Operations credential management
Find a file
tegwick 3aedd8f844
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
docs: record the answers received and the questions routed
Six inbound messages attended, three of them carrying real asks.

flex-auth FLEX-DEC-2026-004 answers WARDEN-WP-0034-T05's decision-lifetime
question: a decision lifetime shorter than the certificate TTL is meaningful,
but only as authority to ISSUE, never to USE an already-issued certificate.
The question had mistaken a decision lifetime for a credential lifetime. They
declined to move the §9.7.2 revocation residue to their side; that refusal is
right and the stance map is unchanged. T05 still waits on ops-mason and
railiance-infra.

WARDEN-WP-0039-T03 routed to flex-auth: is there an admitted contract for a
delegated credential read where caller and resource owner differ? Three
outcomes named as equally acceptable, including that there should be no such
contract and the interim proxy transport is itself the defect -- which would
shorten WP-0033 rather than block it. Two easy fixes ruled out in writing:
broadening the caller binding, and relabelling resource.system as ops-warden
so the binding matches. The second would make the audit trail assert we own
credentials we deliberately do not, by editing a field instead of making an
argument.

WARDEN-WP-0037: npm path routed to railiance-platform, catalog unchanged
pending their answer. secrets-engine refused to resolve it from a
coordination message and was right; asserting our own pointer is
authoritative because it is ours would route around that. The ask names a
location only, and flags that a `bao kv get` answer would be the 2026-07-16
disclosure vector on a risk: high lane.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1276224@bnt-lap001
Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
2026-09-09 16:40:46 +02:00
.claude/rules Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:35:30 +02:00
.repo-manager chore: refresh Warden work-record indexes 2026-09-01 01:27:55 +02:00
deploy/kubernetes WARDEN-WP-0031 T04: prove ops-warden's caller identity against the live pin 2026-08-19 19:06:04 +02:00
docs feat: complete local layer model v0.7 conformance work 2026-09-05 01:19:48 +02:00
examples feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
history docs: assent to v0.8 obligation 3, and price its adoption 2026-09-09 14:42:20 +02:00
intakes chore(registrar): assign State Hub identifiers 2026-08-29 14:56:21 +02:00
interfaces/reviews docs: project remaining WP0027 owner gates 2026-08-22 23:50:46 +02:00
registry chore: refresh high-risk paths for committed catalog 2026-09-09 14:43:48 +02:00
scripts feat: assert flex-auth ceiling keys are declared, not assumed 2026-09-09 14:40:05 +02:00
src/warden Refuse explicit policy authentication and binding denials before side effects 2026-09-08 16:46:00 +02:00
systemd feat(WARDEN-WP-0021): T1+T2 — scheduled worker tick enabled (systemd --user timer) 2026-06-30 15:19:23 +02:00
tests feat: assert flex-auth ceiling keys are declared, not assumed 2026-09-09 14:40:05 +02:00
wiki fix: name the npm KV field, not the env var it becomes 2026-09-09 14:43:44 +02:00
workplans docs: record the answers received and the questions routed 2026-09-09 16:40:46 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-08 20:23:59 +02:00
.gitignore feat(WP-0011): warden route lookup CLI over the pointer catalog 2026-06-18 21:07:13 +02:00
.repo-classification.yaml Mark .repo-classification.yaml human-reviewed (CUST-WP-0050 T02) 2026-06-22 11:40:44 +02:00
AGENTS.md docs: use canonical State Hub reads with caller attribution 2026-09-05 10:24:19 +02:00
CLAUDE.md Adopt risk-nexus finding routing; record the ADR gap policy-nexus exposes 2026-08-18 13:04:50 +02:00
INTENT.md Align INTENT and SCOPE to layer model v0.7; assess gaps; open WARDEN-WP-0034 2026-08-29 14:50:55 +02:00
layer.yaml feat: complete local layer model v0.7 conformance work 2026-09-05 01:19:48 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:42:48 +02:00
Makefile fix(install): refresh Warden source when reinstalling the CLI 2026-09-08 16:58:22 +02:00
pep-stance.yaml feat: complete local layer model v0.7 conformance work 2026-09-05 01:19:48 +02:00
pyproject.toml Release v0.1.2. 2026-07-07 16:59:22 +02:00
README.md Release v0.1.2. 2026-07-07 16:59:22 +02:00
SCOPE.md Align INTENT and SCOPE to layer model v0.7; assess gaps; open WARDEN-WP-0034 2026-08-29 14:50:55 +02:00
tenancy.yaml feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
uv.lock Release v0.1.2. 2026-07-07 16:59:22 +02:00
WORK-RECORDS.md chore(records): index the policy refusal workplan and residual 2026-09-08 20:35:52 +02:00

ops-warden

SSH Certificate Authority and certificate lifecycle manager for the ops fleet. Signs short-lived certs for adm / agt / atm actors and exposes the cert_command interface consumed by ops-bridge and other tooling.

See INTENT.md for direction, SCOPE.md for current implementation, and wiki/AccessManagementDirective.md for SSH policy. ops-warden issues SSH certs and routes every other credential need to its owner — see wiki/AccessRouting.md. Latest gap analysis: history/2026-06-17-post-wp0007-reassessment.md.

Get the source (Forgejo)

Canonical repo: https://forgejo.coulomb.social/coulomb/ops-warden
Releases: https://forgejo.coulomb.social/coulomb/ops-warden/releases

HTTPS clone:

git clone https://forgejo.coulomb.social/coulomb/ops-warden.git ~/ops-warden
cd ~/ops-warden

SSH clone (recommended for push/pull; add to ~/.ssh/config if missing):

Host forgejo-remote
    HostName 92.205.62.239
    Port 30022
    User git
    IdentityFile ~/.ssh/id_gitea
    StrictHostKeyChecking accept-new
git clone forgejo-remote:coulomb/ops-warden.git ~/ops-warden
cd ~/ops-warden

Legacy Gitea remotes (gitea-remote, gitea.coulomb.social) still work during migration; new checkouts should use Forgejo.

Install

From a Forgejo checkout:

Recommended (warden + experiential memory for route/worker/agent sessions):

make install-all
make verify-memory

SSH-only install (no phase-memory):

make install

Manual equivalent:

uv sync
uv tool install . --with-editable ../phase-memory --force

Or run without installing:

uv run warden --help

phase-memory must be a sibling checkout at ../phase-memory by default, or set PHASE_MEMORY_REPO when running make. Opt out of memory at runtime with WARDEN_MEMORY=0.

Upgrade after a release

When a new tag is published on Forgejo (e.g. v0.1.2):

cd ~/ops-warden
git fetch --tags origin
git pull --ff-only
make install-all
warden route list   # sanity check the installed CLI

If warden still behaves like an older build (same version string but missing recent subcommands or fixes), clear the cached wheel and reinstall:

uv cache clean ops-warden
uv tool install . --with-editable ../phase-memory --reinstall --force

Check out a specific release:

git fetch --tags origin
git checkout v0.1.2
make install-all

Quick start (local backend)

# One-time: generate a CA key (keep mode 600, never commit)
ssh-keygen -t ed25519 -f ~/.ssh/ops-ca-user -C "Ops SSH User CA" -N ""

# Configure warden (~/.config/warden/warden.yaml) — see wiki/OpsWardenConfig.md
warden inventory add agt-example --type agt --principal agt-example
warden sign agt-example --pubkey ~/.ssh/id_ed25519.pub
warden status agt-example
warden scorecard

Production uses the vault backend against OpenBao or HashiCorp Vault (Vault-compatible SSH secrets engine API). Template: examples/warden.production.example.yaml. See wiki/OpsWardenConfig.md and wiki/OpenBaoSshEngineChecklist.md.

Routing lookup (warden route)

ops-warden issues SSH certs and routes every other credential need to its owner. The route command group is a read-only lookup over the pointer catalog (registry/routing/catalog.yaml) — it never calls another subsystem or returns secrets.

warden route list [--all] [--json]                    # scenarios (active-only unless --all)
warden route list --stale [--stale-days 90] [--all]   # past review cadence
warden route show <id> [--json]                       # owner + wiki/canon pointers; SSH adds steps
warden route find "issue an api key"                  # rank scenarios by keyword overlap

Full role and examples: wiki/AccessRouting.md.

Development

make install-all
make test
make lint
uv run pytest -m integration   # requires ssh-keygen in PATH

Key paths

Path Purpose
~/.config/warden/warden.yaml Backend and CA/Vault settings
~/.config/warden/inventory.yaml Actor → principals registry
~/.local/state/warden/ Signed certs, keys, signatures.log

Documentation

  • INTENT.md — operational access steward mission (NetKingdom-aligned)
  • wiki/CredentialRouting.md — which subsystem for each credential type
  • wiki/NetKingdomSecurityMap.md — platform security component map
  • wiki/ActorInventoryPatterns.md — standard adm/agt/atm actor patterns
  • wiki/OpsWardenConfig.md — configuration reference
  • wiki/CertCommandInterface.mdcert_command contract for callers
  • wiki/InterHubBootstrapAccessLane.md — short-lived cert envelope for bootstrap tasks

Workplans

Active and proposed work lives in workplans/. Finished plans are archived under workplans/archived/.