- docs/tutorials: template, OpenBao and SSH tutorials (unexercised) - tools/tutorial-verify + make tutorials-verify (NK-WP-0009-T06) - ADR-0009 proposed: expanded-mode Keycloak trigger and topology Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 295952@bnt-lap001 Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
3.1 KiB
3.1 KiB
OpenBao: consume, attend, recover
Exercise status: unexercised
Workplan task: NK-WP-0009-T03
Pattern(s): platform-root custody (docs/platform-root-custody.md); credential routing
Outcome
You can reach the already-deployed private OpenBao, read a secret you are entitled to, know which unseal custody model governs it, and follow the attended recovery path without exposing shares or tokens.
Prerequisites
- [owner: ops-bridge]
bridgeCLI and the namedopenbao-ui-railiance01tunnel; an SSH certificate (see the SSH tutorial). - [owner: ops-warden]
wardenCLI for credential routing. - [owner: railiance-platform] OpenBao is already deployed and private. Greenfield deployment is a lab exercise only, never against the live estate.
Architecture context
OpenBao is the runtime secret authority. railiance-platform deploys and
operates it; net-kingdom owns the custody canon and the guarded bootstrap
console, which refuses live bao operator init. Three unseal custody models
exist (docs/openbao-unseal-custody-models.md); production blocks the
sops-held-automation lab model.
Steps
- [owner: ops-warden] Find the owner of your need:
warden route find "read a database password" --json. - [owner: ops-bridge] Check and, if needed, restore the tunnel:
bridge status, thenbridge up openbao-ui-railiance01. - [owner: railiance-platform] Authenticate with your own identity and read
only the path the routing result names. Use the owner's
railiance-platform/docs/openbao.mdfor exact commands. - [owner: net-kingdom] Know your custody model:
python3 tools/security-bootstrap-console/security_bootstrap_console.py openbao-unseal-custody-models. - [owner: net-kingdom + railiance-platform] Recovery after a seal event
follows
docs/openbao-attended-ceremony-runbook.md: operator and witness present, shares escrowed out of band, root token revoked after handoff. Record the ceremony in a non-secret record and runmake security-bootstrap-validate-openbao-ceremony-record.
Verification
Done when:
bridge statusshowsopenbao-ui-railiance01up.make security-bootstrap-consolereports no unmet custody gate for the selected model.make security-bootstrap-validate-openbao-ceremony-recordpasses on a ceremony record, and fails on one containing a token-shaped marker.
Rollback
- Close the tunnel:
bridge down openbao-ui-railiance01. - Read-only steps need no rollback. A ceremony cannot be undone; a mistaken share transcription is corrected by re-escrow per the custody roster.
Threat checks
- Init output, shares and tokens go to the operator's screen only: never to chat, State Hub, logs, or a Git checkout.
- Never use a public Bao URL;
bao.coulomb.socialis retired. - Never place root token and unseal shares in one artifact outside lab.
Ownership notes
| Concern | Owner |
|---|---|
| OpenBao deployment, config, unseal execution | railiance-platform |
| Custody canon, ceremony record validator | net-kingdom |
| Tunnel | ops-bridge |
| Credential routing | ops-warden |