Draft the flex-auth envelope-signing credential route.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Pointer-only, warden_executes false. Shape lives in flex-auth;
OpenBao path is not built yet. Testdata keys are not this lane.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
This commit is contained in:
tegwick 2026-09-14 09:59:11 +02:00
parent 427105519b
commit 8a40dcb11b
3 changed files with 63 additions and 4 deletions

View file

@ -10,18 +10,19 @@
# declares it, and is null where the field set has not been established --
# null means unknown, never 'one field'.
generated_at: "2026-09-14T02:57:04Z"
generated_at: "2026-09-14T07:58:30Z"
source: ops-warden/registry/routing/catalog.yaml
catalog_revision: "73e40af6ca27ca547eb42782d2ceb1a5cc8c3534"
catalog_revision_date: "2026-09-14T02:47:32+02:00"
catalog_revision: "4ebd241d88e0f65125b3097a6d3aeccd4c294eb6"
catalog_revision_date: "2026-09-14T04:57:55+02:00"
catalog_dirty: true
high_risk_lane_count: 27
high_risk_lane_count: 28
concrete_path_count: 15
# Graded high but not a single KV address -- a routing pattern, a broker
# grant, or a non-KV lane. Nothing here for a policy to deny.
no_concrete_path:
- database-dynamic-credentials
- flex-auth-decision-envelope-signing-key
- inter-hub-bootstrap-ssh
- net-kingdom-lldap-bind-credential
- net-kingdom-privacyidea-admin-token

View file

@ -684,6 +684,29 @@ entries:
- "Verify capabilities-safe on the data path (`bao token capabilities`); run a restore drill against a re-encrypted artifact."
- "After rotation, clear EXPOSED taint: remove custom_metadata exposed_at/exposed_version (see `warden taint railiance-backup-offsite-lane`)."
- id: flex-auth-decision-envelope-signing-key
title: Ed25519 key that signs flex-auth decision envelopes
risk: high
workload_ref:
applicability: applicable
unknown_reason: "flex-auth has not published an authoritative workload identity declaration for envelope signing."
need_keywords: [flex-auth, decision, envelope, signing, signature, ed25519, responder, authenticity, FLEX-WP-0024]
owner_repo: railiance-platform
subsystem: OpenBao + flex-auth
warden_executes: false
wiki_ref: wiki/playbooks/flex-auth-decision-envelope-signing-key.md#worker-checklist
canon_ref: flex-auth/docs/decision-envelope-signature.md
reviewed: "2026-09-14"
status: draft
delegation:
mode: interim
intended_owner: railiance-platform
blocked_on: "Shape is chosen in flex-auth (FLEX-WP-0024-T02). OpenBao KV path, Kubernetes auth role, and paste_once_provision of the private seed are not built. Testdata key in flex-auth is not this lane."
reviewed: "2026-09-14"
verified: unverified
auth_method: "Kubernetes auth from the flex-auth pin (to be bound); not a static secret in git"
path_template: "platform/workloads/flex-auth/envelope-signing (fields ED25519_PRIVATE_KEY, ED25519_PUBLIC_KEY, kid)"
- id: state-hub-forge-derivation-read
title: Forgejo read-only token for State Hub projection derivation
risk: high