Headless multi-application, multi-tenant secrets mangement engine.
Find a file
tegwick 03c0569820
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
feat: adopt the owner-documented PDP access path, and prove it live
Adoption asked for by flex-auth (FLEX-WP-0021-T05) and glas-harness
(GLAS-WP-0015), plus the first real decision this engine has obtained from
the deployed pin -- which found a defect the fixtures could not.

ACCESS PATH. require_supported_pdp_address refuses in-cluster Service names
and any non-loopback host. This is no longer a unilateral call: the owner
path is documented as loopback kubectl port-forward over the authenticated
Kubernetes API, which is what authenticates the responder transitively
(FLEX-DEC-2026-010). A Service name from a workstation does not fail, it
resolves through the DNS search suffix to an unrelated public host, and
since decision records carry no signature, a responder knowing the
published package and version can return an allow that passes every check
we make. Fail-closed protects against a PDP that is absent, not one that
lies. The guard runs before the token is read, so a misdirected request
cannot leak it; a test pins that ordering.

LIVE PROOF. Minted a 10-minute TokenRequest token (audience flex-auth, SA
secrets-engine/secrets-engine, mode 0600 outside the worktree, shredded
after), forwarded to the named pod, and sent a real CheckRequest for
glas-claude-agent-dev-anthropic. Result: allow, catalog_lane_policy_matched,
served by v2 (sha256:bd11c5fe...) -- so the redeploy flex-auth flagged as
outstanding has landed and the pin no longer serves the tenant-blind v1.
Our tenant fix is confirmed against the real service: binding.tenant is
tenant:platform.

THE DEFECT IT FOUND. The evaluator enriches from its registry before
hashing -- subject gains attributes and tenant, resource gains tenant --
so binding.request_digest is over material we never sent and cannot
reproduce. validate_decision_envelope rejects every real allow.

Every replay test passes because _request_from() rebuilds the request out
of the binding, i.e. the enriched form: a self-consistent fake agreeing
with itself, which hid this through three rounds of digest work. Third
time a real artifact has beaten a fake in this integration.

NOT FIXED, DELIBERATELY. Rejecting a valid allow is wrong in the safe
direction. Which fields may be enriched is flex-auth's contract to publish;
inferring it means accepting a binding that differs from our proposal in a
way we decided was benign -- the fail-open shape GH-DEC-2026-008 rejected
for vocabularies and FLEX-DEC-2026-007 for digests. Raised with them.

Tenant question closed by operator decision 5ed3fb35: tenant:platform
exactly, and service_auth.TENANT stays tenant:coulomb because the two
identity layers are to remain distinct. Declining to author that mapping
was right -- the answer was neither reading offered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E4tNMAYcSQmZWUE4wqP4ij

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715726@bnt-lap001
Assistant-Session: 80a42b32-cba6-4b23-8be0-68819b1a6092
2026-09-07 00:22:12 +02:00
.claude/rules Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
.decisions Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:37:57 +02:00
catalog docs: record whynot-design lane pointer discrepancy from ops-warden 2026-09-06 00:46:02 +02:00
docs feat: adopt the owner-documented PDP access path, and prove it live 2026-09-07 00:22:12 +02:00
history Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
intakes chore(registrar): assign State Hub identifiers 2026-08-29 12:00:51 +02:00
policies Harden secret provisioning and lifecycle controls 2026-08-23 12:05:58 +02:00
registry Initial commit 2026-06-28 09:03:37 +00:00
scripts Implement SECRETS-WP-0008 unblocked layer-model obligations 2026-08-29 12:52:55 +02:00
src/secrets_engine feat: adopt the owner-documented PDP access path, and prove it live 2026-09-07 00:22:12 +02:00
tests feat: adopt the owner-documented PDP access path, and prove it live 2026-09-07 00:22:12 +02:00
workplans docs: answer the GLAS-WP-0015 tenant question and record the DNS hazard 2026-09-06 22:34:20 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-06 22:36:34 +02:00
.gitignore Ignore local repo-manager index 2026-08-29 11:59:33 +02:00
.repo-classification.yaml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
AGENTS.md Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
CLAUDE.md Regenerate agent instructions from state-hub templates (CUST-WP-0055 T01) 2026-07-08 14:50:36 +02:00
evidence-classification.yaml Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
INTENT.md Implement GH-DEC-2026-003 consume-before-OpenBao PEP gate 2026-09-02 01:06:50 +02:00
layer.yaml Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 01:04:47 +02:00
pep-stance.yaml Implement SECRETS-WP-0008 unblocked layer-model obligations 2026-08-29 12:52:55 +02:00
ProductRequirementsDocument.md Add value-safe verification and audit reporting 2026-08-23 12:33:38 +02:00
pyproject.toml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
README.md Prepare WP-0006 first-lane native cutover packet 2026-09-03 23:36:42 +02:00
SCOPE.md Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
uv.lock Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
WORK-RECORDS.md docs: index Glas native credential delivery workplan 2026-09-06 00:30:10 +02:00

secrets-engine

Headless, multi-application, multi-tenant secrets workflow and automation layer for approved secret custody, delivery, and lifecycle work across build, test, and production stages.

Layer: Engine / Lifecycle under the accepted NetKingdom Security Layer Model (layer.yaml). OpenBao remains the custody and enforcement backend. secrets-engine is the deterministic API over it: catalog, decision consumption, plan/apply, guarded provisioning, verification, delivery, evidence, lifecycle metadata, and native-access deactivation. It does not render authorization decisions. Local evidence can be inspected through an allowlisted per-lane audit summary without exposing record detail.

Start Here

Core Direction

The MVP proves the whynot-design-npm-publish lane end to end:

  1. describe the lane in a non-secret catalog (catalog/);
  2. verify an approved decision (State Hub or local fixture);
  3. apply OpenBao policy/auth metadata through a stage-aware role;
  4. provision and verify the value without printing it;
  5. run a workload command through safe exec-time delivery.

Target command shape:

secrets-engine exec --catalog whynot-design-npm-publish -- npm publish

Quickstart

uv venv && uv pip install -e ".[dev]"
source .venv/bin/activate
secrets-engine catalog list

# Run the whole pilot chain live against a throwaway OpenBao dev server:
SECRETS_ENGINE_HUB_URL="" bash scripts/demo-e2e.sh

The implementation is a Python package (src/secrets_engine/). OpenBao is reached only through the bao CLI adapter (openbao.py); the rest of the code speaks in lanes and guarded plans.

Security Rules

  • Do not put raw secret values in Git, State Hub, chat, prompts, issue comments, workplans, or normal logs.
  • OpenBao is the backend custody and audit authority.
  • Build, test, and production have separate policy boundaries.
  • Production live actions fail closed until the durable State Hub action-authorization endpoint is available; local approval mirrors are throwaway-demo material only.
  • A privileged production OpenBao call also requires a successful approval-engine CAS consume first. Conflict or unavailability means do not write.
  • Temporary bootstrap OpenBao credentials must live outside repos, use mode 0600, be revocable, and be removed after narrower auth is working.