railiance-platform/docs/platform-tenant-essentials-review.md
codex 5781d34b3b
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Prepare tenant-zero OpenBao roles and review platform essentials
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
2026-09-27 16:43:32 +02:00

4.1 KiB

Platform essentials tenant review — 2026-09-27

Operator requirement: tenant:platform is tenant zero for platform infrastructure. tenant:coulomb is a workload/product tenant. The shared coulomb.social DNS suffix does not establish tenant ownership. Provider ownership, caller identity, resource tenant and enforcement capability are separate facts.

Essential / boundary Source reviewed Result and action
OpenBao custody/provider tenancy.yaml, docs/tenancy-posture.md, openbao/auth/ Platform-owned. Correct both infrastructure JWT roles to platform; retain exact audience/subject/scope and bounded policies.
Platform coding agent KeyCape service registration; coding-agent-jwt-role.json Incorrect Coulomb claim corrected in both source owners. Existing workload read policy remains explicit; changing identity tenant grants no additional data access.
Secrets Engine service login KeyCape registration; consumer service_auth.py; proposed service role Incorrect Coulomb claim corrected together to platform. Login-only self policy; no lane mutation privilege.
Approval / informed decision / policy checks KeyCape registrations; Secrets Engine approval and authorization profiles Already platform-bound. Keep exact tenant comparison, distinct audiences/scopes and human controls.
Audit senders docs/credential-lane-designs/factory-audit-senders-review.md; Audit Core tenancy declaration Factory senders already restricted to platform. Provider ownership does not relabel historical events or consumer tenants.
KeyCape human directory fallback KeyCape token.go, tenant claim contract Still legacy tenant:coulomb when directory tenant is missing. Do not change the default to platform: that would implicitly elevate unclassified users. Explicit platform registration/directory binding remains necessary.
Shared PostgreSQL / Forgejo database tenancy.yaml, docs/tenancy-posture.md, rapp-postgres declarations Platform provider ownership; consumers retain their databases and workload isolation. No tenant claim is implemented at the substrate by these declarations.
OpenBao package rapp-openbao YAML/JSON source review No runtime tenant claim found in package declarations; package ownership and the auth role bindings above must not be inferred from ingress DNS. Absence of a claim is not live verification.
Warden / Forgejo Warden tenancy declaration; Forgejo YAML/JSON source review Infrastructure belongs to platform. SSH, package and workload grants retain their explicit identities; do not replace Coulomb organization or KV path components with platform.

This is a bounded source review of the existing credential-chain dependencies, not a claim that every platform deployment has been audited. No live tenant migration, token issuance, value read or workload relocation was performed. The existing RPF-WP-0035-T02 owns the coordinated service-login return; existing KEY-WP-0009 contract and SECRETS-WP-0008-T06 carry provider/consumer changes. No new work item is opened.

Deployment and acceptance

  1. Inventory exact live KeyCape registrations and OpenBao mount/roles using metadata-only, attended authority. Source files are not live-state receipts.
  2. Compare issuer, audience, subject, tenant, policies and aliases. Preserve workload grants; do not introduce a tenant alias or accept both tenants.
  3. Coordinate issuance and verifier/consumer deployment. Old Coulomb-bound platform JWTs must fail; new platform-bound JWTs must succeed. Rollback is an explicit coordinated restoration, never a fallback to another identity.
  4. Already-issued OpenBao tokens do not change tenant/policies when a JWT role changes. Revoke affected tokens under owner custody and verify denial. Bound the remaining JWT and token lifetimes; retain only non-secret results.
  5. Prove wrong-tenant/audience/subject/scope refusal, exact effective policies, expiry/use limits and self-revocation before publishing the consumer contract.

Tenant ownership does not raise the historical I/A/E/R/V posture scores. The posture records describe demonstrated isolation/recovery, not the owner tenant.