feat: adopt security zones and explicit workload refs
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
parent
12c637cbf2
commit
7ce58ae638
52 changed files with 1547 additions and 658 deletions
|
|
@ -26,6 +26,11 @@
|
|||
# canon_ref upstream net-kingdom doc the wiki section tracks
|
||||
# reviewed date this pointer was last checked against canon (YYYY-MM-DD)
|
||||
# status active (surfaced by default) | draft (hidden unless --all)
|
||||
# workload_ref explicit workload applicability and authoritative join.
|
||||
# Managed deployables use rapp_id + name (+ optional deployable);
|
||||
# operational workloads use name + declaration_ref; unresolved
|
||||
# applicable lanes carry unknown_reason; native non-workload
|
||||
# subjects carry not-applicable + reason. Never infer from paths.
|
||||
# steps ONLY when warden_executes: true
|
||||
# cert_command ONLY when warden_executes: true
|
||||
# delegation WP-0030 register. mode: native | interim | permanent.
|
||||
|
|
@ -39,6 +44,9 @@ entries:
|
|||
title: Short-lived SSH certificate for host / ops reachability
|
||||
# Emits a signed certificate — a public artifact. The private key never leaves the caller (WARDEN-WP-0032-T05).
|
||||
risk: standard
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Generic certificate-signing lane; each actor resource must resolve its own target workload."
|
||||
need_keywords: [ssh, certificate, cert, host, access, sign, adm, agt, atm, reachability, ops]
|
||||
owner_repo: ops-warden
|
||||
subsystem: ops-warden
|
||||
|
|
@ -61,6 +69,10 @@ entries:
|
|||
title: Scoped OpenBao token for ops-warden SSH signing (warden-sign)
|
||||
# A scoped VAULT_TOKEN is a credential in its own right. Graded on what the value is, not on whether ops-warden currently proxies it (WARDEN-WP-0032-T05).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
name: ops-warden
|
||||
declaration_ref: tenancy.yaml
|
||||
need_keywords: [vault_token, vault, token, warden-sign, warden, ops-warden, signing, sign, smoke, flex-auth, credential, broker, lease, openbao, ssh, production]
|
||||
owner_repo: railiance-platform
|
||||
subsystem: OpenBao credential broker
|
||||
|
|
@ -97,6 +109,9 @@ entries:
|
|||
title: API key, DB credential, or dynamic lease
|
||||
# Wildcard lane over platform/workloads/<domain>/<workload>/<bundle>: its ceiling is the most dangerous bundle it can resolve to (WARDEN-WP-0032-T05).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Generic credential-path pattern; concrete lanes carry the workload reference."
|
||||
need_keywords: [api, key, secret, database, db, password, token, lease, openbao, vault, kv, dynamic, credential, npm, npm_auth_token, registry]
|
||||
owner_repo: railiance-platform
|
||||
subsystem: OpenBao
|
||||
|
|
@ -133,6 +148,9 @@ entries:
|
|||
title: whynot-design npm publish token (@whynot/design → coulomb Gitea registry)
|
||||
# Publish rights to the package registry — a leaked token is a supply-chain write, not a read (WARDEN-WP-0032-T05).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "whynot-design has not published an authoritative workload identity declaration."
|
||||
need_keywords: [whynot-design, whynot, npm, publish, npm_auth_token, gitea, registry, coulomb, package]
|
||||
owner_repo: railiance-platform
|
||||
subsystem: OpenBao
|
||||
|
|
@ -177,6 +195,9 @@ entries:
|
|||
title: Authorization decision — may this actor perform this action
|
||||
# Returns an authorization decision; no credential flows (WARDEN-WP-0032-T05).
|
||||
risk: standard
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Generic authorization action; the governed resource supplies workload identity."
|
||||
need_keywords: [authorization, policy, permission, allow, deny, may, flex-auth, topaz, pdp, decision]
|
||||
owner_repo: flex-auth
|
||||
subsystem: flex-auth
|
||||
|
|
@ -195,6 +216,9 @@ entries:
|
|||
title: Interactive login, OIDC token, or MFA
|
||||
# Interactive browser OIDC: a login flow, not a KV read. No stored value is fetched, and warden access already excludes is_login from raw-value streaming (WARDEN-WP-0032-T05).
|
||||
risk: standard
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Interactive login action; caller identity is native context, not a workload target."
|
||||
need_keywords: [login, oidc, identity, mfa, token, jwt, sso, keycloak, key-cape, iam, claims, authenticate, signin]
|
||||
owner_repo: key-cape
|
||||
subsystem: key-cape / Keycloak
|
||||
|
|
@ -222,6 +246,9 @@ entries:
|
|||
title: SSH tunnel or port forward
|
||||
# Routes to ops-bridge and supplies a cert_command; no secret value flows (WARDEN-WP-0032-T05).
|
||||
risk: standard
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "ops-bridge has not published the operational tunnel workload declaration."
|
||||
need_keywords: [tunnel, port, forward, bridge, ops-bridge, reverse, transport, ssh-tunnel, cert_command]
|
||||
owner_repo: ops-bridge
|
||||
subsystem: ops-bridge
|
||||
|
|
@ -240,6 +267,9 @@ entries:
|
|||
title: Host SSH principal file or force-command deployment
|
||||
# Principal-file deployment via Ansible; no secret value flows (WARDEN-WP-0032-T05).
|
||||
risk: standard
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Host principal-file deployment is an infrastructure action, not a workload."
|
||||
need_keywords: [principal, auth_principals, force-command, host, sshd, hardening, railiance-infra, ansible]
|
||||
owner_repo: railiance-infra
|
||||
subsystem: railiance-infra
|
||||
|
|
@ -258,6 +288,9 @@ entries:
|
|||
title: Inter-Hub bootstrap SSH envelope
|
||||
# Graded high conservatively: ops-warden could not establish from the lane definition that no key material moves in the envelope. Regrade with evidence, do not assume down (WARDEN-WP-0032-T05).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "The inter-hub bootstrap execution unit has no authoritative workload declaration."
|
||||
need_keywords: [inter-hub, interhub, bootstrap, ops-hub, agt-interhub-bootstrap, envelope, force-command, CUST-WP-0049]
|
||||
owner_repo: ops-warden
|
||||
subsystem: ops-warden + railiance-infra
|
||||
|
|
@ -276,6 +309,9 @@ entries:
|
|||
title: activity-core IssueSink → issue-core REST emission
|
||||
# Emission routing only — the API key is a separate lane (WARDEN-WP-0032-T05).
|
||||
risk: standard
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "activity-core has not published an authoritative workload identity declaration."
|
||||
need_keywords: [activity-core, issue-sink, issue-core, emission, issue_core_url, issue_core_api_key, tasks, ingest, rest, issuesink]
|
||||
owner_repo: activity-core
|
||||
subsystem: activity-core + issue-core
|
||||
|
|
@ -301,6 +337,11 @@ entries:
|
|||
# A Forgejo backend token is not recovered by rotating an ingestion key.
|
||||
# Found by secrets-engine reviewing SECRETS-WP-0006 -- not by us.
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
rapp_id: rapp-issue-core
|
||||
name: issue-core
|
||||
deployable: issue-core
|
||||
fields: [ISSUE_CORE_API_KEY, GITEA_BACKEND_TOKEN] # CCR-2026-0002
|
||||
need_keywords: [issue-core, ingestion, api, key, openbao, issue_core_api_key, eso, external-secrets]
|
||||
owner_repo: railiance-platform
|
||||
|
|
@ -349,6 +390,9 @@ entries:
|
|||
# rotation. Disclosure lets an attacker forge webhook deliveries into the
|
||||
# federation hub, which rotating the write token alone does not undo.
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "reuse-surface has not published an authoritative workload identity declaration."
|
||||
fields: [REUSE_SURFACE_TOKEN, REUSE_SURFACE_FORGEJO_WEBHOOK_SECRET] # CCR-2026-0005
|
||||
need_keywords: [reuse-surface, reuse_surface, hub, register, federation, write, token, bearer, REUSE_SURFACE_TOKEN, REUSE_SURFACE_FORGEJO_WEBHOOK_SECRET, reuse.coulomb.social]
|
||||
owner_repo: railiance-platform
|
||||
|
|
@ -404,6 +448,9 @@ entries:
|
|||
verified: owner-confirmed
|
||||
# High-risk: provider API key with spend impact + prompt-adjacent (WP-0026 T04).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "llm-connect has not published an authoritative workload identity declaration."
|
||||
# Concrete, owner-confirmed lane — railiance-platform CCR-2026-0003 / RAILIANCE-WP-0010
|
||||
# (promoted 2026-07-02): policy workload-kv-read-llm-connect-provider-secrets and k8s
|
||||
# auth role external-secrets-activity-core applied; ExternalSecret
|
||||
|
|
@ -445,6 +492,9 @@ entries:
|
|||
verified: unverified
|
||||
# High-risk: WebDAV upload token + AGE recovery escrow (WP-0026 T04).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "The backup execution unit has no authoritative workload identity declaration."
|
||||
# CCR-2026-0004: policy + OIDC role applied; values provisioned 2026-07-07.
|
||||
# Capabilities-safe re-verify 2026-07-16 (WP-0026 T07): lane-policy token
|
||||
# capabilities=read on data path; default-policy and agent-high-risk-boundary = deny;
|
||||
|
|
@ -491,6 +541,9 @@ entries:
|
|||
verified: owner-confirmed
|
||||
# High-risk: site-admin PAT (WP-0026 T04).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "The Forgejo administration workload has no authoritative workload identity declaration."
|
||||
# CCR-2026-0006: approved by platform-operator 2026-07-12; policy
|
||||
# workload-kv-read-forgejo-admin + OIDC role forgejo-admin-workload-kv-read live on
|
||||
# bao.coulomb.social; PAT attended-minted and stored under field API_TOKEN at
|
||||
|
|
@ -533,6 +586,9 @@ entries:
|
|||
reviewed: "2026-08-11"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "The Binky email consumer has no authoritative workload identity declaration."
|
||||
# CCR-2026-0007: tenants/ mount + policy + OIDC role applied; founder provisioned
|
||||
# values via UI (version ≥2, not placeholder). Capabilities-safe verify 2026-07-17:
|
||||
# lane-policy read; default deny. Host: imap.ionos.de:993 (binky-control config).
|
||||
|
|
@ -568,6 +624,9 @@ entries:
|
|||
reviewed: "2026-08-11"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "The Binky Qonto MCP consumer has no authoritative workload identity declaration."
|
||||
# CCR-2026-0008: policy + OIDC role applied; secret at tenants/binky/qonto-api
|
||||
# (fields API_KEY, API_USER). Map to QONTO_API_KEY / QONTO_ORGANIZATION_ID for
|
||||
# qonto-mcp-server. First read-only pull 2026-07-21 (BINKY-WP-0005-T05).
|
||||
|
|
@ -604,6 +663,11 @@ entries:
|
|||
reviewed: "2026-08-17"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
rapp_id: rapp-qonto
|
||||
name: qonto
|
||||
deployable: rapp-qonto
|
||||
auth_method: "OpenBao platform workload lane; KeyCape client_secret_basic exchange"
|
||||
path_template: "platform/workloads/rapp-qonto/keycape-client"
|
||||
fetch_command: "bao kv get -field=client_secret platform/workloads/rapp-qonto/keycape-client"
|
||||
|
|
@ -635,6 +699,9 @@ entries:
|
|||
reviewed: "2026-08-11"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "agent-harness has not published an authoritative workload identity declaration."
|
||||
# Provisioned 2026-07-17 on railiance01: ed25519 keypair on host, OpenBao copy at
|
||||
# platform/workloads/agent-harness/forgejo-deploy-key, write deploy key on
|
||||
# coulomb/executor-sandbox (title agent-harness-railiance01). Git push verified.
|
||||
|
|
@ -671,6 +738,9 @@ entries:
|
|||
reviewed: "2026-08-15"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "agent-harness has not published an authoritative workload identity declaration."
|
||||
# Provisioned 2026-07-17: role agent-harness-binky-mail bound to existing policy
|
||||
# workload-kv-read-binky-company-email-imap; role_id/secret_id delivered to
|
||||
# railiance01 ~/.local/agent-harness/approle-binky-mail (0600). Positive IMAP field
|
||||
|
|
@ -696,6 +766,9 @@ entries:
|
|||
title: Object-storage STS / temporary S3 credentials
|
||||
# Temporary S3 credentials are still credentials (WARDEN-WP-0032-T05).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Generic STS credential-vending pattern; concrete consumers carry workload references."
|
||||
need_keywords: [s3, sts, object-storage, minio, artifact-store, temporary, credentials, bucket, vending]
|
||||
owner_repo: net-kingdom
|
||||
subsystem: flex-auth + OpenBao + artifact-store
|
||||
|
|
@ -726,6 +799,9 @@ entries:
|
|||
reviewed: "2026-08-15"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Generic database credential-vending pattern; concrete consumers carry workload references."
|
||||
exec_capable: false
|
||||
|
||||
- id: rein-openweights-openrouter-approle
|
||||
|
|
@ -745,6 +821,9 @@ entries:
|
|||
reviewed: "2026-08-15"
|
||||
verified: unverified
|
||||
risk: standard
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "rein-openweights has not published an authoritative workload identity declaration."
|
||||
# Built 2026-07-27 by ops-mason (MASON-WP-0001-T05), approved by Bernd
|
||||
# Worsch 2026-07-27. Policy + AppRole live; reins/ KV v2 mount created
|
||||
# (no existing mount fit without widening scope beyond what was
|
||||
|
|
@ -805,6 +884,9 @@ entries:
|
|||
# railiance-apps; user-engine is consumer-only and claims no lane here.
|
||||
consumers: [user-engine]
|
||||
risk: standard
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "coulomb-social has not published an authoritative workload identity declaration."
|
||||
# K8s assembly is the live handoff today (same pattern as vergage-teilnahme-env).
|
||||
# OpenBao KV platform/workloads/coulomb/coulomb-social/runtime-env is the
|
||||
# future custody home — CCR not yet applied; resolvable via operator script.
|
||||
|
|
@ -827,6 +909,9 @@ entries:
|
|||
title: audit-core sender registry (write and operator-read tokens)
|
||||
# Vends write and operator-read tokens (WARDEN-WP-0032-T05).
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "audit-core has not published an authoritative workload identity declaration."
|
||||
need_keywords: [audit-core, senders, sender registry, ingest token, AUDIT_CORE_SENDERS]
|
||||
owner_repo: ops-mason
|
||||
subsystem: OpenBao + audit-core
|
||||
|
|
@ -864,6 +949,9 @@ entries:
|
|||
reviewed: "2026-08-21"
|
||||
verified: owner-confirmed
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "email-connect has not published an authoritative workload identity declaration."
|
||||
# CCR-2026-0010 approved 2026-08-12; applied same day (EMAIL-WP-0004-T03):
|
||||
# policies external-secrets-email-connect + workload-kv-read-email-connect-transactional,
|
||||
# KV platform/workloads/email-connect/transactional v1, ESO token Secret,
|
||||
|
|
@ -906,6 +994,9 @@ entries:
|
|||
reviewed: "2026-08-15"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: applicable
|
||||
unknown_reason: "The attended Scaleway bootstrap execution unit has no authoritative workload identity declaration."
|
||||
# CCR-2026-0011. Values via founder paste-once or local tfvars ingest.
|
||||
# Not the Barman runtime key (platform-pg-backup-s3).
|
||||
auth_method: "caller's own OpenBao token (founder / operator workstation)"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue