# OpenBao: consume, attend, recover Exercise status: unexercised Workplan task: NK-WP-0009-T03 Pattern(s): platform-root custody (`docs/platform-root-custody.md`); credential routing ## Outcome You can reach the already-deployed private OpenBao, read a secret you are entitled to, know which unseal custody model governs it, and follow the attended recovery path without exposing shares or tokens. ## Prerequisites - **[owner: ops-bridge]** `bridge` CLI and the named `openbao-ui-railiance01` tunnel; an SSH certificate (see the SSH tutorial). - **[owner: ops-warden]** `warden` CLI for credential routing. - **[owner: railiance-platform]** OpenBao is already deployed and private. Greenfield deployment is a lab exercise only, never against the live estate. ## Architecture context OpenBao is the runtime secret authority. railiance-platform deploys and operates it; net-kingdom owns the custody canon and the guarded bootstrap console, which refuses live `bao operator init`. Three unseal custody models exist (`docs/openbao-unseal-custody-models.md`); production blocks the `sops-held-automation` lab model. ## Steps 1. **[owner: ops-warden]** Find the owner of your need: `warden route find "read a database password" --json`. 2. **[owner: ops-bridge]** Check and, if needed, restore the tunnel: `bridge status`, then `bridge up openbao-ui-railiance01`. 3. **[owner: railiance-platform]** Authenticate with your own identity and read only the path the routing result names. Use the owner's `railiance-platform/docs/openbao.md` for exact commands. 4. **[owner: net-kingdom]** Know your custody model: `python3 tools/security-bootstrap-console/security_bootstrap_console.py openbao-unseal-custody-models`. 5. **[owner: net-kingdom + railiance-platform]** Recovery after a seal event follows `docs/openbao-attended-ceremony-runbook.md`: operator and witness present, shares escrowed out of band, root token revoked after handoff. Record the ceremony in a non-secret record and run `make security-bootstrap-validate-openbao-ceremony-record`. ## Verification Done when: - `bridge status` shows `openbao-ui-railiance01` up. - `make security-bootstrap-console` reports no unmet custody gate for the selected model. - `make security-bootstrap-validate-openbao-ceremony-record` passes on a ceremony record, and fails on one containing a token-shaped marker. ## Rollback - Close the tunnel: `bridge down openbao-ui-railiance01`. - Read-only steps need no rollback. A ceremony cannot be undone; a mistaken share transcription is corrected by re-escrow per the custody roster. ## Threat checks - Init output, shares and tokens go to the operator's screen only: never to chat, State Hub, logs, or a Git checkout. - Never use a public Bao URL; `bao.coulomb.social` is retired. - Never place root token and unseal shares in one artifact outside lab. ## Ownership notes | Concern | Owner | | --- | --- | | OpenBao deployment, config, unseal execution | railiance-platform | | Custody canon, ceremony record validator | net-kingdom | | Tunnel | ops-bridge | | Credential routing | ops-warden |