- docs/tutorials: template, OpenBao and SSH tutorials (unexercised) - tools/tutorial-verify + make tutorials-verify (NK-WP-0009-T06) - ADR-0009 proposed: expanded-mode Keycloak trigger and topology Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 295952@bnt-lap001 Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
2.3 KiB
2.3 KiB
Short-lived SSH credentials for admins, agents and automations
Exercise status: unexercised
Workplan task: NK-WP-0009-T04
Pattern(s): credential routing; ops-warden AccessManagementDirective
Outcome
An actor obtains a short-lived CA-signed SSH certificate and uses it through an ops-bridge tunnel, with no static key doing the work.
Prerequisites
- [owner: ops-warden]
wardenCLI installed; actor registered in the principals inventory. - [owner: ops-bridge]
bridgeCLI and a tunnel definition. - [owner: railiance-infra] Target hosts trust the SSH CA and carry the actor's principal.
Architecture context
ops-warden issues SSH certificates only (warden sign). ops-bridge runs the
tunnel and calls the cert_command before each connect. Max TTLs: adm 48 h,
agt 24 h, atm 8 h; the caller refreshes about 5 minutes before expiry.
See ops-warden/wiki/CertCommandInterface.md.
Steps
- [owner: ops-warden] Sign a public key for the actor:
warden sign <actor> --pubkey ~/.ssh/<actor>_ed25519.pub. - [owner: ops-bridge] Set
cert_commandto that command in the tunnel definition. Leave static-key mode unused. - [owner: ops-bridge]
bridge up <tunnel>thenbridge status. - [owner: ops-warden] Inspect the cert:
warden status; audit history viawarden log.
Verification
Done when:
ssh-keygen -L -f ~/.local/state/warden/<actor>-cert.pubshows the expected principal and aValid beforewithin the actor-type TTL.warden statusexits 0 (it exits 1 if any cert is expired).- After expiry, the tunnel reconnects only after
cert_commandsucceeds.
Rollback
bridge down <tunnel>;warden cleanupremoves stale certificates.- Certificates expire on their own; there is no long-lived credential to revoke. Remove the actor from the inventory to stop future signing.
Threat checks
- Cert files must be mode 600; never reuse a cert across reconnects.
- A non-zero
cert_commandexit is a failure and must trigger backoff. - ops-warden never vends API keys or passwords; route them with
warden route find.
Ownership notes
| Concern | Owner |
|---|---|
| Certificate issuance and TTL policy | ops-warden |
| Tunnel lifecycle and refresh | ops-bridge |
| Host CA trust and principals | railiance-infra |