# whynot-design npm publish token — the MVP pilot lane. # This file is NON-SECRET. It describes where the token lives in OpenBao and how # it may be consumed. The token VALUE never appears here. id: whynot-design-npm-publish owner: whynot-design stage: prod description: >- npm automation token used to publish the whynot-design package. Delivered to `npm publish` via an exec-time temporary npm config; never printed or exported into the parent shell. # OpenBao KV v2 location of the secret material. mount: secret path: whynot-design/npm/publish # Field(s) inside the KV entry. The publish token is stored under this key. fields: - npm_token # Who may consume this lane and the identity claim that binds them. consumers: - name: whynot-design-ci auth: approle # bound OpenBao auth method claim: "role:whynot-design-publish" purpose: "publish whynot-design npm package from CI" # How the value may leave OpenBao. npm-config = temp .npmrc for the child only. delivery_modes: - npm-config - read-check # Privileged actions on this lane require an approved decision/CCR. approval: model: decision decision_ref: "whynot-design-npm-publish" # State Hub decision/CCR id or slug notes: "Production lane: apply requires an approved decision." # Verification expectations (no value is ever printed). verification: positive: "approved consumer token can read the lane field" negative: "an unrelated token is denied read on the lane path" rotation: expectation: "rotate on compromise or every 90 days" ttl: "90d" deactivation: expectation: "revoke approle + delete KV metadata; record evidence" audit: evidence: "decision id, actor, path, timestamp, result — no secret value"