net-kingdom/docs/tutorials/openbao-operating-path.md
tegwick 0d460e3c02
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Activate NK-WP-0009/0011; add tutorials slice and proposed ADR-0009
- docs/tutorials: template, OpenBao and SSH tutorials (unexercised)
- tools/tutorial-verify + make tutorials-verify (NK-WP-0009-T06)
- ADR-0009 proposed: expanded-mode Keycloak trigger and topology

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 295952@bnt-lap001
Assistant-Session: e93f64ad-516c-46eb-9666-aad8d300c477
2026-09-28 23:31:48 +02:00

3.1 KiB

OpenBao: consume, attend, recover

Exercise status: unexercised Workplan task: NK-WP-0009-T03 Pattern(s): platform-root custody (docs/platform-root-custody.md); credential routing

Outcome

You can reach the already-deployed private OpenBao, read a secret you are entitled to, know which unseal custody model governs it, and follow the attended recovery path without exposing shares or tokens.

Prerequisites

  • [owner: ops-bridge] bridge CLI and the named openbao-ui-railiance01 tunnel; an SSH certificate (see the SSH tutorial).
  • [owner: ops-warden] warden CLI for credential routing.
  • [owner: railiance-platform] OpenBao is already deployed and private. Greenfield deployment is a lab exercise only, never against the live estate.

Architecture context

OpenBao is the runtime secret authority. railiance-platform deploys and operates it; net-kingdom owns the custody canon and the guarded bootstrap console, which refuses live bao operator init. Three unseal custody models exist (docs/openbao-unseal-custody-models.md); production blocks the sops-held-automation lab model.

Steps

  1. [owner: ops-warden] Find the owner of your need: warden route find "read a database password" --json.
  2. [owner: ops-bridge] Check and, if needed, restore the tunnel: bridge status, then bridge up openbao-ui-railiance01.
  3. [owner: railiance-platform] Authenticate with your own identity and read only the path the routing result names. Use the owner's railiance-platform/docs/openbao.md for exact commands.
  4. [owner: net-kingdom] Know your custody model: python3 tools/security-bootstrap-console/security_bootstrap_console.py openbao-unseal-custody-models.
  5. [owner: net-kingdom + railiance-platform] Recovery after a seal event follows docs/openbao-attended-ceremony-runbook.md: operator and witness present, shares escrowed out of band, root token revoked after handoff. Record the ceremony in a non-secret record and run make security-bootstrap-validate-openbao-ceremony-record.

Verification

Done when:

  • bridge status shows openbao-ui-railiance01 up.
  • make security-bootstrap-console reports no unmet custody gate for the selected model.
  • make security-bootstrap-validate-openbao-ceremony-record passes on a ceremony record, and fails on one containing a token-shaped marker.

Rollback

  • Close the tunnel: bridge down openbao-ui-railiance01.
  • Read-only steps need no rollback. A ceremony cannot be undone; a mistaken share transcription is corrected by re-escrow per the custody roster.

Threat checks

  • Init output, shares and tokens go to the operator's screen only: never to chat, State Hub, logs, or a Git checkout.
  • Never use a public Bao URL; bao.coulomb.social is retired.
  • Never place root token and unseal shares in one artifact outside lab.

Ownership notes

Concern Owner
OpenBao deployment, config, unseal execution railiance-platform
Custody canon, ceremony record validator net-kingdom
Tunnel ops-bridge
Credential routing ops-warden