ops-warden/wiki/playbooks/openbao-platform-admin-login.md
tegwick 8280c0b7b7
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
fix: route OpenBao platform administration login
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0290b-3241-74c3-b868-6049545af836
2026-08-22 19:08:21 +02:00

2.1 KiB

OpenBao platform-admin login

Worker checklist

Use this lane only for an attended OpenBao control-plane operation whose reviewed procedure requires platform-admin, such as configuring a database secrets-engine connection, policies, auth roles, or token roles. It is not a workload KV-read lane and it does not provision a secret value.

  1. Plan the exact administration need before drafting any operator step:

    warden plan "attended OpenBao platform administration for <reviewed operation>" --json
    

    The result must select openbao-platform-admin-login, return founder_required, and name one oidc_login act. If it selects openbao-api-key, a workload role, paste-once provisioning, or root, stop and report a routing defect.

  2. The operator performs the one identity act through KeyCape OIDC/MFA:

    bao login -no-print -method=oidc -path=netkingdom role=platform-admin
    

    -no-print is mandatory. Do not paste a token into chat, State Hub, a shell argument, or a temporary handoff file. Root is offline break-glass authority, not a fallback for an OIDC or callback failure.

  3. Verify authority using metadata or capabilities only, never by reading a secret value. Then run only the separately reviewed owner procedure. For the database engine this procedure lives in rapp-postgres; the login does not itself approve configuration changes.

  4. Revoke the attended token when the reviewed operation and its non-secret verification are complete:

    bao token revoke -self
    

If browser login fails before authentication, confirm the netkingdom auth mount, platform-admin role, and allowed callback with railiance-platform and key-cape. Do not retry with a workload-specific OIDC role: it is intentionally incapable of OpenBao control-plane administration.

Authority

  • OpenBao policy and role owner: railiance-platform/docs/openbao.md
  • Human identity and MFA provider: key-cape / Keycloak
  • Database-engine procedure owner: rapp-postgres
  • Routing decision and founder-act surface: WARDEN-WP-0029