Bind platform OpenBao service identity to tenant zero
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:43:31 +02:00
parent cbe218b26a
commit f0d82908e9
6 changed files with 35 additions and 17 deletions

View file

@ -331,7 +331,7 @@ Acceptance:
```task
id: SECRETS-WP-0008-T06
status: wait
blocking_reason: "RPF-WP-0035-T02 still awaits exact service claims/tenant, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption."
blocking_reason: "RPF-WP-0035-T02 awaits coordinated platform-tenant live registration, credential custody and scoped attended JWT role provisioning with native login/negative/revocation proof. The historical env-auth acceptance is not service-JWT adoption."
priority: medium
state_hub_task_id: "d7bc8bdc-a0f8-5058-a640-374ef9859148"
```
@ -354,12 +354,13 @@ Designed: role/audience `secrets-engine-openbao`, subject
budget, login-only. KeyCape issuer `https://kc.coulomb.social` and its JWKS are
now confirmed live, so the remaining blocker is this registration's issued
claims, consumer readiness, an approved source and attended apply authority.
**Open question for secrets-engine, not answered in the triage session:** the
JWT design says `tenant:coulomb`, while the approval chain resolved to
`tenant:platform` (decision `5ed3fb35`) and approval-engine compares tenant by
exact string. Which tenant the OpenBao service identity carries is a design
decision for an owner session; platform will correct its design before the
role exists once told. A service login grants no lane mutation authority. Companion §7 / statute §3.4: an
**Resolved by the operator, 2026-09-27:** OpenBao is platform infrastructure,
belonging to tenant zero, `tenant:platform`. Coulomb is a workload tenant;
its DNS domain does not own the platform. The former matching Coulomb claims
were incorrect. KeyCape registrations, platform JWT roles and this consumer's
strict preflight are corrected together in source. Live registration/custody,
coordinated deployment and native refusal/revocation proof remain T06.
A service login grants no lane mutation authority. Companion §7 / statute §3.4: an
agent holds no long-lived credential of its own. Authority is per task,
time-bounded, and attributable to the principal it acts for.
@ -511,6 +512,17 @@ refuses nested/identity-bearing version pins and names the accepted text and
rulings on every run, including PASS. Declaration spellings are unchanged.
T06 remains wait: railiance-platform's RPF-WP-0035-T02 still records an
unprovisioned, login-only JWT role, pending exact service claims/tenant and
unprovisioned, login-only JWT role, pending platform-tenant live registration and
custody/attended admission. The existing env-auth native receipt cannot prove
steady-state service JWT login. This is the only remaining task in this workplan.
### 2026-09-27 platform essentials follow-up
Operator tenant-zero decision `be5287cb-d458-47bc-9183-2a40dd7ae04b` corrects
OpenBao infrastructure identities to `tenant:platform`. Source changes are
coordinated in KeyCape, railiance-platform and Secrets Engine. The platform
owner records the bounded essentials review in
`docs/platform-tenant-essentials-review.md`. T06 remains wait for coordinated
live registration/custody, provisioning and native refusal/revocation evidence.
No new task or workplan was created. Warden's npm no-rotation hold remains;
factory records now consume the completed generic approval and companion returns.