80 lines
3.2 KiB
Markdown
80 lines
3.2 KiB
Markdown
|
|
---
|
||
|
|
id: ops-warden-adr-0005
|
||
|
|
type: adr
|
||
|
|
title: "ADR-0005 — Implement one lane narrowly, route everything else"
|
||
|
|
domain: infotech
|
||
|
|
repo: ops-warden
|
||
|
|
status: accepted
|
||
|
|
version: "1.0"
|
||
|
|
revision: "1"
|
||
|
|
owner: ops-warden
|
||
|
|
binds: "ops-warden"
|
||
|
|
created: "2026-06-18"
|
||
|
|
updated: "2026-08-18"
|
||
|
|
last_reviewed: "2026-08-18"
|
||
|
|
review_interval: 6m
|
||
|
|
enforced_by: "SCOPE.md; registry/routing/catalog.yaml warden_executes"
|
||
|
|
supersedes: ""
|
||
|
|
successor: ""
|
||
|
|
---
|
||
|
|
|
||
|
|
# ADR-0005 — Implement one lane narrowly, route everything else
|
||
|
|
|
||
|
|
## Status
|
||
|
|
|
||
|
|
Accepted. The founding charter decision, taken 2026-06-18
|
||
|
|
(`history/2026-06-18-access-routing-intent-shift-assessment.md`).
|
||
|
|
|
||
|
|
## Context
|
||
|
|
|
||
|
|
ops-warden began as an SSH certificate manager. It then became the place workers
|
||
|
|
asked when they did not know where a credential came from — which is a real need,
|
||
|
|
and the obvious way to serve it is to start fetching credentials.
|
||
|
|
|
||
|
|
Down that path is a component that issues SSH certificates, vends API keys, brokers
|
||
|
|
tokens, and holds authority over all of them: a single point whose compromise is
|
||
|
|
total. NetKingdom's architecture deliberately separates identity (key-cape),
|
||
|
|
authorization (flex-auth), and secrets (OpenBao). A helpful front door that absorbed
|
||
|
|
all three would quietly undo that separation, one convenience at a time.
|
||
|
|
|
||
|
|
## Decision
|
||
|
|
|
||
|
|
**ops-warden executes exactly one lane with its own authority: SSH certificate
|
||
|
|
issuance for `adm`/`agt`/`atm` actors.** `warden_executes: true` appears on one
|
||
|
|
catalog entry and is expected to stay that way.
|
||
|
|
|
||
|
|
**For every other need it routes, and where the lane is `exec_capable` it may assist
|
||
|
|
by proxying as the caller** under `ADR-0002`. Routing is not a lesser service — it is
|
||
|
|
the service. Knowing which subsystem owns a need, and being right about it, is what
|
||
|
|
this repo sells.
|
||
|
|
|
||
|
|
**Scope growth is tested by ownership, not by usefulness.** "Would this be handy in
|
||
|
|
ops-warden?" is the wrong question and almost always answers yes. The right question
|
||
|
|
is "does ops-warden have the authority to own this, permanently?" If the answer is no,
|
||
|
|
the correct outcome is a pointer, or an `interim` cover recorded under `ADR-0003`.
|
||
|
|
|
||
|
|
## Consequences
|
||
|
|
|
||
|
|
**The blast radius stays bounded and known.** Compromising ops-warden yields the SSH
|
||
|
|
signing lane. That is worth defending well precisely because it is the only thing here.
|
||
|
|
|
||
|
|
**We say no to requests that would be easy to say yes to.** `warden secret`,
|
||
|
|
`warden login`, `warden bao`, `warden tunnel` do not exist and must not be invented;
|
||
|
|
the agent instructions name them as anti-patterns because agents keep reaching for
|
||
|
|
them. Each would be a day's work and a permanent widening.
|
||
|
|
|
||
|
|
**Being useful therefore depends on the pointers being right**, which is the whole
|
||
|
|
weight behind `ADR-0001`'s anchor enforcement and the catalog's review dates. A router
|
||
|
|
that routes wrongly is worse than no router.
|
||
|
|
|
||
|
|
**It leaves real gaps visible rather than filled.** Six workload lanes and three
|
||
|
|
tenant lanes are covered interim because secrets-engine and tenant-engine have not
|
||
|
|
shipped front doors. Under this ADR that is the correct state, tracked under
|
||
|
|
`ADR-0003`, and not a signal that ops-warden should absorb them.
|
||
|
|
|
||
|
|
## Related
|
||
|
|
|
||
|
|
- `SCOPE.md` — the issue-vs-route table
|
||
|
|
- `wiki/AccessRouting.md` — role and boundary
|
||
|
|
- `ADR-0001`, `ADR-0002`, `ADR-0003` — the three rules that follow from this one
|