Prepare tenant-zero OpenBao roles and review platform essentials
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
4f20e755c4
commit
5781d34b3b
10 changed files with 179 additions and 14 deletions
43
docs/platform-tenant-essentials-review.md
Normal file
43
docs/platform-tenant-essentials-review.md
Normal file
|
|
@ -0,0 +1,43 @@
|
|||
# Platform essentials tenant review — 2026-09-27
|
||||
|
||||
Operator requirement: `tenant:platform` is tenant zero for platform infrastructure.
|
||||
`tenant:coulomb` is a workload/product tenant. The shared `coulomb.social` DNS
|
||||
suffix does not establish tenant ownership. Provider ownership, caller identity,
|
||||
resource tenant and enforcement capability are separate facts.
|
||||
|
||||
| Essential / boundary | Source reviewed | Result and action |
|
||||
| --- | --- | --- |
|
||||
| OpenBao custody/provider | `tenancy.yaml`, `docs/tenancy-posture.md`, `openbao/auth/` | Platform-owned. Correct both infrastructure JWT roles to platform; retain exact audience/subject/scope and bounded policies. |
|
||||
| Platform coding agent | KeyCape service registration; `coding-agent-jwt-role.json` | Incorrect Coulomb claim corrected in both source owners. Existing workload read policy remains explicit; changing identity tenant grants no additional data access. |
|
||||
| Secrets Engine service login | KeyCape registration; consumer `service_auth.py`; proposed service role | Incorrect Coulomb claim corrected together to platform. Login-only self policy; no lane mutation privilege. |
|
||||
| Approval / informed decision / policy checks | KeyCape registrations; Secrets Engine approval and authorization profiles | Already platform-bound. Keep exact tenant comparison, distinct audiences/scopes and human controls. |
|
||||
| Audit senders | `docs/credential-lane-designs/factory-audit-senders-review.md`; Audit Core tenancy declaration | Factory senders already restricted to platform. Provider ownership does not relabel historical events or consumer tenants. |
|
||||
| KeyCape human directory fallback | KeyCape `token.go`, tenant claim contract | Still legacy `tenant:coulomb` when directory tenant is missing. Do not change the default to platform: that would implicitly elevate unclassified users. Explicit platform registration/directory binding remains necessary. |
|
||||
| Shared PostgreSQL / Forgejo database | `tenancy.yaml`, `docs/tenancy-posture.md`, rapp-postgres declarations | Platform provider ownership; consumers retain their databases and workload isolation. No tenant claim is implemented at the substrate by these declarations. |
|
||||
| OpenBao package | rapp-openbao YAML/JSON source review | No runtime tenant claim found in package declarations; package ownership and the auth role bindings above must not be inferred from ingress DNS. Absence of a claim is not live verification. |
|
||||
| Warden / Forgejo | Warden tenancy declaration; Forgejo YAML/JSON source review | Infrastructure belongs to platform. SSH, package and workload grants retain their explicit identities; do not replace Coulomb organization or KV path components with platform. |
|
||||
|
||||
This is a bounded source review of the existing credential-chain dependencies,
|
||||
not a claim that every platform deployment has been audited. No live tenant
|
||||
migration, token issuance, value read or workload relocation was performed.
|
||||
The existing RPF-WP-0035-T02 owns the coordinated service-login return; existing
|
||||
KEY-WP-0009 contract and SECRETS-WP-0008-T06 carry provider/consumer changes.
|
||||
No new work item is opened.
|
||||
|
||||
## Deployment and acceptance
|
||||
|
||||
1. Inventory exact live KeyCape registrations and OpenBao mount/roles using
|
||||
metadata-only, attended authority. Source files are not live-state receipts.
|
||||
2. Compare issuer, audience, subject, tenant, policies and aliases. Preserve
|
||||
workload grants; do not introduce a tenant alias or accept both tenants.
|
||||
3. Coordinate issuance and verifier/consumer deployment. Old Coulomb-bound
|
||||
platform JWTs must fail; new platform-bound JWTs must succeed. Rollback is
|
||||
an explicit coordinated restoration, never a fallback to another identity.
|
||||
4. Already-issued OpenBao tokens do not change tenant/policies when a JWT role
|
||||
changes. Revoke affected tokens under owner custody and verify denial. Bound
|
||||
the remaining JWT and token lifetimes; retain only non-secret results.
|
||||
5. Prove wrong-tenant/audience/subject/scope refusal, exact effective policies,
|
||||
expiry/use limits and self-revocation before publishing the consumer contract.
|
||||
|
||||
Tenant ownership does not raise the historical I/A/E/R/V posture scores. The
|
||||
posture records describe demonstrated isolation/recovery, not the owner tenant.
|
||||
Loading…
Add table
Add a link
Reference in a new issue