Prepare tenant-zero OpenBao roles and review platform essentials
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
4f20e755c4
commit
5781d34b3b
10 changed files with 179 additions and 14 deletions
|
|
@ -8,7 +8,7 @@
|
|||
"bound_claims": {
|
||||
"sub": "service:codex:railiance-platform",
|
||||
"principal_type": "service",
|
||||
"tenant": "tenant:coulomb",
|
||||
"tenant": "tenant:platform",
|
||||
"roles": "coding-agent"
|
||||
},
|
||||
"token_policies": [
|
||||
|
|
|
|||
7
openbao/auth/keycape-services-config.json
Normal file
7
openbao/auth/keycape-services-config.json
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
{
|
||||
"jwks_url": "https://kc.coulomb.social/jwks",
|
||||
"bound_issuer": "https://kc.coulomb.social",
|
||||
"jwt_supported_algs": [
|
||||
"RS256"
|
||||
]
|
||||
}
|
||||
25
openbao/auth/secrets-engine-jwt-role.json
Normal file
25
openbao/auth/secrets-engine-jwt-role.json
Normal file
|
|
@ -0,0 +1,25 @@
|
|||
{
|
||||
"role_type": "jwt",
|
||||
"user_claim": "sub",
|
||||
"bound_audiences": [
|
||||
"secrets-engine-openbao"
|
||||
],
|
||||
"bound_subject": "service:secrets-engine",
|
||||
"bound_claims_type": "string",
|
||||
"bound_claims": {
|
||||
"principal_type": "service",
|
||||
"tenant": "tenant:platform",
|
||||
"roles": "secrets-engine",
|
||||
"scope": "openbao:login"
|
||||
},
|
||||
"token_policies": [
|
||||
"secrets-engine-login-self"
|
||||
],
|
||||
"token_no_default_policy": true,
|
||||
"token_type": "service",
|
||||
"token_ttl": "5m",
|
||||
"token_max_ttl": "5m",
|
||||
"token_explicit_max_ttl": "5m",
|
||||
"token_num_uses": 8,
|
||||
"verbose_oidc_logging": false
|
||||
}
|
||||
10
openbao/policies/secrets-engine-login-self.hcl
Normal file
10
openbao/policies/secrets-engine-login-self.hcl
Normal file
|
|
@ -0,0 +1,10 @@
|
|||
# RPF-WP-0035-T02: proposed login-only service policy; not a lane applier.
|
||||
path "auth/token/lookup-self" {
|
||||
capabilities = ["read"]
|
||||
}
|
||||
path "sys/capabilities-self" {
|
||||
capabilities = ["update"]
|
||||
}
|
||||
path "auth/token/revoke-self" {
|
||||
capabilities = ["update"]
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue