Prepare tenant-zero OpenBao roles and review platform essentials
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
codex 2026-09-27 16:43:32 +02:00
parent 4f20e755c4
commit 5781d34b3b
10 changed files with 179 additions and 14 deletions

View file

@ -1,6 +1,6 @@
# Secrets-engine service JWT login
Status: proposed, not provisioned. Owner: railiance-platform, RPF-WP-0032.
Status: proposed, not provisioned. Owner: railiance-platform, RPF-WP-0035-T02 (design origin RPF-WP-0032).
Demand: State Hub message `38b47122-07eb-4a7f-a5df-13a38f50e110`.
## Contract and ownership
@ -20,11 +20,11 @@ or the coding-agent mount to introduce this service.
| Setting | Proposed value / evidence required |
| --- | --- |
| Verification | RS256 only; exact HTTPS issuer and approved discovery/JWKS URL, both pending KeyCape owner confirmation |
| Verification | RS256 only; issuer `https://kc.coulomb.social`, JWKS `https://kc.coulomb.social/jwks`; public discovery rechecked 2026-09-27; live registration remains unverified |
| Role type / user claim | `jwt` / `sub` |
| Audience | `secrets-engine-openbao` |
| Subject | `service:secrets-engine` |
| Bound claims, string matching | `principal_type=service`, `tenant=tenant:coulomb`, required `roles=secrets-engine`, `scope=openbao:login` |
| Bound claims, string matching | `principal_type=service`, `tenant=tenant:platform`, required `roles=secrets-engine`, `scope=openbao:login` |
| Token policy | `secrets-engine-login-self` only; no default policy |
| Token bounds | service token, TTL/max/explicit max `5m`, 8 uses, no periodic token; budget must include cleanup |
| Logging | verbose OIDC logging disabled; no JWT claim dump or token/accessor in receipts |
@ -96,3 +96,27 @@ OpenBao's [JWT documentation](https://openbao.org/docs/auth/jwt/) describes
signature verification and claim binding; its [role API](https://openbao.org/docs/2.4.x/api/auth/jwt/)
defines token TTL/use limits and the explicit maximum. These are mechanism
references, not evidence of this cluster's installed configuration.
## Prepared source return — 2026-09-27
The exact proposed bundle is `openbao/auth/keycape-services-config.json`,
`openbao/auth/secrets-engine-jwt-role.json` and
`openbao/policies/secrets-engine-login-self.hcl`. These files are non-secret
inputs for the existing attended platform procedure, not an applied receipt.
The discovery document advertises `/token` and `client_credentials`.
The operator clarified that platform infrastructure belongs to tenant zero,
`tenant:platform`. Coulomb is a workload tenant; its DNS domain is not ownership.
The former `tenant:coulomb` service registration and consumer preflight were
consistent but incorrectly scoped. The corrected source uses `tenant:platform`
for both OpenBao infrastructure clients and the existing approval clients.
Before writing: survey mounts/roles, confirm exact live client registration and
protected client-side custody, review this bundle and obtain the scoped attended
window via `warden access openbao-platform-admin-login --exec -- <reviewed-command>`.
Do not execute a placeholder command. The reviewed child must install only this
isolated mount/config, self policy and role, compare effective policy metadata,
then perform the positive/negative/expiry/use-limit/revocation checks above.
Do not print login responses. Publish the consumer contract only after those
checks pass. A conflicting existing mount/role requires review, not overwrite.
No service-client secret is created, moved or requested by this source return.

View file

@ -0,0 +1,43 @@
# Platform essentials tenant review — 2026-09-27
Operator requirement: `tenant:platform` is tenant zero for platform infrastructure.
`tenant:coulomb` is a workload/product tenant. The shared `coulomb.social` DNS
suffix does not establish tenant ownership. Provider ownership, caller identity,
resource tenant and enforcement capability are separate facts.
| Essential / boundary | Source reviewed | Result and action |
| --- | --- | --- |
| OpenBao custody/provider | `tenancy.yaml`, `docs/tenancy-posture.md`, `openbao/auth/` | Platform-owned. Correct both infrastructure JWT roles to platform; retain exact audience/subject/scope and bounded policies. |
| Platform coding agent | KeyCape service registration; `coding-agent-jwt-role.json` | Incorrect Coulomb claim corrected in both source owners. Existing workload read policy remains explicit; changing identity tenant grants no additional data access. |
| Secrets Engine service login | KeyCape registration; consumer `service_auth.py`; proposed service role | Incorrect Coulomb claim corrected together to platform. Login-only self policy; no lane mutation privilege. |
| Approval / informed decision / policy checks | KeyCape registrations; Secrets Engine approval and authorization profiles | Already platform-bound. Keep exact tenant comparison, distinct audiences/scopes and human controls. |
| Audit senders | `docs/credential-lane-designs/factory-audit-senders-review.md`; Audit Core tenancy declaration | Factory senders already restricted to platform. Provider ownership does not relabel historical events or consumer tenants. |
| KeyCape human directory fallback | KeyCape `token.go`, tenant claim contract | Still legacy `tenant:coulomb` when directory tenant is missing. Do not change the default to platform: that would implicitly elevate unclassified users. Explicit platform registration/directory binding remains necessary. |
| Shared PostgreSQL / Forgejo database | `tenancy.yaml`, `docs/tenancy-posture.md`, rapp-postgres declarations | Platform provider ownership; consumers retain their databases and workload isolation. No tenant claim is implemented at the substrate by these declarations. |
| OpenBao package | rapp-openbao YAML/JSON source review | No runtime tenant claim found in package declarations; package ownership and the auth role bindings above must not be inferred from ingress DNS. Absence of a claim is not live verification. |
| Warden / Forgejo | Warden tenancy declaration; Forgejo YAML/JSON source review | Infrastructure belongs to platform. SSH, package and workload grants retain their explicit identities; do not replace Coulomb organization or KV path components with platform. |
This is a bounded source review of the existing credential-chain dependencies,
not a claim that every platform deployment has been audited. No live tenant
migration, token issuance, value read or workload relocation was performed.
The existing RPF-WP-0035-T02 owns the coordinated service-login return; existing
KEY-WP-0009 contract and SECRETS-WP-0008-T06 carry provider/consumer changes.
No new work item is opened.
## Deployment and acceptance
1. Inventory exact live KeyCape registrations and OpenBao mount/roles using
metadata-only, attended authority. Source files are not live-state receipts.
2. Compare issuer, audience, subject, tenant, policies and aliases. Preserve
workload grants; do not introduce a tenant alias or accept both tenants.
3. Coordinate issuance and verifier/consumer deployment. Old Coulomb-bound
platform JWTs must fail; new platform-bound JWTs must succeed. Rollback is
an explicit coordinated restoration, never a fallback to another identity.
4. Already-issued OpenBao tokens do not change tenant/policies when a JWT role
changes. Revoke affected tokens under owner custody and verify denial. Bound
the remaining JWT and token lifetimes; retain only non-secret results.
5. Prove wrong-tenant/audience/subject/scope refusal, exact effective policies,
expiry/use limits and self-revocation before publishing the consumer contract.
Tenant ownership does not raise the historical I/A/E/R/V posture scores. The
posture records describe demonstrated isolation/recovery, not the owner tenant.

View file

@ -256,3 +256,12 @@ renumbered.
Six months, or on any of: a service moving placement level, a backup target
becoming available, or the framework reaching `accepted`. Next review due
**2027-02-17**.
## Platform ownership clarification — 2026-09-27
All infrastructure providers in this declaration belong to `tenant:platform`
(tenant zero), including OpenBao, shared PostgreSQL and Forgejo's database.
Coulomb is a workload tenant; DNS under `coulomb.social` does not assign these
providers to it. Provider ownership is separate from the measured tenancy
posture axes and from each credential or database consumer's resource tenant.
See [the source review and migration requirements](platform-tenant-essentials-review.md).