Prepare tenant-zero OpenBao roles and review platform essentials
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
4f20e755c4
commit
5781d34b3b
10 changed files with 179 additions and 14 deletions
|
|
@ -1,6 +1,6 @@
|
|||
# Secrets-engine service JWT login
|
||||
|
||||
Status: proposed, not provisioned. Owner: railiance-platform, RPF-WP-0032.
|
||||
Status: proposed, not provisioned. Owner: railiance-platform, RPF-WP-0035-T02 (design origin RPF-WP-0032).
|
||||
Demand: State Hub message `38b47122-07eb-4a7f-a5df-13a38f50e110`.
|
||||
|
||||
## Contract and ownership
|
||||
|
|
@ -20,11 +20,11 @@ or the coding-agent mount to introduce this service.
|
|||
|
||||
| Setting | Proposed value / evidence required |
|
||||
| --- | --- |
|
||||
| Verification | RS256 only; exact HTTPS issuer and approved discovery/JWKS URL, both pending KeyCape owner confirmation |
|
||||
| Verification | RS256 only; issuer `https://kc.coulomb.social`, JWKS `https://kc.coulomb.social/jwks`; public discovery rechecked 2026-09-27; live registration remains unverified |
|
||||
| Role type / user claim | `jwt` / `sub` |
|
||||
| Audience | `secrets-engine-openbao` |
|
||||
| Subject | `service:secrets-engine` |
|
||||
| Bound claims, string matching | `principal_type=service`, `tenant=tenant:coulomb`, required `roles=secrets-engine`, `scope=openbao:login` |
|
||||
| Bound claims, string matching | `principal_type=service`, `tenant=tenant:platform`, required `roles=secrets-engine`, `scope=openbao:login` |
|
||||
| Token policy | `secrets-engine-login-self` only; no default policy |
|
||||
| Token bounds | service token, TTL/max/explicit max `5m`, 8 uses, no periodic token; budget must include cleanup |
|
||||
| Logging | verbose OIDC logging disabled; no JWT claim dump or token/accessor in receipts |
|
||||
|
|
@ -96,3 +96,27 @@ OpenBao's [JWT documentation](https://openbao.org/docs/auth/jwt/) describes
|
|||
signature verification and claim binding; its [role API](https://openbao.org/docs/2.4.x/api/auth/jwt/)
|
||||
defines token TTL/use limits and the explicit maximum. These are mechanism
|
||||
references, not evidence of this cluster's installed configuration.
|
||||
|
||||
## Prepared source return — 2026-09-27
|
||||
|
||||
The exact proposed bundle is `openbao/auth/keycape-services-config.json`,
|
||||
`openbao/auth/secrets-engine-jwt-role.json` and
|
||||
`openbao/policies/secrets-engine-login-self.hcl`. These files are non-secret
|
||||
inputs for the existing attended platform procedure, not an applied receipt.
|
||||
The discovery document advertises `/token` and `client_credentials`.
|
||||
|
||||
The operator clarified that platform infrastructure belongs to tenant zero,
|
||||
`tenant:platform`. Coulomb is a workload tenant; its DNS domain is not ownership.
|
||||
The former `tenant:coulomb` service registration and consumer preflight were
|
||||
consistent but incorrectly scoped. The corrected source uses `tenant:platform`
|
||||
for both OpenBao infrastructure clients and the existing approval clients.
|
||||
|
||||
Before writing: survey mounts/roles, confirm exact live client registration and
|
||||
protected client-side custody, review this bundle and obtain the scoped attended
|
||||
window via `warden access openbao-platform-admin-login --exec -- <reviewed-command>`.
|
||||
Do not execute a placeholder command. The reviewed child must install only this
|
||||
isolated mount/config, self policy and role, compare effective policy metadata,
|
||||
then perform the positive/negative/expiry/use-limit/revocation checks above.
|
||||
Do not print login responses. Publish the consumer contract only after those
|
||||
checks pass. A conflicting existing mount/role requires review, not overwrite.
|
||||
No service-client secret is created, moved or requested by this source return.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue