Bind platform OpenBao service identity to tenant zero
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:43:31 +02:00
parent cbe218b26a
commit f0d82908e9
6 changed files with 35 additions and 17 deletions

View file

@ -36,11 +36,9 @@ DIGEST_RE = re.compile(r"^sha256:[0-9a-f]{64}$")
#: the vendored replay fixtures in ``tests/test_decision_replay.py`` instead of
#: being left to a deployment to supply correctly.
#:
#: This is not the KeyCape JWT tenant. ``service_auth.TENANT`` is
#: ``tenant:coulomb``, which is the exact value this package denies. Whether
#: those name one tenant or two layers is an open owner question -- see
#: ``docs/tenant-alignment.md`` -- and is deliberately not resolved by reusing
#: one constant for both.
#: Operator clarification, 2026-09-27: the platform infrastructure identity
#: also belongs to tenant:platform. Keep audience-specific profile validation;
#: matching tenant strings do not grant cross-audience or workload authority.
REQUEST_TENANT = "tenant:platform"
SCHEMA_VERSION = "0.1"

View file

@ -1,7 +1,7 @@
"""KeyCape service-JWT exchange shared by two separately validated profiles.
The OpenBao login profile and approval consumer profile have distinct clients,
audiences, tenants and scopes. Provider selection never falls back to another
audiences and scopes; both belong to tenant:platform. Provider selection never falls back to another
identity. Token parsing is a claim preflight, not signature verification: the
receiving OpenBao or approval-engine service verifies RS256 before accepting it.
"""
@ -24,7 +24,7 @@ from secrets_engine.openbao import read_strict_token_file
CLIENT_ID = "secrets-engine-openbao"
SUBJECT = "service:secrets-engine"
PRINCIPAL_TYPE = "service"
TENANT = "tenant:coulomb"
TENANT = "tenant:platform"
ROLE = "secrets-engine"
SCOPE = "openbao:login"
MAX_TOKEN_SECONDS = 15 * 60