feat: add auth-capability lanes and pilot closeout

Add the warden-sign auth-capability lane, AppRole handoff, verification guards, docs, and tests.

Point the whynot-design pilot at the canonical decision and add the real publish closeout preflight/runbook.
This commit is contained in:
tegwick 2026-06-29 16:58:16 +02:00
parent a621fbaffd
commit 6382139890
27 changed files with 1455 additions and 107 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Provision a scoped warden-sign token lane (ops-warden / FLEX-WP-0007 T4)"
domain: infotech
repo: secrets-engine
status: proposed
status: active
owner: codex
topic_slug: custodian
created: "2026-06-29"
@ -59,11 +59,15 @@ OpenBao, so it also exercises parts of the engine the npm pilot did not.
```task
id: SECRETS-WP-0004-T01
status: todo
status: done
priority: high
state_hub_task_id: "278e9a20-eaa6-47a8-9dd7-62952961d520"
```
2026-06-29: Implemented `kind: auth-capability` catalog support, fieldless
non-KV validation, KV provisioning bypass/rejection, route semantics, and dry-run
plan/apply handling while preserving the existing KV/npm lane behavior.
Add a lane kind that represents an OpenBao auth credential (AppRole + policy)
granting a capability on a mount, rather than a KV value. The current schema
assumes a KV `mount/path/fields` value and `provision --from-file`; an
@ -81,11 +85,17 @@ Acceptance:
```task
id: SECRETS-WP-0004-T02
status: todo
status: done
priority: high
state_hub_task_id: "f4b209e5-c900-4f5e-bb0c-f0c5b27b70c2"
```
2026-06-29: Added `catalog/warden-sign.yaml`, exact `warden-sign` policy/AppRole
planning, guard coverage rejecting broad `ssh/*`, `sys/`, `auth/token/`,
`identity/`, wildcard, root-like, and non-`update` grants, plus tests for the
allowlist and denial probes. Production stage policy now has exact
`warden-sign` policy/AppRole management exceptions only.
Author the `warden-sign` ACL policy and AppRole. Policy: `update` on
`ssh/sign/agt-role` (plus `adm-role`, `atm-role`) on the `ssh` mount; nothing
else. AppRole `warden-sign` bound to that policy with a short token TTL, usable
@ -103,11 +113,16 @@ Acceptance:
```task
id: SECRETS-WP-0004-T03
status: todo
status: wait
priority: high
state_hub_task_id: "4b414788-d670-496b-9c57-074464a012c4"
```
2026-06-29: Source apply path is implemented and dry-run verified. Live apply is
waiting on an approved SECRETS-WP-0004 decision/workplan gate plus a mode-0600
production bootstrap token outside any repo. The pending token path/revocation
row is recorded in `docs/hardening-backlog.md` H0.
Apply the policy + AppRole on `https://bao.coulomb.social` using a mode-0600
bootstrap token stored outside any repo. Idempotent re-apply.
@ -122,11 +137,17 @@ Acceptance:
```task
id: SECRETS-WP-0004-T04
status: todo
status: wait
priority: high
state_hub_task_id: "52b5cf88-029f-4f4b-8fe9-0a8dc30378b5"
```
2026-06-29: Added `secrets-engine handoff` and
`docs/warden-sign-auth-capability.md`. Handoff writes `role_id` and a fresh
single-use `secret_id` to caller-chosen mode-0600 files outside Git worktrees and
records only non-secret file paths/TTL metadata. Execution is waiting on live
apply and attended out-of-band operator delivery.
Define and execute the handoff: mint a fresh `secret_id`, deliver it (with the
`role_id`) to the operator out-of-band; warden does `approle login` to obtain a
`VAULT_TOKEN`. Post the non-secret pointers on the ops-warden thread (policy name,
@ -143,11 +164,15 @@ Acceptance:
```task
id: SECRETS-WP-0004-T05
status: todo
status: wait
priority: medium
state_hub_task_id: "aa0f281e-976d-4fcd-b8a3-78582117f86f"
```
2026-06-29: Offline tests pass (`59 passed, 2 skipped`) and route/dry-run CLI
checks produce non-secret pointers. Joint production smoke and ops-warden signal
remain waiting on live OpenBao apply, handoff, and operator-run smoke evidence.
Confirm the unblock end to end, then reply to ops-warden (msg 077ac90d) with the
pointers and runbook alignment. The reply is the explicit "we will signal
ops-warden when done" step.