Operations credential management
Find a file
tegwick 9514ad914e WARDEN-WP-0004: repo hygiene and hub sync
Update SCOPE and README to reflect the shipped warden CLI, fill agent
rules for stack/architecture/boundary, archive finished workplans
0001–0003, and register WP-0004 in State Hub.
2026-06-17 07:33:49 +02:00
.claude/rules WARDEN-WP-0004: repo hygiene and hub sync 2026-06-17 07:33:49 +02:00
registry Add capability registry scaffold (REUSE-WP-0014-T06 B04) 2026-06-16 01:56:08 +02:00
src/warden feat(warden): WARDEN-WP-0003 — test coverage, permissions, status --state-dir 2026-05-15 17:05:38 +02:00
tests feat(warden): WARDEN-WP-0003 — test coverage, permissions, status --state-dir 2026-05-15 17:05:38 +02:00
wiki docs: add interhub bootstrap access lane 2026-06-17 00:18:01 +02:00
workplans WARDEN-WP-0004: repo hygiene and hub sync 2026-06-17 07:33:49 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-05-15 17:06:06 +02:00
.gitignore chore: remove swap file, add *.swp to .gitignore 2026-05-15 15:53:58 +02:00
AGENTS.md Refresh agent instruction files 2026-05-18 16:55:47 +02:00
CLAUDE.md Refresh agent instruction files 2026-05-18 16:55:47 +02:00
LICENSE Initial commit 2026-03-28 00:35:11 +00:00
pyproject.toml feat(warden): WARDEN-WP-0003 — test coverage, permissions, status --state-dir 2026-05-15 17:05:38 +02:00
README.md WARDEN-WP-0004: repo hygiene and hub sync 2026-06-17 07:33:49 +02:00
SCOPE.md WARDEN-WP-0004: repo hygiene and hub sync 2026-06-17 07:33:49 +02:00
uv.lock feat(bootstrap): WARDEN-WP-0001 initial implementation — 42 tests passing 2026-05-15 13:27:49 +02:00

ops-warden

SSH Certificate Authority and certificate lifecycle manager for the ops fleet. Signs short-lived certs for adm / agt / atm actors and exposes the cert_command interface consumed by ops-bridge and other tooling.

See SCOPE.md for boundaries and wiki/AccessManagementDirective.md for policy.

Install

uv sync
uv tool install .

Or run without installing:

uv run warden --help

Quick start (local backend)

# One-time: generate a CA key (keep mode 600, never commit)
ssh-keygen -t ed25519 -f ~/.ssh/ops-ca-user -C "Ops SSH User CA" -N ""

# Configure warden (~/.config/warden/warden.yaml) — see wiki/OpsWardenConfig.md
warden inventory add agt-example --type agt --principal agt-example
warden sign agt-example --pubkey ~/.ssh/id_ed25519.pub
warden status agt-example
warden scorecard

Production uses the vault backend against OpenBao or HashiCorp Vault (Vault-compatible SSH secrets engine API). See wiki/OpsWardenConfig.md.

Development

uv sync
uv run pytest              # unit tests (integration excluded)
uv run pytest -m integration   # requires ssh-keygen in PATH
uv run ruff check .

Key paths

Path Purpose
~/.config/warden/warden.yaml Backend and CA/Vault settings
~/.config/warden/inventory.yaml Actor → principals registry
~/.local/state/warden/ Signed certs, keys, signatures.log

Documentation

  • wiki/OpsWardenConfig.md — configuration reference
  • wiki/CertCommandInterface.mdcert_command contract for callers
  • wiki/InterHubBootstrapAccessLane.md — short-lived cert envelope for bootstrap tasks

Workplans

Active and proposed work lives in workplans/. Finished plans are archived under workplans/archived/.