feat: add auth-capability lanes and pilot closeout
Add the warden-sign auth-capability lane, AppRole handoff, verification guards, docs, and tests. Point the whynot-design pilot at the canonical decision and add the real publish closeout preflight/runbook.
This commit is contained in:
parent
a621fbaffd
commit
6382139890
27 changed files with 1455 additions and 107 deletions
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Provision a scoped warden-sign token lane (ops-warden / FLEX-WP-0007 T4)"
|
||||
domain: infotech
|
||||
repo: secrets-engine
|
||||
status: proposed
|
||||
status: active
|
||||
owner: codex
|
||||
topic_slug: custodian
|
||||
created: "2026-06-29"
|
||||
|
|
@ -59,11 +59,15 @@ OpenBao, so it also exercises parts of the engine the npm pilot did not.
|
|||
|
||||
```task
|
||||
id: SECRETS-WP-0004-T01
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "278e9a20-eaa6-47a8-9dd7-62952961d520"
|
||||
```
|
||||
|
||||
2026-06-29: Implemented `kind: auth-capability` catalog support, fieldless
|
||||
non-KV validation, KV provisioning bypass/rejection, route semantics, and dry-run
|
||||
plan/apply handling while preserving the existing KV/npm lane behavior.
|
||||
|
||||
Add a lane kind that represents an OpenBao auth credential (AppRole + policy)
|
||||
granting a capability on a mount, rather than a KV value. The current schema
|
||||
assumes a KV `mount/path/fields` value and `provision --from-file`; an
|
||||
|
|
@ -81,11 +85,17 @@ Acceptance:
|
|||
|
||||
```task
|
||||
id: SECRETS-WP-0004-T02
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "f4b209e5-c900-4f5e-bb0c-f0c5b27b70c2"
|
||||
```
|
||||
|
||||
2026-06-29: Added `catalog/warden-sign.yaml`, exact `warden-sign` policy/AppRole
|
||||
planning, guard coverage rejecting broad `ssh/*`, `sys/`, `auth/token/`,
|
||||
`identity/`, wildcard, root-like, and non-`update` grants, plus tests for the
|
||||
allowlist and denial probes. Production stage policy now has exact
|
||||
`warden-sign` policy/AppRole management exceptions only.
|
||||
|
||||
Author the `warden-sign` ACL policy and AppRole. Policy: `update` on
|
||||
`ssh/sign/agt-role` (plus `adm-role`, `atm-role`) on the `ssh` mount; nothing
|
||||
else. AppRole `warden-sign` bound to that policy with a short token TTL, usable
|
||||
|
|
@ -103,11 +113,16 @@ Acceptance:
|
|||
|
||||
```task
|
||||
id: SECRETS-WP-0004-T03
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "4b414788-d670-496b-9c57-074464a012c4"
|
||||
```
|
||||
|
||||
2026-06-29: Source apply path is implemented and dry-run verified. Live apply is
|
||||
waiting on an approved SECRETS-WP-0004 decision/workplan gate plus a mode-0600
|
||||
production bootstrap token outside any repo. The pending token path/revocation
|
||||
row is recorded in `docs/hardening-backlog.md` H0.
|
||||
|
||||
Apply the policy + AppRole on `https://bao.coulomb.social` using a mode-0600
|
||||
bootstrap token stored outside any repo. Idempotent re-apply.
|
||||
|
||||
|
|
@ -122,11 +137,17 @@ Acceptance:
|
|||
|
||||
```task
|
||||
id: SECRETS-WP-0004-T04
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "52b5cf88-029f-4f4b-8fe9-0a8dc30378b5"
|
||||
```
|
||||
|
||||
2026-06-29: Added `secrets-engine handoff` and
|
||||
`docs/warden-sign-auth-capability.md`. Handoff writes `role_id` and a fresh
|
||||
single-use `secret_id` to caller-chosen mode-0600 files outside Git worktrees and
|
||||
records only non-secret file paths/TTL metadata. Execution is waiting on live
|
||||
apply and attended out-of-band operator delivery.
|
||||
|
||||
Define and execute the handoff: mint a fresh `secret_id`, deliver it (with the
|
||||
`role_id`) to the operator out-of-band; warden does `approle login` to obtain a
|
||||
`VAULT_TOKEN`. Post the non-secret pointers on the ops-warden thread (policy name,
|
||||
|
|
@ -143,11 +164,15 @@ Acceptance:
|
|||
|
||||
```task
|
||||
id: SECRETS-WP-0004-T05
|
||||
status: todo
|
||||
status: wait
|
||||
priority: medium
|
||||
state_hub_task_id: "aa0f281e-976d-4fcd-b8a3-78582117f86f"
|
||||
```
|
||||
|
||||
2026-06-29: Offline tests pass (`59 passed, 2 skipped`) and route/dry-run CLI
|
||||
checks produce non-secret pointers. Joint production smoke and ops-warden signal
|
||||
remain waiting on live OpenBao apply, handoff, and operator-run smoke evidence.
|
||||
|
||||
Confirm the unblock end to end, then reply to ops-warden (msg 077ac90d) with the
|
||||
pointers and runbook alignment. The reply is the explicit "we will signal
|
||||
ops-warden when done" step.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue