Bind platform OpenBao service identity to tenant zero
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
cbe218b26a
commit
f0d82908e9
6 changed files with 35 additions and 17 deletions
|
|
@ -6,7 +6,7 @@ secrets-engine now implements the consumer half of KeyCape's accepted
|
|||
the non-cryptographic contract before any future OpenBao login:
|
||||
|
||||
- subject `service:secrets-engine`, audience/client `secrets-engine-openbao`;
|
||||
- service principal in `tenant:coulomb`, role `secrets-engine`;
|
||||
- service principal in `tenant:platform` (platform infrastructure, tenant zero), role `secrets-engine`;
|
||||
- exact `openbao:login` scope and KeyCape AAL1 client-secret assurance;
|
||||
- RS256 declaration, bounded issue/expiry timestamps, maximum 15-minute life,
|
||||
and renewal when no more than three minutes remain;
|
||||
|
|
|
|||
|
|
@ -1,3 +1,10 @@
|
|||
> Superseded source finding, 2026-09-27: the operator confirmed that OpenBao
|
||||
> and its infrastructure service identities belong to `tenant:platform` (tenant
|
||||
> zero). Coulomb is a workload tenant. The former `service_auth.TENANT` value
|
||||
> discussed below is historical; source preflight now requires platform and
|
||||
> rejects Coulomb. Live migration remains SECRETS-WP-0008-T06. See the platform
|
||||
> owner's `docs/platform-tenant-essentials-review.md` for the cross-repo review.
|
||||
|
||||
# Tenant alignment
|
||||
|
||||
Answer to the `GLAS-WP-0015` production-dependency handoff question, which asked
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue