Bind platform OpenBao service identity to tenant zero
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
cbe218b26a
commit
f0d82908e9
6 changed files with 35 additions and 17 deletions
|
|
@ -6,7 +6,7 @@ secrets-engine now implements the consumer half of KeyCape's accepted
|
|||
the non-cryptographic contract before any future OpenBao login:
|
||||
|
||||
- subject `service:secrets-engine`, audience/client `secrets-engine-openbao`;
|
||||
- service principal in `tenant:coulomb`, role `secrets-engine`;
|
||||
- service principal in `tenant:platform` (platform infrastructure, tenant zero), role `secrets-engine`;
|
||||
- exact `openbao:login` scope and KeyCape AAL1 client-secret assurance;
|
||||
- RS256 declaration, bounded issue/expiry timestamps, maximum 15-minute life,
|
||||
and renewal when no more than three minutes remain;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue