net-kingdom/workplans/NK-WP-0032-openbao-operator-loopback-callback.md
tegwick 9383b94019 Reconcile infrastructure workplans and retire stale flex-auth references
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
2026-09-28 12:40:03 +02:00

4.2 KiB

id type title domain repo status flavor owner topic_slug created updated related origin origin_ref state_hub_workstream_id
NK-WP-0032 workplan Admit the operator-tunneled OpenBao browser callback infotech net-kingdom finished implementation codex net-kingdom 2026-08-23 2026-09-28
RMASTER-WP-0020-T09
RAILIANCE-WP-0027-T03
routed State Hub message 5e56b413-d8ec-4718-b432-2debc40498ca 516ee5b9-685b-5986-88d2-bde66c2ba96c

NK-WP-0032 — OpenBao operator loopback callback

Goal

Admit the exact callback derived by the ClusterIP-only OpenBao UI gateway when operators reach it through the named openbao-ui-railiance01 tunnel, without weakening MFA or broadening the OpenBao policy.

T01 — Update and validate the code-defined callback contract

id: NK-WP-0032-T01
status: done
priority: high
state_hub_task_id: "f231077e-7440-5f20-9045-afab90fa8286"

Add http://127.0.0.1:18200/ui/vault/auth/netkingdom/oidc/callback to the KeyCape openbao-admin public-PKCE client, the OpenBao platform-admin role template, bootstrap validation, live authorization verifier, and operator documentation. Preserve the former public callbacks only for the bounded listener rollback window.

Completed 2026-08-23. Three focused regression tests, Python compilation, Bash syntax validation, and git diff --check pass.

T02 — Apply and prove the live KeyCape client addition

id: NK-WP-0032-T02
status: done
priority: high
state_hub_task_id: "360bc410-d7ed-53b6-b5fc-2ce8b37b653f"

Patch only the code-defined non-secret client configuration, restart KeyCape, and prove both the live Secret contract and public authorize endpoint accept the exact loopback URI. Do not record the Secret contents or an authorization code.

Completed 2026-08-23 on Railiance01. sso/keycape-config was patched without printing decoded data, deployment/keycape rolled out successfully, and the value-safe verifier proved the live client contract, exact loopback redirect, legacy rollback redirects, and OIDC discovery endpoint. No authorization code or Secret value was observed.

T03 — Apply and prove the live OpenBao role addition

id: NK-WP-0032-T03
status: done
priority: high
state_hub_task_id: "73b77110-2d4f-527e-98eb-2ec33897681e"

An attended platform-admin/root-sudo authority must apply the updated role template to auth/netkingdom/role/platform-admin. Record only that the exact URI is admitted. Do not record a token, accessor, authorization code, callback query, browser storage, or role response body.

T04 — Return attended-login evidence to Railiance Platform

id: NK-WP-0032-T04
status: done
priority: high
state_hub_task_id: "f62bda4a-7607-5c50-9e04-664cc1b829ac"

After T02 and T03 pass, perform one attended MFA login through http://127.0.0.1:18200 and return only the success/failure outcome. This task does not authorize public Ingress retraction; Railiance Platform retains that separate guarded hold point.

Infrastructure review — 2026-09-28

T03 and T04 are complete from existing owner evidence; no new attended login or role write is needed for this reconciliation. Railiance Platform docs/evidence/2026-09-15-openbao-loopback-callback-already-present.json proves the exact callback already present, Warden exit 0 and session revocation. docs/evidence/2026-09-15-openbao-public-listener-retract.json records successful operator loopback MFA, private HTTP 200, gateway readiness and public Ingress retraction. RPF-WP-0025 closure on September 22 records the handoff to Railiance Master. These receipts discharge the original role and login gates.

Today the gateway and OpenBao are ready, their Services are ClusterIP, and the openbao namespace has no Ingress. The September 24 callback-prune receipt retired the public callbacks; current NetKingdom client source also forbids their return. T01's bounded rollback requirement is historical, not an instruction to restore public callbacks. DNS withdrawal remains the railiance-infra owner residual described by RPF-WP-0025; this review does not claim it is complete or authorize a listener change.

Evidence and cross-plan priorities: estate review.