Declare live platform-admin role and policies; add attended admin check
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Answers the-custodian 641673a4. An attended read-only check (receipt
docs/evidence/2026-09-23-openbao-platform-admin-check.json) found:
- live platform-admin policy = repo file + reins/* (ops-mason, 2026-07-27);
  repo now matches live (sha256 0ca5b821...). No live write.
- role also attaches operator-custody (undeclared); declared here.
- role declared as openbao/auth/netkingdom-platform-admin-role.json.
- default policy is attached and grants revoke-self/lookup-self, so the
  suspected missing grant is not the cause of warden's unconfirmed revocation.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
This commit is contained in:
codex 2026-09-23 19:27:25 +02:00
parent 32ccb1acab
commit 3fbb610d1f
8 changed files with 525 additions and 0 deletions

View file

@ -395,6 +395,21 @@ The browser callback URI must be present in both:
- KeyCape `openbao-admin` client redirect URIs; and
- OpenBao `auth/netkingdom/role/platform-admin` `allowed_redirect_uris`.
Declared state of the administrator login (verified live 2026-09-23,
`docs/evidence/2026-09-23-openbao-platform-admin-check.json`):
- role `auth/netkingdom/role/platform-admin`:
`openbao/auth/netkingdom-platform-admin-role.json`. It is written by
net-kingdom `sso-mfa/k8s/keycape/configure-openbao-oidc.sh`, which lacks
`operator-custody` and still lists retired `bao.coulomb.social` callbacks.
- policies `openbao/policies/platform-admin.hcl` and
`openbao/policies/operator-custody.hcl`, plus the built-in `default`
(`token_no_default_policy: false`). `default` grants `auth/token/revoke-self`
and `lookup-self`, so an attended session can always revoke itself.
- Re-check with the silent attended helper
`scripts/openbao-platform-admin-check.sh --receipt <new-file>`. Run it through
`scripts/openbao-attended-exec.py`. It only reads.
If the compatibility alias is kept enabled, also keep
`http://127.0.0.1:18200/ui/vault/auth/keycape/oidc/callback` in the
KeyCape client and `auth/keycape/role/platform-admin`.