Bind platform OpenBao service identity to tenant zero
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:43:31 +02:00
parent cbe218b26a
commit f0d82908e9
6 changed files with 35 additions and 17 deletions

View file

@ -6,7 +6,7 @@ secrets-engine now implements the consumer half of KeyCape's accepted
the non-cryptographic contract before any future OpenBao login:
- subject `service:secrets-engine`, audience/client `secrets-engine-openbao`;
- service principal in `tenant:coulomb`, role `secrets-engine`;
- service principal in `tenant:platform` (platform infrastructure, tenant zero), role `secrets-engine`;
- exact `openbao:login` scope and KeyCape AAL1 client-secret assurance;
- RS256 declaration, bounded issue/expiry timestamps, maximum 15-minute life,
and renewal when no more than three minutes remain;