T01 (done): canonical capabilities-based verify pattern in the fleet promotion checklist (catalog-lane-promotion.md) and applied to the railiance-backup and forgejo-admin lane playbooks. Verification proves allow/deny via `bao token capabilities` against the KV v2 data path, never `bao kv get`; a denied default-policy token-create is a pass, not a privileged-fallback trigger. T07 (progress): lessons-learned note for the 2026-07-16 CCR-2026-0004 disclosure (three root causes). Live re-verify + rotation block remain (depend on T06). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
4.4 KiB
Catalog Lane Promotion — draft → active
Date: 2026-07-01
Workplan: WARDEN-WP-0023 T05
registry/routing/catalog.yaml entries start as draft until an owner-confirmed
concrete path exists. Draft lanes are hidden from default warden route find unless
--all is passed.
Promotion checklist
Before changing status: draft → status: active:
| # | Criterion | Evidence |
|---|---|---|
| 1 | Owner confirmed | Owner repo workplan or State Hub note naming the lane ready |
| 2 | Concrete path | Real OpenBao path, grant id, or exec command — no unresolved <placeholders> in the primary handoff |
| 3 | Playbook | wiki/playbooks/<id>.md with #worker-checklist section |
| 4 | Exec routing | exec_owner + native command or exec_capable: true with tested warden access proxy |
| 5 | Resolvable | warden route show <id> --json shows resolvable: true when placeholders are documented |
| 6 | Tests | Routing test or smoke proving lookup + handoff shape (no secret values in fixtures) |
| 7 | Review date | Update reviewed: in catalog entry |
| 8 | Verification | Positive + negative proof via bao token capabilities — never bao kv get (see below) |
Promotion PR touches: registry/routing/catalog.yaml, playbook, optional
tests/test_routing.py, and a one-line note in wiki/CredentialRouting.md draft table.
Capabilities-safe lane verification (WARDEN-WP-0026 T01)
Verifying a lane must never read the secret data. A negative deny-test that
runs bao kv get <path> will, if the deny fails (e.g. a privileged token
fallback), print the secret value into a logged context — this is exactly the
2026-07-16 CCR-2026-0004 disclosure. Prove allow/deny with
bao token capabilities, which returns the capability list, not the value.
For KV v2, capabilities are checked against the API data path
(<mount>/data/<lane-path>), not the kv get logical path.
# Positive: the lane's own OIDC identity can read the data path.
bao login -method=oidc -path=netkingdom role=<lane-role> # caller identity
bao token capabilities "$(bao print token)" platform/data/<lane-path>
# → expect the list to include: read
# Negative: a default-only identity is denied — no value is ever read.
DEFAULT_TOKEN=$(bao token create -policy=default -field=token) # if denied, STOP — do not fall back
bao token capabilities "$DEFAULT_TOKEN" platform/data/<lane-path>
# → expect: deny
- Never substitute
bao kv getfor the checks above. Reading a value to "confirm it's there" is the anti-pattern; presence is proven byreadin the capability list. - If
bao token create -policy=defaultis itself denied for your identity, that is a pass for the deny direction — do not fall back to your privileged login token to force the read. - Fetching a value for use (
--fieldinto an env var or file, orwarden access … --field) is a separate, intended action — not verification.
Record the capability lists (allow/deny) as the promotion evidence; they contain no secret material and are safe for CCRs, State Hub, and Git.
Worked examples (already active)
ops-warden-warden-sign-token — promoted 2026-07-01 after RAILIANCE-WP-0005:
- Owner:
railiance-platformcredential broker - Concrete grant:
ops-warden/warden-sign - Playbook:
wiki/playbooks/ops-warden-warden-sign-token.md - Smoke:
make credential-exec-ops-warden-smoke
issue-core-ingestion-api-key — promoted 2026-07-02 after RAILIANCE-WP-0009
(CCR-2026-0002): KV path live, ExternalSecret issue-core/issue-core-runtime
SecretSynced, positive + negative verification audit-logged.
openrouter-llm-connect — promoted 2026-07-02 after RAILIANCE-WP-0010
(CCR-2026-0003): KV path live, ExternalSecret
activity-core/llm-connect-provider-secrets SecretSynced, llm-connect rolled
out on the OpenBao-delivered value, positive + negative verification audit-logged.
Draft lanes (2026-07-02)
Catalog id |
Blocker |
|---|---|
object-storage-sts |
NK-WP-0007 vending path not production-exercised |
database-dynamic-credentials |
OpenBao database engine role paths TBD per workload |
Re-run promotion when the owning repo closes the blocker; do not promote on playbook prose alone.
See also
wiki/CredentialRouting.md— draft table indexwiki/playbooks/ops-warden-warden-sign-token.md— promotion reference