# OpenBao platform-admin login ## Worker checklist Use this lane only for an attended OpenBao control-plane operation whose reviewed procedure requires `platform-admin`, such as configuring a database secrets-engine connection, policies, auth roles, or token roles. It is not a workload KV-read lane and it does not provision a secret value. 1. Plan the exact administration need before drafting any operator step: ```bash warden plan "attended OpenBao platform administration for " --json ``` The result must select `openbao-platform-admin-login`, return `founder_required`, and name one `oidc_login` act. If it selects `openbao-api-key`, a workload role, paste-once provisioning, or root, stop and report a routing defect. 2. The operator performs the one identity act through KeyCape OIDC/MFA: ```bash bao login -no-print -method=oidc -path=netkingdom role=platform-admin ``` `-no-print` is mandatory. Do not paste a token into chat, State Hub, a shell argument, or a temporary handoff file. Root is offline break-glass authority, not a fallback for an OIDC or callback failure. 3. Verify authority using metadata or capabilities only, never by reading a secret value. Then run only the separately reviewed owner procedure. For the database engine this procedure lives in `rapp-postgres`; the login does not itself approve configuration changes. 4. Revoke the attended token when the reviewed operation and its non-secret verification are complete: ```bash bao token revoke -self ``` If browser login fails before authentication, confirm the `netkingdom` auth mount, `platform-admin` role, and allowed callback with `railiance-platform` and `key-cape`. Do not retry with a workload-specific OIDC role: it is intentionally incapable of OpenBao control-plane administration. ## Authority - OpenBao policy and role owner: `railiance-platform/docs/openbao.md` - Human identity and MFA provider: key-cape / Keycloak - Database-engine procedure owner: `rapp-postgres` - Routing decision and founder-act surface: WARDEN-WP-0029