Add response-wrapped operator handoff
secrets-engine wrap writes a single-use OpenBao wrap token to a mode-0600 out-of-repo file and never prints it. KV reads and AppRole secret_ids are wrapped with a 15m TTL cap. Unwrapped secret payloads fail closed. Production wrap remains fail-closed. Assistant: grok Assistant-Session: 01a05f07-ae72-7781-9fcb-19efd61add00
This commit is contained in:
parent
2278cefbb3
commit
afd1c8e593
12 changed files with 387 additions and 8 deletions
|
|
@ -46,8 +46,12 @@ contents in this repo.
|
|||
|
||||
## H2 — Response-wrapped handoff
|
||||
|
||||
- Add a `wrapped` delivery mode using OpenBao response wrapping for operator
|
||||
handoff flows where exec-time injection does not fit.
|
||||
- Implemented: `secrets-engine wrap <catalog-id> --out F [--ttl 15m]` writes a
|
||||
single-use wrap token to a mode-0600 out-of-repo file. KV lanes wrap a read;
|
||||
auth-capability lanes wrap a secret_id. The wrap token is never printed.
|
||||
Evidence is wrap-handle fingerprint, ttl, and path only. TTL max 15m.
|
||||
Unwrapped secret payloads fail closed. Production remains fail-closed.
|
||||
- `exec --mode wrapped` is still not an exec adapter; this is operator handoff.
|
||||
|
||||
## H3 — Production dual-control
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue