net-kingdom/runbooks/openbao-operating-path/pack.yaml

112 lines
5.9 KiB
YAML
Raw Normal View History

spec: runbook-pack/v0.1
id: nk.openbao-operating-path
title: "OpenBao: consume, attend, recover"
owner: net-kingdom
outcome: You can reach the already-deployed private OpenBao, know which owner serves a credential, know the custody model and the attended recovery path, and have seen the ceremony-record validator refuse a secret marker.
exercise_status: unexercised
engine: native
parameters:
- {id: need, label: The credential you need, type: text, default: read a database password, help: Plain words; used only to look up the owner.}
- {id: tunnel, label: OpenBao tunnel, type: string, default: openbao-ui-railiance01, pattern: "[a-z0-9-]+", help: The named ops-bridge tunnel; never a public Bao URL (bao.coulomb.social is retired).}
- {id: evidence, label: Ceremony record path, type: path, default: .local/openbao-ceremony-record.json, help: Relative to the net-kingdom checkout. Only meaningful after an attended ceremony.}
- {id: probe, label: Scratch path for the negative probe, type: path, default: .local/ceremony-negative-probe.json, help: Created and removed by the probe step.}
prerequisites:
- {text: bridge CLI and the named tunnel definition, owner: ops-bridge}
- {text: warden CLI for credential routing, owner: ops-warden}
- {text: OpenBao already deployed and private. Greenfield deployment is a lab exercise only and never part of this pack, owner: railiance-platform}
- {text: A net-kingdom checkout; commands run from its root, owner: net-kingdom}
steps:
- id: route
title: Find who owns the credential
owner: ops-warden
command: warden route find "{{need}}" --json | head -30
verify:
done_when: You know which repository owns the credential and that warden only routes, it does not vend
expect: manual
evidence: [owner_repo]
- id: tunnel-status
title: Check the OpenBao tunnel is connected
owner: ops-bridge
command: bridge status
verify:
done_when: The tunnel row shows connected
command: bridge status | grep -E "{{tunnel}} +connected"
expect: exit-0
- id: tunnel-check
title: Run the end-to-end tunnel diagnostic
owner: ops-bridge
command: bridge check {{tunnel}}
verify:
done_when: The diagnostic passes
command: bridge check {{tunnel}}
expect: exit-0
- id: custody-models
title: See the unseal custody models
owner: net-kingdom
command: python3 tools/security-bootstrap-console/security_bootstrap_console.py openbao-unseal-custody-models
verify:
done_when: attended-ceremony is listed as implemented
command: python3 tools/security-bootstrap-console/security_bootstrap_console.py openbao-unseal-custody-models | grep -q attended-ceremony
expect: exit-0
- id: console-gates
title: Read the custody gates for the selected model
owner: net-kingdom
command: make security-bootstrap-console
verify:
done_when: You have read every gate and know which are met and which are not
expect: manual
- id: recovery-read
title: Read the attended recovery path
owner: net-kingdom
command: sed -n 1,82p docs/openbao-attended-ceremony-runbook.md
verify:
done_when: You can state who must be present, where each unseal share goes, and when the root token is revoked
expect: manual
- id: probe-refused
title: Watch the ceremony-record validator refuse a secret marker
owner: net-kingdom
description: Writes a scratch file holding a fake token-shaped marker, runs the validator on it, and removes the file. The marker is assembled at run time so this pack never contains one.
command: |
printf '{"note":"%s%s"}\n' hvs. AAAAAAAAAAAAAAAA > {{probe}}
make security-bootstrap-validate-openbao-ceremony-record EVIDENCE={{probe}} 2>&1 | grep "secret-looking marker present"
rm -f {{probe}}
risk: changes-state
rollback: rm -f the probe file; nothing else is written.
verify:
done_when: The validator names a secret-looking marker as a reason for refusal
command: |
printf '{"note":"%s%s"}\n' hvs. AAAAAAAAAAAAAAAA > {{probe}}
make security-bootstrap-validate-openbao-ceremony-record EVIDENCE={{probe}} 2>&1 | grep -q "secret-looking marker present"
r=$?
rm -f {{probe}}
exit $r
expect: exit-0
- id: valid-record
title: Validate a real ceremony record
owner: net-kingdom
description: Only possible after an attended ceremony has produced a record. Without one, skip this step; a run with a skipped step cannot exercise the pack.
command: make security-bootstrap-validate-openbao-ceremony-record EVIDENCE={{evidence}}
verify:
done_when: The validator passes on the ceremony record
command: make security-bootstrap-validate-openbao-ceremony-record EVIDENCE={{evidence}}
expect: exit-0
- id: read-secret
title: Read one secret you are entitled to
owner: railiance-platform
description: Authenticate with your own identity and read only the path the routing result names, following railiance-platform/docs/openbao.md. Never paste the value anywhere.
risk: attended
rollback: Close the session; the read changes no state. If a value was exposed, treat it as compromised and rotate it through its owner.
verify:
done_when: You read only the routed path with your own identity and no value was pasted into chat, logs, State Hub or a checkout
expect: manual
threat_checks:
- Init output, unseal shares and tokens go to the operator's screen only, never to chat, State Hub, logs or a Git checkout.
- Never use a public Bao URL; bao.coulomb.social is retired.
- Never place the root token and unseal shares in one artifact outside a lab.
- This pack never initializes or unseals the live estate.
ownership:
- {concern: "OpenBao deployment, configuration and unseal execution", owner: railiance-platform}
- {concern: Custody canon and the ceremony-record validator, owner: net-kingdom}
- {concern: Tunnel, owner: ops-bridge}
- {concern: Credential routing, owner: ops-warden}