From a9086ad6b6f426bd97abe52c2efdddceb6256c49 Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 10 Aug 2026 19:37:05 +0200 Subject: [PATCH] Route dynamic database credentials to rapp-postgres --- registry/routing/catalog.yaml | 12 +- .../playbooks/database-dynamic-credentials.md | 109 ++---------------- 2 files changed, 19 insertions(+), 102 deletions(-) diff --git a/registry/routing/catalog.yaml b/registry/routing/catalog.yaml index 0c2570c..2fa0dae 100644 --- a/registry/routing/catalog.yaml +++ b/registry/routing/catalog.yaml @@ -552,13 +552,15 @@ entries: - id: database-dynamic-credentials title: Database dynamic credentials (OpenBao secrets engine) need_keywords: [database, db, postgres, cnpg, dynamic, credentials, password, lease, openbao] - owner_repo: railiance-platform - subsystem: OpenBao + owner_repo: rapp-postgres + subsystem: rapp-postgres + railiance-platform OpenBao broker warden_executes: false wiki_ref: wiki/playbooks/database-dynamic-credentials.md#worker-checklist - canon_ref: net-kingdom/docs/platform-identity-security-architecture.md - reviewed: "2026-06-24" - status: draft + canon_ref: rapp-postgres/docs/canon-drafts/shared-platform-relational-storage_v0.1-draft.md + reviewed: "2026-08-10" + status: active + risk: high + exec_capable: false - id: rein-openweights-openrouter-approle title: rein-openweights AppRole for non-interactive OpenRouter key read diff --git a/wiki/playbooks/database-dynamic-credentials.md b/wiki/playbooks/database-dynamic-credentials.md index c4bf019..11b4eac 100644 --- a/wiki/playbooks/database-dynamic-credentials.md +++ b/wiki/playbooks/database-dynamic-credentials.md @@ -1,102 +1,17 @@ -# Database Dynamic Credentials — OpenBao - -Date: 2026-06-24 -Workplan: WARDEN-WP-0012 T4 -Catalog: `database-dynamic-credentials` (draft until engine ships) - -Pointer playbook for short-lived database passwords issued by OpenBao dynamic -secret engines (e.g. CNPG-managed PostgreSQL). ops-warden does not issue DB -credentials — custody and engine configuration belong to `railiance-platform`; -consumers request credentials through approved paths after flex-auth policy where -required. - ---- - -## Owners - -| Concern | Owner repo | Authoritative doc | -| --- | --- | --- | -| OpenBao database engine, paths, policies | `railiance-platform` | `docs/openbao.md`, `workplans/RAIL-PL-WP-0002-openbao-platform-secrets-service.md` | -| Authorization before sensitive reads | `flex-auth` | `INTENT.md` | -| Application connection and lease handling | Owning app repo | App-specific deployment docs | - ---- - -## Do not ask ops-warden - -```bash -warden route show openbao-api-key --json -warden route show database-dynamic-credentials --json # after promotion -``` - -Never paste DB passwords, connection strings with credentials, or root DB admin -tokens in Git, State Hub, logs, or agent chat. - ---- - -## Platform path convention - -From `railiance-platform/docs/openbao.md`: - -```text -platform/databases/ -``` - -Dynamic credentials are issued via OpenBao database secrets engine roles — not -static KV copies. Coordinate the exact mount and role name with platform before -wiring workloads. - -**Promotion gate:** catalog entry stays `status: draft` until the database -secrets engine and consumer role exist in the live cluster. - ---- +# Database dynamic credentials ## Worker checklist -### 1. Confirm need type +This file is a pointer only. ops-warden does not issue database credentials and +does not duplicate the operating procedure. -- [ ] Short-lived DB password (dynamic) vs long-lived KV secret — prefer dynamic -- [ ] Target database identified (CNPG cluster, service name, database name) -- [ ] flex-auth policy requires approval for this read (if tenant policy says so) +- Package and authoritative procedure: + `rapp-postgres/wiki/playbooks/database-dynamic-credentials.md#worker-checklist` +- Consumer/isolation decision: + `rapp-postgres/docs/adr/ADR-0001-consumer-boundary-and-tenant-isolation.md` +- Credential engine and grant catalog owner: `railiance-platform` +- Canon draft: + `rapp-postgres/docs/canon-drafts/shared-platform-relational-storage_v0.1-draft.md` -### 2. Platform provisioning (operator) - -- [ ] Database secrets engine configured with least-privilege creation statements -- [ ] Role TTL aligned to workload session (minutes–hours, not days) -- [ ] Path registered under `platform/databases/` -- [ ] Audit logging enabled on secret access - -### 3. Workload consumption - -- [ ] App uses ESO or CSI to materialize username/password into K8s Secret -- [ ] Connection pool handles credential rotation before lease expiry -- [ ] No hard-coded passwords in Helm values or ConfigMaps - -### 4. Verify - -- [ ] App connects with issued credentials -- [ ] Lease renewal or re-read succeeds before expiry -- [ ] Revocation on pod teardown (if policy requires) - -### 5. Rotation / revocation - -- [ ] OpenBao revokes lease on role change -- [ ] Platform operator documents break-glass DB admin path separately (not via warden) - ---- - -## Owner-repo next actions - -| Repo | Action | -| --- | --- | -| `railiance-platform` | Configure database secrets engine, roles, and policies | -| Owning application | Wire ESO/CSI and connection handling for lease TTL | -| `flex-auth` | Policy for database credential requests (if gated) | - ---- - -## See also - -- `railiance-platform/docs/openbao.md` -- `railiance-platform/workplans/RAIL-PL-WP-0002-openbao-platform-secrets-service.md` -- `wiki/CredentialRouting.md#routing-table` \ No newline at end of file +Never place a database password, credential-bearing DSN, lease value, or +bootstrap token in Git, State Hub, logs, or chat.