Bind platform OpenBao service identity to tenant zero
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
cbe218b26a
commit
f0d82908e9
6 changed files with 35 additions and 17 deletions
|
|
@ -331,7 +331,7 @@ Acceptance:
|
|||
```task
|
||||
id: SECRETS-WP-0008-T06
|
||||
status: wait
|
||||
blocking_reason: "RPF-WP-0035-T02 still awaits exact service claims/tenant, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption."
|
||||
blocking_reason: "RPF-WP-0035-T02 awaits coordinated platform-tenant live registration, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption."
|
||||
priority: medium
|
||||
state_hub_task_id: "d7bc8bdc-a0f8-5058-a640-374ef9859148"
|
||||
```
|
||||
|
|
@ -354,12 +354,13 @@ Designed: role/audience `secrets-engine-openbao`, subject
|
|||
budget, login-only. KeyCape issuer `https://kc.coulomb.social` and its JWKS are
|
||||
now confirmed live, so the remaining blocker is this registration's issued
|
||||
claims, consumer readiness, an approved source and attended apply authority.
|
||||
**Open question for secrets-engine, not answered in the triage session:** the
|
||||
JWT design says `tenant:coulomb`, while the approval chain resolved to
|
||||
`tenant:platform` (decision `5ed3fb35`) and approval-engine compares tenant by
|
||||
exact string. Which tenant the OpenBao service identity carries is a design
|
||||
decision for an owner session; platform will correct its design before the
|
||||
role exists once told. A service login grants no lane mutation authority. Companion §7 / statute §3.4: an
|
||||
**Resolved by the operator, 2026-09-27:** OpenBao is platform infrastructure,
|
||||
belonging to tenant zero, `tenant:platform`. Coulomb is a workload tenant;
|
||||
its DNS domain does not own the platform. The former matching Coulomb claims
|
||||
were incorrect. KeyCape registrations, platform JWT roles and this consumer's
|
||||
strict preflight are corrected together in source. Live registration/custody,
|
||||
coordinated deployment and native refusal/revocation proof remain T06.
|
||||
A service login grants no lane mutation authority. Companion §7 / statute §3.4: an
|
||||
agent holds no long-lived credential of its own. Authority is per task,
|
||||
time-bounded, and attributable to the principal it acts for.
|
||||
|
||||
|
|
@ -511,6 +512,17 @@ refuses nested/identity-bearing version pins and names the accepted text and
|
|||
rulings on every run, including PASS. Declaration spellings are unchanged.
|
||||
|
||||
T06 remains wait: railiance-platform's RPF-WP-0035-T02 still records an
|
||||
unprovisioned, login-only JWT role, pending exact service claims/tenant and
|
||||
unprovisioned, login-only JWT role, pending platform-tenant live registration and
|
||||
custody/attended admission. The existing env-auth native receipt cannot prove
|
||||
steady-state service JWT login. This is the only remaining task in this workplan.
|
||||
|
||||
### 2026-09-27 platform essentials follow-up
|
||||
|
||||
Operator tenant-zero decision `be5287cb-d458-47bc-9183-2a40dd7ae04b` corrects
|
||||
OpenBao infrastructure identities to `tenant:platform`. Source changes are
|
||||
coordinated in KeyCape, railiance-platform and Secrets Engine. The platform
|
||||
owner records the bounded essentials review in
|
||||
`docs/platform-tenant-essentials-review.md`. T06 remains wait for coordinated
|
||||
live registration/custody, provisioning and native refusal/revocation evidence.
|
||||
No new task or workplan was created. Warden's npm no-rotation hold remains;
|
||||
factory records now consume the completed generic approval and companion returns.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue