Add named engine auth and accessor-file session revoke
Select service-jwt, bootstrap, or env exclusively: JWT login uses a JSON file, self-revokes, and never falls back to bootstrap or BAO_TOKEN. The platform JWT mount/role is still unpublished, so auto keeps named bootstrap/env providers. session revoke --accessor-file revokes an already-issued token with fingerprint-only evidence. Production remains fail-closed. Assistant: grok Assistant-Session: 01a05f07-ae72-7781-9fcb-19efd61add00
This commit is contained in:
parent
a94003de4f
commit
3abee434df
18 changed files with 698 additions and 135 deletions
|
|
@ -1,6 +1,6 @@
|
|||
"""Runtime configuration resolved from environment and repo layout.
|
||||
|
||||
Nothing here is a secret. Backend auth (BAO_TOKEN / bootstrap token files) is
|
||||
Nothing here is a secret. Backend auth (named providers in engine_auth) is
|
||||
resolved lazily inside the backend adapter, never cached on disk by this module.
|
||||
"""
|
||||
from __future__ import annotations
|
||||
|
|
@ -29,11 +29,17 @@ class Config:
|
|||
topic_id: str
|
||||
approval_url: str = ""
|
||||
approval_token_file: Path | None = None
|
||||
keycape_token_url: str = ""
|
||||
keycape_issuer: str = ""
|
||||
keycape_client_secret_file: Path | None = None
|
||||
openbao_jwt_login_file: Path | None = None
|
||||
|
||||
@classmethod
|
||||
def load(cls) -> "Config":
|
||||
root = repo_root()
|
||||
token_file = os.environ.get("SECRETS_ENGINE_APPROVAL_TOKEN_FILE", "")
|
||||
keycape_secret = os.environ.get("SECRETS_ENGINE_KEYCAPE_CLIENT_SECRET_FILE", "")
|
||||
jwt_login = os.environ.get("SECRETS_ENGINE_OPENBAO_JWT_LOGIN", "")
|
||||
return cls(
|
||||
catalog_dir=Path(os.environ.get("SECRETS_ENGINE_CATALOG", root / "catalog")),
|
||||
policy_dir=Path(os.environ.get("SECRETS_ENGINE_POLICIES", root / "policies")),
|
||||
|
|
@ -45,4 +51,8 @@ class Config:
|
|||
),
|
||||
approval_url=os.environ.get("SECRETS_ENGINE_APPROVAL_URL", ""),
|
||||
approval_token_file=Path(token_file) if token_file else None,
|
||||
keycape_token_url=os.environ.get("SECRETS_ENGINE_KEYCAPE_TOKEN_URL", ""),
|
||||
keycape_issuer=os.environ.get("SECRETS_ENGINE_KEYCAPE_ISSUER", ""),
|
||||
keycape_client_secret_file=Path(keycape_secret) if keycape_secret else None,
|
||||
openbao_jwt_login_file=Path(jwt_login) if jwt_login else None,
|
||||
)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue