# Hardening Backlog — Exit From Bootstrap Mode The MVP runs in **bootstrap mode**: stage roles may be driven by temporary root-created OpenBao tokens read from mode-0600 files. That is acceptable setup material, **not** the steady state. This backlog tracks the work to retire it. The MVP is honest about this: bootstrap mode is a documented, bounded phase with explicit revocation tasks — not a hidden permanent security posture. ## H0 — Revoke outstanding bootstrap tokens (always-on hygiene) Every minted bootstrap token has a revocation task. Track each here: | Token file | Stage | Minted | TTL | Revoked? | | --- | --- | --- | --- | --- | | `~/.secrets-engine/bootstrap/prod.token` | prod | (n/a — demo uses dev server) | 1h | n/a | Revoke: `bao token revoke -accessor ` then `shred -u `. ## H1 — Replace bootstrap token files with OIDC / service auth - Stand up an OpenBao auth method (OIDC or AppRole bound to a workload identity) for each stage role. - secrets-engine logs in via that method instead of reading a token file. - Remove `--bootstrap-token-file` from the steady-state path (keep only for true break-glass, heavily audited). ## H2 — Response-wrapped handoff - Add a `wrapped` delivery mode using OpenBao response wrapping for operator handoff flows where exec-time injection does not fit. ## H3 — Production dual-control - Require two-person approval (`approval.model: dual-control`) for prod value provisioning before automating raw-value writes beyond the pilot. ## H4 — Rotation & lifecycle states - Implement `rotate`, and explicit `compromised` / `deactivated` lane states with evidence, beyond the current `revoke` (metadata delete). ## H5 — Audit report command - `secrets-engine audit ` summarizing non-secret evidence (decision, applies, provisions, verifications, execs, revokes) for a lane. ## H6 — API service mode - Expose the stabilized CLI semantics as a local service API for ops-warden, CI, agents, and a future UI — **after** the CLI contract is proven. ## Exit criteria for "bootstrap mode is over" - No steady-state flow reads a bootstrap token file. - Every stage role authenticates through OIDC/service auth. - Production provisioning beyond the pilot requires dual-control. - Rotation and deactivation are first-class, evidenced operations.