Answers the-custodian 641673a4. An attended read-only check (receipt docs/evidence/2026-09-23-openbao-platform-admin-check.json) found: - live platform-admin policy = repo file + reins/* (ops-mason, 2026-07-27); repo now matches live (sha256 0ca5b821...). No live write. - role also attaches operator-custody (undeclared); declared here. - role declared as openbao/auth/netkingdom-platform-admin-role.json. - default policy is attached and grants revoke-self/lookup-self, so the suspected missing grant is not the cause of warden's unconfirmed revocation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 150322@bnt-lap001 Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
47 lines
1.1 KiB
JSON
47 lines
1.1 KiB
JSON
{
|
|
"allowed_redirect_uris": [
|
|
"http://localhost:8250/oidc/callback",
|
|
"http://127.0.0.1:8250/oidc/callback",
|
|
"https://bao.coulomb.social/ui/vault/auth/netkingdom/oidc/callback",
|
|
"https://bao.coulomb.social/ui/vault/auth/keycape/oidc/callback",
|
|
"http://127.0.0.1:18200/ui/vault/auth/netkingdom/oidc/callback"
|
|
],
|
|
"bound_audiences": [],
|
|
"bound_claims": {
|
|
"groups": [
|
|
"net-kingdom-admins"
|
|
]
|
|
},
|
|
"bound_claims_type": "string",
|
|
"bound_subject": "",
|
|
"claim_mappings": {
|
|
"email": "email",
|
|
"preferred_username": "username"
|
|
},
|
|
"groups_claim": "groups",
|
|
"oidc_scopes": [
|
|
"openid",
|
|
"profile",
|
|
"email",
|
|
"groups"
|
|
],
|
|
"policies": [
|
|
"platform-admin",
|
|
"operator-custody"
|
|
],
|
|
"role_type": "oidc",
|
|
"token_bound_cidrs": [],
|
|
"token_explicit_max_ttl": 0,
|
|
"token_max_ttl": 0,
|
|
"token_no_default_policy": false,
|
|
"token_num_uses": 0,
|
|
"token_period": 0,
|
|
"token_policies": [
|
|
"platform-admin",
|
|
"operator-custody"
|
|
],
|
|
"token_ttl": 3600,
|
|
"token_type": "default",
|
|
"ttl": 3600,
|
|
"user_claim": "sub"
|
|
}
|