spec: runbook-pack/v0.1 id: nk.ssh-certificates title: Short-lived SSH credentials for admins, agents and automations owner: net-kingdom outcome: An actor obtains a short-lived CA-signed SSH certificate and uses it through an ops-bridge tunnel, with no static key doing the work. exercise_status: unexercised engine: native parameters: - {id: actor, label: Actor name, type: string, default: agt-claude-railiance01, pattern: "(adm|agt|atm)-[a-z0-9-]+", help: "Actor type prefix decides the maximum TTL: adm 48h, agt 24h, atm 8h."} - {id: pubkey, label: Public key path, type: path, default: ~/.ssh/id_ed25519.pub} - {id: tunnel, label: Tunnel name, type: string, default: k3s-api-railiance01, pattern: "[a-z0-9-]+"} prerequisites: - {text: warden CLI installed and actor present in the principals inventory, owner: ops-warden} - {text: bridge CLI and a tunnel definition, owner: ops-bridge} - {text: Target hosts trust the SSH CA and carry the actor principal, owner: railiance-infra} steps: - id: status-before title: Look at current certificates owner: ops-warden command: warden status verify: {done_when: You know which certificates are current and which are expired, expect: manual} - id: sign title: Sign a public key for the actor owner: ops-warden command: warden sign {{actor}} --pubkey {{pubkey}} > /tmp/{{actor}}-cert.pub risk: changes-state rollback: Delete /tmp/{{actor}}-cert.pub; the certificate expires on its own. verify: done_when: A certificate file exists and names the expected principal command: ssh-keygen -L -f /tmp/{{actor}}-cert.pub expect: exit-0 evidence: [actor, certificate_valid_before] - id: inspect-ttl title: Check the certificate lifetime owner: ops-warden command: ssh-keygen -L -f /tmp/{{actor}}-cert.pub | grep -E "Key ID|Principals|Valid" verify: {done_when: "Valid before is within the actor-type TTL (adm 48h, agt 24h, atm 8h)", expect: manual} - id: tunnel-up title: Bring up the tunnel that uses cert_command owner: ops-bridge command: bridge up {{tunnel}} risk: changes-state rollback: bridge down {{tunnel}} verify: done_when: The tunnel shows connected command: bridge status expect: output-contains contains: "{{tunnel}}" - id: audit title: Confirm the signing was audited owner: ops-warden command: warden log | tail -5 verify: {done_when: Your signing appears in the history, expect: manual} threat_checks: - Certificate files must be mode 600 and are never reused across reconnects. - A non-zero cert_command exit is a failure and must trigger backoff. - ops-warden never vends API keys or passwords; route them with warden route find. ownership: - {concern: Certificate issuance and TTL policy, owner: ops-warden} - {concern: Tunnel lifecycle and refresh, owner: ops-bridge} - {concern: Host CA trust and principals, owner: railiance-infra}