fix: name the npm KV field, not the env var it becomes

secrets-engine corrected our claim (msg 15f0c0ca): `npm_token` is the KV
field on the whynot-design publish lane; `NPM_AUTH_TOKEN` is the environment
variable their publication-scope policy injects. Their doc lists the two as
separate rows and we had copied the env var in as the field name, so our
`fetch_command` named a field that does not exist -- `bao kv get
-field=NPM_AUTH_TOKEN` could only ever have failed.

This is ADR-0001's failure mode, not a typo: a pointer layer restating an
owner's procedure and getting it wrong. Corrected from the owner's statement
rather than re-derived here, and the catalog now records the distinction
inline so the env var does not get copied back in.

The path is a separate and still-open question. secrets-engine declined to
resolve it unilaterally -- which location backs the lane for reads is
railiance-platform's custody state -- so the path is unchanged and routed to
them rather than moved on a coordination message.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1276224@bnt-lap001
Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
This commit is contained in:
tegwick 2026-09-09 14:43:44 +02:00
parent 8e1b621116
commit 83fdd08f88
2 changed files with 17 additions and 7 deletions

View file

@ -241,7 +241,15 @@ entries:
# form is superseded; do not reintroduce it.
auth_method: "bao login -method=oidc -path=netkingdom role=whynot-design-workload-kv-read"
path_template: "platform/workloads/coulomb/whynot-design/npm-publish"
fetch_command: "bao kv get -field=NPM_AUTH_TOKEN platform/workloads/coulomb/whynot-design/npm-publish"
# Field corrected 2026-09-09 on the owner's statement (secrets-engine msg
# 15f0c0ca): `npm_token` is the KV FIELD; `NPM_AUTH_TOKEN` is the environment
# variable the publication-scope policy injects, and ops-warden had copied the
# env var in as the field name. That is ADR-0001's failure mode exactly — a
# pointer layer restating an owner's procedure and getting it wrong — so it is
# corrected from the owner's doc (secrets-engine docs/whynot-design-real-publish-closeout.md),
# never re-derived here. The path is a separate question, open with
# railiance-platform; do not change it on this correction.
fetch_command: "bao kv get -field=npm_token platform/workloads/coulomb/whynot-design/npm-publish"
policy_ref: "flex-auth check secret.read:whynot-design"
exec_capable: true
lane: secret
@ -257,7 +265,7 @@ entries:
automatable: false
steps:
- "In the coulomb Forgejo registry, revoke the current @whynot/design publish token and generate a new one (scope: package read/write) for the whynot-design publish identity."
- "Write it back: `bao kv put platform/workloads/coulomb/whynot-design/npm-publish NPM_AUTH_TOKEN=@file` (value from a mode-0600 file)."
- "Write it back: `bao kv put platform/workloads/coulomb/whynot-design/npm-publish npm_token=@file` (value from a mode-0600 file). The field is `npm_token`; `NPM_AUTH_TOKEN` is the injected env var, not a KV key."
- "Verify capabilities-safe, then publish a fresh version and confirm it with Forgejo-supported `npm view <package>@<version>` through the governed execution lane (value used, not printed)."
- id: policy-nexus-forgejo-source-read

View file

@ -10,7 +10,8 @@ Owner: `railiance-platform` (OpenBao) · provisioning CCR-2026-0001 (commit 8f61
> plan-authorized Forgejo admin recovery lane. Treat this dedicated lane as
> unverified for writes until its package token is rotated and re-proven.
The `NPM_AUTH_TOKEN` that publishes `@whynot/design` to the coulomb Forgejo npm registry
The npm publish token for `@whynot/design` on the coulomb Forgejo npm registry
(KV field `npm_token`; reaching the publish command as `NPM_AUTH_TOKEN`)
(`https://forgejo.coulomb.social/api/packages/coulomb/npm/`). ops-warden **does not hold
this token** — it is the access front door: `warden access` proxies the read from OpenBao
**as the caller** and never persists, caches, or logs the value.
@ -22,7 +23,8 @@ this token** — it is the access front door: `warden access` proxies the read f
| Field | Value |
| --- | --- |
| OpenBao path | `platform/workloads/coulomb/whynot-design/npm-publish` |
| Field | `NPM_AUTH_TOKEN` |
| KV field | `npm_token` |
| Injected env var | `NPM_AUTH_TOKEN` (set by the publication-scope policy; not a KV key) |
| KV mount | `platform` |
| Read policy | `workload-kv-read-whynot-design-npm-publish` |
| OIDC login | `bao login -method=oidc -path=netkingdom role=whynot-design-workload-kv-read` |
@ -59,12 +61,12 @@ this token** — it is the access front door: `warden access` proxies the read f
token fragment at `forgejo.coulomb.social`:
```bash
# --exec needs the env-var name. The zone-aware policy gate always runs first.
warden access whynot-design-npm-publish --field NPM_AUTH_TOKEN \
warden access whynot-design-npm-publish --field npm_token \
--exec -- npm view @whynot/design@<version> version \
--registry=https://forgejo.coulomb.social/api/packages/coulomb/npm/
warden access whynot-design-npm-publish --field NPM_AUTH_TOKEN \
warden access whynot-design-npm-publish --field npm_token \
--exec -- npm publish
warden access whynot-design-npm-publish --field NPM_AUTH_TOKEN --fetch
warden access whynot-design-npm-publish --field npm_token --fetch
```
On either path the value transits to you (or the child env) and never enters
ops-warden's memory, disk, or audit log.