- {id: actor, label: Actor name, type: string, default: agt-claude-railiance01, pattern: "(adm|agt|atm)-[a-z0-9-]+", help: "Actor type prefix decides the maximum TTL: adm 48h, agt 24h, atm 8h."}
|
||
|
|
- {id: pubkey, label: Public key path, type: path, default: ~/.ssh/id_ed25519.pub}
|
||
|
|
- {id: tunnel, label: Tunnel name, type: string, default: k3s-api-railiance01, pattern: "[a-z0-9-]+"}
|
||
|
|
prerequisites:
|
||
|
|
- {text: warden CLI installed and actor present in the principals inventory, owner: ops-warden}
|
||
|
|
- {text: bridge CLI and a tunnel definition, owner: ops-bridge}
|
||
|
|
- {text: Target hosts trust the SSH CA and carry the actor principal, owner: railiance-infra}
|
||
|
|
steps:
|
||
|
|
- id: status-before
|
||
|
|
title: Look at current certificates
|
||
|
|
owner: ops-warden
|
||
|
|
command: warden status
|
||
|
|
verify: {done_when: You know which certificates are current and which are expired, expect: manual}
|
||
|
|
- id: sign
|
||
|
|
title: Sign a public key for the actor
|
||
|
|
owner: ops-warden
|
||
|
|
command: warden sign {{actor}} --pubkey {{pubkey}} > /tmp/{{actor}}-cert.pub
|
||
|
|
risk: changes-state
|
||
|
|
rollback: Delete /tmp/{{actor}}-cert.pub; the certificate expires on its own.
|
||
|
|
verify:
|
||
|
|
done_when: A certificate file exists and names the expected principal
|
||
|
|
command: ssh-keygen -L -f /tmp/{{actor}}-cert.pub
|
||
|
|
expect: exit-0
|
||
|
|
evidence: [actor, certificate_valid_before]
|
||
|
|
- id: inspect-ttl
|
||
|
|
title: Check the certificate lifetime
|
||
|
|
owner: ops-warden
|
||
|
|
command: ssh-keygen -L -f /tmp/{{actor}}-cert.pub | grep -E "Key ID|Principals|Valid"
|
||
|
|
verify: {done_when: "Valid before is within the actor-type TTL (adm 48h, agt 24h, atm 8h)", expect: manual}
|
||
|
|
- id: tunnel-up
|
||
|
|
title: Bring up the tunnel that uses cert_command
|
||
|
|
owner: ops-bridge
|
||
|
|
command: bridge up {{tunnel}}
|
||
|
|
risk: changes-state
|
||
|
|
rollback: bridge down {{tunnel}}
|
||
|
|
verify:
|
||
|
|
done_when: The tunnel shows connected
|
||
|
|
command: bridge status
|
||
|
|
expect: output-contains
|
||
|
|
contains: "{{tunnel}}"
|
||
|
|
- id: audit
|
||
|
|
title: Confirm the signing was audited
|
||
|
|
owner: ops-warden
|
||
|
|
command: warden log | tail -5
|
||
|
|
verify: {done_when: Your signing appears in the history, expect: manual}
|
||
|
|
threat_checks:
|
||
|
|
- Certificate files must be mode 600 and are never reused across reconnects.
|
||
|
|
- A non-zero cert_command exit is a failure and must trigger backoff.
|
||
|
|
- ops-warden never vends API keys or passwords; route them with warden route find.
|
||
|
|
ownership:
|
||
|
|
- {concern: Certificate issuance and TTL policy, owner: ops-warden}
|
||
|
|
- {concern: Tunnel lifecycle and refresh, owner: ops-bridge}
|
||
|
|
- {concern: Host CA trust and principals, owner: railiance-infra}
|