ops-warden/wiki/playbooks/openbao-platform-admin-login.md
tegwick 0fae0904ce fix: contain attended OpenBao login output
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0290b-3241-74c3-b868-6049545af836
2026-08-23 01:31:05 +02:00

2.8 KiB

OpenBao platform-admin login

Worker checklist

Use this lane only for an attended OpenBao control-plane operation whose reviewed procedure requires platform-admin, such as configuring a database secrets-engine connection, policies, auth roles, or token roles. It is not a workload KV-read lane and it does not provision a secret value.

  1. Plan the exact administration need before drafting any operator step:

    warden plan "attended OpenBao platform administration for <reviewed operation>" --json
    

    The result must select openbao-platform-admin-login, return founder_required, and name one oidc_login act. If it selects openbao-api-key, a workload role, paste-once provisioning, or root, stop and report a routing defect.

  2. The operator performs the identity act and the separately reviewed owner command through one contained envelope:

    warden access openbao-platform-admin-login --exec -- <reviewed-owner-command>
    

    Warden refuses a login-only --fetch. Before OIDC it proves the caller's default home is usable, creates a caller-owned 0700 isolated home and a 0600 token helper, and then runs bao login -no-print with both stdout and stderr captured. The reviewed command runs in the same contained home with both streams captured; it must persist any permitted metadata evidence itself and remain silent. Warden self-revokes the session and removes the helper on every success or failure path.

    Safety does not rely on -no-print. Any client or child output, helper persistence defect, non-zero exit, or revocation/cleanup defect fails closed. Captured bytes are never returned, logged, excerpted, hashed, or fingerprinted. Do not paste a token into chat, State Hub, a shell argument, or a handoff file. Root is offline break-glass authority, not a fallback for failure.

  3. Verify authority using metadata or capabilities only, never by reading a secret value. Then run only the separately reviewed owner procedure. For the database engine this procedure lives in rapp-postgres; the login does not itself approve configuration changes.

  4. Confirm the contained command exits successfully. Warden performs and checks bao token revoke -self inside the contained environment before cleanup; do not retain or reuse the helper.

If browser login fails before authentication, confirm the netkingdom auth mount, platform-admin role, and allowed callback with railiance-platform and key-cape. Do not retry with a workload-specific OIDC role: it is intentionally incapable of OpenBao control-plane administration.

Authority

  • OpenBao policy and role owner: railiance-platform/docs/openbao.md
  • Human identity and MFA provider: key-cape / Keycloak
  • Database-engine procedure owner: rapp-postgres
  • Routing decision and founder-act surface: WARDEN-WP-0029