ops-warden/wiki/playbooks/secrets-engine-approval-client-login.md
tegwick edbe95fe15
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 1s
Route attended approval-client login to scoped OpenBao reader
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 01:46:46 +02:00

1.6 KiB

Scoped approval-client reader login

CCR-2026-0019 names the operator-confirmed net-kingdom-admins group and live OIDC role secrets-engine-approval-client-workload-kv-read. This login lane establishes only that reader session. Warden applies its normal policy gate, contained OIDC helper, silent child and self-revocation/cleanup.

Before delivery, run the platform metadata-only preflight:

warden access secrets-engine-approval-client-login --exec -- python3 /home/worsch/railiance-platform/scripts/approval-client-reader-preflight.py

The command verifies effective exact-path read and sibling/parent/write denial. It reads no KV value. Login readiness does not activate credential delivery. CCR-2026-0019 retains its separate pending native delivery acceptance. No raw fetch, retained token, admin fallback or verifier Kubernetes Secret substitution.

Origin: operator-authorized SECRETS-WP-0010-T03 continuation, 2026-09-14.

Live reader preflight and protected file/token-exchange checks passed on 2026-09-14. Platform evidence names this session's scope and its remaining wrong-group and real claim/consume checks. The acceptance command is /home/worsch/secrets-engine/.venv/bin/python -B /home/worsch/railiance-platform/scripts/approval-client-delivery-check.py. It requires the owner-bound Approval Engine tunnel on 127.0.0.1:18281, removes its private runtime file, and never creates/binds/consumes an approval.

When the installed package uses its older bundled catalog, explicitly select WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml.