# Short-lived SSH credentials for admins, agents and automations Exercise status: unexercised Workplan task: NK-WP-0009-T04 Pattern(s): credential routing; ops-warden `AccessManagementDirective` ## Outcome An actor obtains a short-lived CA-signed SSH certificate and uses it through an ops-bridge tunnel, with no static key doing the work. ## Prerequisites - **[owner: ops-warden]** `warden` CLI installed; actor registered in the principals inventory. - **[owner: ops-bridge]** `bridge` CLI and a tunnel definition. - **[owner: railiance-infra]** Target hosts trust the SSH CA and carry the actor's principal. ## Architecture context ops-warden issues SSH certificates only (`warden sign`). ops-bridge runs the tunnel and calls the `cert_command` before each connect. Max TTLs: `adm` 48 h, `agt` 24 h, `atm` 8 h; the caller refreshes about 5 minutes before expiry. See `ops-warden/wiki/CertCommandInterface.md`. ## Steps 1. **[owner: ops-warden]** Sign a public key for the actor: `warden sign --pubkey ~/.ssh/_ed25519.pub`. 2. **[owner: ops-bridge]** Set `cert_command` to that command in the tunnel definition. Leave static-key mode unused. 3. **[owner: ops-bridge]** `bridge up ` then `bridge status`. 4. **[owner: ops-warden]** Inspect the cert: `warden status`; audit history via `warden log`. ## Verification Done when: - `ssh-keygen -L -f ~/.local/state/warden/-cert.pub` shows the expected principal and a `Valid before` within the actor-type TTL. - `warden status` exits 0 (it exits 1 if any cert is expired). - After expiry, the tunnel reconnects only after `cert_command` succeeds. ## Rollback - `bridge down `; `warden cleanup` removes stale certificates. - Certificates expire on their own; there is no long-lived credential to revoke. Remove the actor from the inventory to stop future signing. ## Threat checks - Cert files must be mode 600; never reuse a cert across reconnects. - A non-zero `cert_command` exit is a failure and must trigger backoff. - ops-warden never vends API keys or passwords; route them with `warden route find`. ## Ownership notes | Concern | Owner | | --- | --- | | Certificate issuance and TTL policy | ops-warden | | Tunnel lifecycle and refresh | ops-bridge | | Host CA trust and principals | railiance-infra |