Operations credential management
Find a file
custodian-sync a45280f30d
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-28:
  - update .custodian-brief.md for ops-warden

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014535@bnt-lap001
Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2026-08-28 22:02:58 +02:00
.claude/rules Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:35:30 +02:00
.repo-manager Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
deploy/kubernetes WARDEN-WP-0031 T04: prove ops-warden's caller identity against the live pin 2026-08-19 19:06:04 +02:00
docs Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
examples feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
history Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
intakes chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00
interfaces/reviews docs: project remaining WP0027 owner gates 2026-08-22 23:50:46 +02:00
registry WARDEN-WP-0033 finished — key-cape accepted the issuance question five days ago 2026-08-28 22:00:09 +02:00
scripts docs: record live zone config migration 2026-08-22 15:50:42 +02:00
src/warden fix: contain attended OpenBao login output 2026-08-23 01:31:05 +02:00
systemd feat(WARDEN-WP-0021): T1+T2 — scheduled worker tick enabled (systemd --user timer) 2026-06-30 15:19:23 +02:00
tests Re-emit the high-risk path artifact after the NetKingdom SSO lanes 2026-08-28 21:55:33 +02:00
wiki Add NetKingdom SSO credential routing lanes 2026-08-23 21:43:12 +02:00
workplans WARDEN-WP-0027-T02: the owner gate closed five days ago 2026-08-28 22:01:47 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-28 22:02:58 +02:00
.gitignore feat(WP-0011): warden route lookup CLI over the pointer catalog 2026-06-18 21:07:13 +02:00
.repo-classification.yaml Mark .repo-classification.yaml human-reviewed (CUST-WP-0050 T02) 2026-06-22 11:40:44 +02:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:21:31 +02:00
CLAUDE.md Adopt risk-nexus finding routing; record the ADR gap policy-nexus exposes 2026-08-18 13:04:50 +02:00
INTENT.md Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:42:48 +02:00
Makefile Add Makefile targets to install and verify phase-memory with warden. 2026-07-03 00:54:21 +02:00
pyproject.toml Release v0.1.2. 2026-07-07 16:59:22 +02:00
README.md Release v0.1.2. 2026-07-07 16:59:22 +02:00
SCOPE.md Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
tenancy.yaml feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
uv.lock Release v0.1.2. 2026-07-07 16:59:22 +02:00
WORK-RECORDS.md chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00

ops-warden

SSH Certificate Authority and certificate lifecycle manager for the ops fleet. Signs short-lived certs for adm / agt / atm actors and exposes the cert_command interface consumed by ops-bridge and other tooling.

See INTENT.md for direction, SCOPE.md for current implementation, and wiki/AccessManagementDirective.md for SSH policy. ops-warden issues SSH certs and routes every other credential need to its owner — see wiki/AccessRouting.md. Latest gap analysis: history/2026-06-17-post-wp0007-reassessment.md.

Get the source (Forgejo)

Canonical repo: https://forgejo.coulomb.social/coulomb/ops-warden
Releases: https://forgejo.coulomb.social/coulomb/ops-warden/releases

HTTPS clone:

git clone https://forgejo.coulomb.social/coulomb/ops-warden.git ~/ops-warden
cd ~/ops-warden

SSH clone (recommended for push/pull; add to ~/.ssh/config if missing):

Host forgejo-remote
    HostName 92.205.62.239
    Port 30022
    User git
    IdentityFile ~/.ssh/id_gitea
    StrictHostKeyChecking accept-new
git clone forgejo-remote:coulomb/ops-warden.git ~/ops-warden
cd ~/ops-warden

Legacy Gitea remotes (gitea-remote, gitea.coulomb.social) still work during migration; new checkouts should use Forgejo.

Install

From a Forgejo checkout:

Recommended (warden + experiential memory for route/worker/agent sessions):

make install-all
make verify-memory

SSH-only install (no phase-memory):

make install

Manual equivalent:

uv sync
uv tool install . --with-editable ../phase-memory --force

Or run without installing:

uv run warden --help

phase-memory must be a sibling checkout at ../phase-memory by default, or set PHASE_MEMORY_REPO when running make. Opt out of memory at runtime with WARDEN_MEMORY=0.

Upgrade after a release

When a new tag is published on Forgejo (e.g. v0.1.2):

cd ~/ops-warden
git fetch --tags origin
git pull --ff-only
make install-all
warden route list   # sanity check the installed CLI

If warden still behaves like an older build (same version string but missing recent subcommands or fixes), clear the cached wheel and reinstall:

uv cache clean ops-warden
uv tool install . --with-editable ../phase-memory --reinstall --force

Check out a specific release:

git fetch --tags origin
git checkout v0.1.2
make install-all

Quick start (local backend)

# One-time: generate a CA key (keep mode 600, never commit)
ssh-keygen -t ed25519 -f ~/.ssh/ops-ca-user -C "Ops SSH User CA" -N ""

# Configure warden (~/.config/warden/warden.yaml) — see wiki/OpsWardenConfig.md
warden inventory add agt-example --type agt --principal agt-example
warden sign agt-example --pubkey ~/.ssh/id_ed25519.pub
warden status agt-example
warden scorecard

Production uses the vault backend against OpenBao or HashiCorp Vault (Vault-compatible SSH secrets engine API). Template: examples/warden.production.example.yaml. See wiki/OpsWardenConfig.md and wiki/OpenBaoSshEngineChecklist.md.

Routing lookup (warden route)

ops-warden issues SSH certs and routes every other credential need to its owner. The route command group is a read-only lookup over the pointer catalog (registry/routing/catalog.yaml) — it never calls another subsystem or returns secrets.

warden route list [--all] [--json]                    # scenarios (active-only unless --all)
warden route list --stale [--stale-days 90] [--all]   # past review cadence
warden route show <id> [--json]                       # owner + wiki/canon pointers; SSH adds steps
warden route find "issue an api key"                  # rank scenarios by keyword overlap

Full role and examples: wiki/AccessRouting.md.

Development

make install-all
make test
make lint
uv run pytest -m integration   # requires ssh-keygen in PATH

Key paths

Path Purpose
~/.config/warden/warden.yaml Backend and CA/Vault settings
~/.config/warden/inventory.yaml Actor → principals registry
~/.local/state/warden/ Signed certs, keys, signatures.log

Documentation

  • INTENT.md — operational access steward mission (NetKingdom-aligned)
  • wiki/CredentialRouting.md — which subsystem for each credential type
  • wiki/NetKingdomSecurityMap.md — platform security component map
  • wiki/ActorInventoryPatterns.md — standard adm/agt/atm actor patterns
  • wiki/OpsWardenConfig.md — configuration reference
  • wiki/CertCommandInterface.mdcert_command contract for callers
  • wiki/InterHubBootstrapAccessLane.md — short-lived cert envelope for bootstrap tasks

Workplans

Active and proposed work lives in workplans/. Finished plans are archived under workplans/archived/.