Add response-wrapped operator handoff
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

secrets-engine wrap writes a single-use OpenBao wrap token to a mode-0600
out-of-repo file and never prints it. KV reads and AppRole secret_ids are
wrapped with a 15m TTL cap. Unwrapped secret payloads fail closed.
Production wrap remains fail-closed.

Assistant: grok
Assistant-Session: 01a05f07-ae72-7781-9fcb-19efd61add00
This commit is contained in:
tegwick 2026-09-02 08:12:42 +02:00
parent 2278cefbb3
commit afd1c8e593
12 changed files with 387 additions and 8 deletions

View file

@ -46,8 +46,12 @@ contents in this repo.
## H2 — Response-wrapped handoff
- Add a `wrapped` delivery mode using OpenBao response wrapping for operator
handoff flows where exec-time injection does not fit.
- Implemented: `secrets-engine wrap <catalog-id> --out F [--ttl 15m]` writes a
single-use wrap token to a mode-0600 out-of-repo file. KV lanes wrap a read;
auth-capability lanes wrap a secret_id. The wrap token is never printed.
Evidence is wrap-handle fingerprint, ttl, and path only. TTL max 15m.
Unwrapped secret payloads fail closed. Production remains fail-closed.
- `exec --mode wrapped` is still not an exec adapter; this is operator handoff.
## H3 — Production dual-control