Close warden-sign token lane

This commit is contained in:
tegwick 2026-06-30 01:01:55 +02:00
parent 52e850f26b
commit e0ab1b8420
3 changed files with 64 additions and 14 deletions

View file

@ -4,11 +4,11 @@ type: workplan
title: "Provision a scoped warden-sign token lane (ops-warden / FLEX-WP-0007 T4)"
domain: infotech
repo: secrets-engine
status: active
status: finished
owner: codex
topic_slug: custodian
created: "2026-06-29"
updated: "2026-06-29"
updated: "2026-06-30"
state_hub_workstream_id: "eb1bdff7-909c-4391-8b95-6baf1feb3a54"
---
@ -23,7 +23,8 @@ narrow capability), not a KV value. Post the non-secret pointers to State Hub an
hand the token/secret_id to the operator out-of-band.
This unblocks FLEX-WP-0007 T4 (the joint OpenBao + policy-gate production smoke),
after which `policy.enabled: true` can go live on CoulombCore.
after which the verified gate can be banked until `policy.enabled: true`
is appropriate for the ecosystem maturity stage.
## Context
@ -113,7 +114,7 @@ Acceptance:
```task
id: SECRETS-WP-0004-T03
status: wait
status: done
priority: high
state_hub_task_id: "4b414788-d670-496b-9c57-074464a012c4"
```
@ -136,9 +137,18 @@ missing lane decision or the documented bootstrap handoff.
2026-06-30: Approval mirror `.decisions/SECRETS-WP-0004.yaml` is now present
and `secrets-engine route warden-sign --json` reports `decision_status:
resolved` for canonical decision `4589dcb7-c0df-4073-9a0b-4f80a0fcdb93`.
Readiness remains false because the OpenBao `warden-sign` policy/AppRole has
not been applied (`metadata_applied: false`), and the documented lane bootstrap
token file is still absent. Live apply and handoff were not executed.
Readiness remained false at that checkpoint because the OpenBao `warden-sign`
policy/AppRole had not yet been applied (`metadata_applied: false`), and the
documented lane bootstrap token file was still absent. Live apply and handoff
were not executed in that checkpoint.
2026-06-30 closeout: ops-warden later reported that production OpenBao was
unsealed, the secrets-engine `warden-sign` lane was applied, and a scoped
AppRole token with `ssh/sign/agt-role` update capability was verified through
the vault-backed smoke. No token value, role_id, secret_id, token accessor, or
raw smoke log is recorded here. The documented bootstrap-token file path remains
part of the hardening/audit backlog, but live lane metadata is no longer the
blocker.
Apply the policy + AppRole on `https://bao.coulomb.social` using a mode-0600
bootstrap token stored outside any repo. Idempotent re-apply.
@ -154,7 +164,7 @@ Acceptance:
```task
id: SECRETS-WP-0004-T04
status: wait
status: done
priority: high
state_hub_task_id: "52b5cf88-029f-4f4b-8fe9-0a8dc30378b5"
```
@ -186,6 +196,13 @@ so handoff is waiting on live OpenBao apply plus an attended, out-of-band
bootstrap path. No `role_id`, `secret_id`, token value, token accessor, or
smoke output was written to Git or State Hub.
2026-06-30 closeout: the scoped warden-sign handoff path was exercised by the
operator/ops-warden outside Git and State Hub. The only recorded evidence is the
non-secret result: the vault-backed smoke used backend `vault` and policy
decision `decision:032b096c433ad80c`. `policy.enabled` is intentionally left off
until testing/production maturity; that is a separate operator posture decision,
not an unfinished secrets-engine handoff.
Define and execute the handoff: mint a fresh `secret_id`, deliver it (with the
`role_id`) to the operator out-of-band; warden does `approle login` to obtain a
`VAULT_TOKEN`. Post the non-secret pointers on the ops-warden thread (policy name,
@ -202,14 +219,22 @@ Acceptance:
```task
id: SECRETS-WP-0004-T05
status: wait
status: done
priority: medium
state_hub_task_id: "aa0f281e-976d-4fcd-b8a3-78582117f86f"
```
2026-06-29: Offline tests pass (`59 passed, 2 skipped`) and route/dry-run CLI
checks produce non-secret pointers. Joint production smoke and ops-warden signal
remain waiting on live OpenBao apply, handoff, and operator-run smoke evidence.
remained waiting on live OpenBao apply, handoff, and operator-run smoke evidence
at that checkpoint.
2026-06-30 closeout: ops-warden reported the joint smoke passed with non-secret
evidence only: allow path `warden sign agt-state-hub-bridge` returned
policy_decision_id `decision:032b096c433ad80c`, excessive TTL `--ttl 999` was
rejected with `ttl_out_of_bounds` before OpenBao, and the vault-backed allow path
used the scoped warden-sign lane. flex-auth closed `FLEX-WP-0007-T04` from this
evidence, so secrets-engine can close the credential/capability lane too.
Confirm the unblock end to end, then reply to ops-warden (msg 077ac90d) with the
pointers and runbook alignment. The reply is the explicit "we will signal
@ -231,3 +256,16 @@ Acceptance:
external condition).
- ops-warden has the non-secret pointers; no secret value crossed State Hub.
- The bootstrap token and the minted credential have revocation tasks.
## Closeout Evidence
2026-06-30: SECRETS-WP-0004 is finished from the same non-secret smoke evidence
used to close `FLEX-WP-0007-T04`:
- `warden-sign` policy/AppRole lane applied in production OpenBao after operator unseal.
- Scoped token capability verified for `ssh/sign/agt-role` update during the vault-backed smoke.
- Allow smoke: `warden sign agt-state-hub-bridge` -> `decision:032b096c433ad80c`.
- Deny smoke: `--ttl 999` -> `ttl_out_of_bounds` before OpenBao signing.
- No raw token, AppRole `secret_id`, `role_id`, token accessor, or smoke log was written to Git, State Hub, prompts, chat, or normal logs.
- `policy.enabled` remains off by build-stage maturity decision and can be flipped later by the ops-warden operator when testing/production posture requires live enforcement.