Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0290b-3241-74c3-b868-6049545af836
61 lines
2.8 KiB
Markdown
61 lines
2.8 KiB
Markdown
# OpenBao platform-admin login
|
|
|
|
## Worker checklist
|
|
|
|
Use this lane only for an attended OpenBao control-plane operation whose
|
|
reviewed procedure requires `platform-admin`, such as configuring a database
|
|
secrets-engine connection, policies, auth roles, or token roles. It is not a
|
|
workload KV-read lane and it does not provision a secret value.
|
|
|
|
1. Plan the exact administration need before drafting any operator step:
|
|
|
|
```bash
|
|
warden plan "attended OpenBao platform administration for <reviewed operation>" --json
|
|
```
|
|
|
|
The result must select `openbao-platform-admin-login`, return
|
|
`founder_required`, and name one `oidc_login` act. If it selects
|
|
`openbao-api-key`, a workload role, paste-once provisioning, or root, stop and
|
|
report a routing defect.
|
|
|
|
2. The operator performs the identity act and the separately reviewed owner
|
|
command through one contained envelope:
|
|
|
|
```bash
|
|
warden access openbao-platform-admin-login --exec -- <reviewed-owner-command>
|
|
```
|
|
|
|
Warden refuses a login-only `--fetch`. Before OIDC it proves the caller's
|
|
default home is usable, creates a caller-owned `0700` isolated home and a
|
|
`0600` token helper, and then runs `bao login -no-print` with both stdout and
|
|
stderr captured. The reviewed command runs in the same contained home with
|
|
both streams captured; it must persist any permitted metadata evidence itself
|
|
and remain silent. Warden self-revokes the session and removes the helper on
|
|
every success or failure path.
|
|
|
|
Safety does not rely on `-no-print`. Any client or child output, helper
|
|
persistence defect, non-zero exit, or revocation/cleanup defect fails closed.
|
|
Captured bytes are never returned, logged, excerpted, hashed, or fingerprinted.
|
|
Do not paste a token into chat, State Hub, a shell argument, or a handoff file.
|
|
Root is offline break-glass authority, not a fallback for failure.
|
|
|
|
3. Verify authority using metadata or capabilities only, never by reading a
|
|
secret value. Then run only the separately reviewed owner procedure. For the
|
|
database engine this procedure lives in `rapp-postgres`; the login does not
|
|
itself approve configuration changes.
|
|
|
|
4. Confirm the contained command exits successfully. Warden performs and checks
|
|
`bao token revoke -self` inside the contained environment before cleanup; do
|
|
not retain or reuse the helper.
|
|
|
|
If browser login fails before authentication, confirm the `netkingdom` auth
|
|
mount, `platform-admin` role, and allowed callback with `railiance-platform` and
|
|
`key-cape`. Do not retry with a workload-specific OIDC role: it is intentionally
|
|
incapable of OpenBao control-plane administration.
|
|
|
|
## Authority
|
|
|
|
- OpenBao policy and role owner: `railiance-platform/docs/openbao.md`
|
|
- Human identity and MFA provider: key-cape / Keycloak
|
|
- Database-engine procedure owner: `rapp-postgres`
|
|
- Routing decision and founder-act surface: WARDEN-WP-0029
|