Operations credential management
Find a file
tegwick ee94c18938 WARDEN-WP-0033 finished — key-cape accepted the issuance question five days ago
T04 was the last open task, waiting on key-cape to accept or refuse ownership of
the coding-agent OpenBao issuance identity. They accepted, in KEY-WP-0009-T03,
on 2026-08-23: codex-railiance-platform is published in their
config/service-clients.example.yaml with subject service:codex:railiance-platform,
role coding-agent, scope openbao:login, 15m lifetime, and the service-auth
semantics in docs/openbao-service-auth-contract.md. The split is the one we
routed for — KeyCape issues, railiance-platform binds the OpenBao role, OpenBao
enforces, no secret value in either repo.

We found it by reading their repository. KEY-WP-0009-T04 records replying to
ops-warden; the inbox has zero messages from key-cape, read or unread. The task
sat `wait` on an answer that already existed.

That is T05's own lesson arriving on T04: a blocker is a claim about the world at
a date. So the same pass re-verified the two lanes pointing at key-cape against
their source instead of bumping dates:

- rapp-qonto-keycape-client -> verified: source-read. KEY-WP-0009-T02 did add
  bounded service-auth, but that is client_credentials JWT issuance for OpenBao
  machine login and does not front this client_secret_basic exchange or its
  rotation. Blocker stands, now with evidence rather than memory.
- key-cape-oidc-login -> asked of key-cape today, which the entry had recorded
  as still outstanding since 2026-08-21.

Also cleared the inbox that hid this: 9 stale unread, all superseded by shipped
work, with late closes sent to secrets-engine and llm-connect on the two threads
that had asked ops-warden something and never got an answer.

391 tests pass, ruff clean, boundary coverage 0 uncovered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4014535@bnt-lap001
Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
2026-08-28 22:00:09 +02:00
.claude/rules Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:35:30 +02:00
.repo-manager Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
deploy/kubernetes WARDEN-WP-0031 T04: prove ops-warden's caller identity against the live pin 2026-08-19 19:06:04 +02:00
docs Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
examples feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
history Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
intakes chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00
interfaces/reviews docs: project remaining WP0027 owner gates 2026-08-22 23:50:46 +02:00
registry WARDEN-WP-0033 finished — key-cape accepted the issuance question five days ago 2026-08-28 22:00:09 +02:00
scripts docs: record live zone config migration 2026-08-22 15:50:42 +02:00
src/warden fix: contain attended OpenBao login output 2026-08-23 01:31:05 +02:00
systemd feat(WARDEN-WP-0021): T1+T2 — scheduled worker tick enabled (systemd --user timer) 2026-06-30 15:19:23 +02:00
tests Re-emit the high-risk path artifact after the NetKingdom SSO lanes 2026-08-28 21:55:33 +02:00
wiki Add NetKingdom SSO credential routing lanes 2026-08-23 21:43:12 +02:00
workplans WARDEN-WP-0033 finished — key-cape accepted the issuance question five days ago 2026-08-28 22:00:09 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-25 20:17:24 +02:00
.gitignore feat(WP-0011): warden route lookup CLI over the pointer catalog 2026-06-18 21:07:13 +02:00
.repo-classification.yaml Mark .repo-classification.yaml human-reviewed (CUST-WP-0050 T02) 2026-06-22 11:40:44 +02:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:21:31 +02:00
CLAUDE.md Adopt risk-nexus finding routing; record the ADR gap policy-nexus exposes 2026-08-18 13:04:50 +02:00
INTENT.md Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:42:48 +02:00
Makefile Add Makefile targets to install and verify phase-memory with warden. 2026-07-03 00:54:21 +02:00
pyproject.toml Release v0.1.2. 2026-07-07 16:59:22 +02:00
README.md Release v0.1.2. 2026-07-07 16:59:22 +02:00
SCOPE.md Assent to the NetKingdom security layer model (WARDEN-IN-0001) 2026-08-28 21:47:44 +02:00
tenancy.yaml feat: adopt security zones and explicit workload refs 2026-08-22 15:36:37 +02:00
uv.lock Release v0.1.2. 2026-07-07 16:59:22 +02:00
WORK-RECORDS.md chore(registrar): assign State Hub identifiers 2026-08-28 21:52:03 +02:00

ops-warden

SSH Certificate Authority and certificate lifecycle manager for the ops fleet. Signs short-lived certs for adm / agt / atm actors and exposes the cert_command interface consumed by ops-bridge and other tooling.

See INTENT.md for direction, SCOPE.md for current implementation, and wiki/AccessManagementDirective.md for SSH policy. ops-warden issues SSH certs and routes every other credential need to its owner — see wiki/AccessRouting.md. Latest gap analysis: history/2026-06-17-post-wp0007-reassessment.md.

Get the source (Forgejo)

Canonical repo: https://forgejo.coulomb.social/coulomb/ops-warden
Releases: https://forgejo.coulomb.social/coulomb/ops-warden/releases

HTTPS clone:

git clone https://forgejo.coulomb.social/coulomb/ops-warden.git ~/ops-warden
cd ~/ops-warden

SSH clone (recommended for push/pull; add to ~/.ssh/config if missing):

Host forgejo-remote
    HostName 92.205.62.239
    Port 30022
    User git
    IdentityFile ~/.ssh/id_gitea
    StrictHostKeyChecking accept-new
git clone forgejo-remote:coulomb/ops-warden.git ~/ops-warden
cd ~/ops-warden

Legacy Gitea remotes (gitea-remote, gitea.coulomb.social) still work during migration; new checkouts should use Forgejo.

Install

From a Forgejo checkout:

Recommended (warden + experiential memory for route/worker/agent sessions):

make install-all
make verify-memory

SSH-only install (no phase-memory):

make install

Manual equivalent:

uv sync
uv tool install . --with-editable ../phase-memory --force

Or run without installing:

uv run warden --help

phase-memory must be a sibling checkout at ../phase-memory by default, or set PHASE_MEMORY_REPO when running make. Opt out of memory at runtime with WARDEN_MEMORY=0.

Upgrade after a release

When a new tag is published on Forgejo (e.g. v0.1.2):

cd ~/ops-warden
git fetch --tags origin
git pull --ff-only
make install-all
warden route list   # sanity check the installed CLI

If warden still behaves like an older build (same version string but missing recent subcommands or fixes), clear the cached wheel and reinstall:

uv cache clean ops-warden
uv tool install . --with-editable ../phase-memory --reinstall --force

Check out a specific release:

git fetch --tags origin
git checkout v0.1.2
make install-all

Quick start (local backend)

# One-time: generate a CA key (keep mode 600, never commit)
ssh-keygen -t ed25519 -f ~/.ssh/ops-ca-user -C "Ops SSH User CA" -N ""

# Configure warden (~/.config/warden/warden.yaml) — see wiki/OpsWardenConfig.md
warden inventory add agt-example --type agt --principal agt-example
warden sign agt-example --pubkey ~/.ssh/id_ed25519.pub
warden status agt-example
warden scorecard

Production uses the vault backend against OpenBao or HashiCorp Vault (Vault-compatible SSH secrets engine API). Template: examples/warden.production.example.yaml. See wiki/OpsWardenConfig.md and wiki/OpenBaoSshEngineChecklist.md.

Routing lookup (warden route)

ops-warden issues SSH certs and routes every other credential need to its owner. The route command group is a read-only lookup over the pointer catalog (registry/routing/catalog.yaml) — it never calls another subsystem or returns secrets.

warden route list [--all] [--json]                    # scenarios (active-only unless --all)
warden route list --stale [--stale-days 90] [--all]   # past review cadence
warden route show <id> [--json]                       # owner + wiki/canon pointers; SSH adds steps
warden route find "issue an api key"                  # rank scenarios by keyword overlap

Full role and examples: wiki/AccessRouting.md.

Development

make install-all
make test
make lint
uv run pytest -m integration   # requires ssh-keygen in PATH

Key paths

Path Purpose
~/.config/warden/warden.yaml Backend and CA/Vault settings
~/.config/warden/inventory.yaml Actor → principals registry
~/.local/state/warden/ Signed certs, keys, signatures.log

Documentation

  • INTENT.md — operational access steward mission (NetKingdom-aligned)
  • wiki/CredentialRouting.md — which subsystem for each credential type
  • wiki/NetKingdomSecurityMap.md — platform security component map
  • wiki/ActorInventoryPatterns.md — standard adm/agt/atm actor patterns
  • wiki/OpsWardenConfig.md — configuration reference
  • wiki/CertCommandInterface.mdcert_command contract for callers
  • wiki/InterHubBootstrapAccessLane.md — short-lived cert envelope for bootstrap tasks

Workplans

Active and proposed work lives in workplans/. Finished plans are archived under workplans/archived/.