102 lines
3.3 KiB
YAML
102 lines
3.3 KiB
YAML
# warden-sign auth-capability lane.
|
|
# NON-SECRET: this file contains only OpenBao policy/AppRole metadata and
|
|
# operational pointers. AppRole secret_id values and tokens must never appear in
|
|
# Git, State Hub, chat, prompts, workplans, or normal logs.
|
|
id: warden-sign
|
|
kind: auth-capability
|
|
org: netkingdom
|
|
repo: ops-warden
|
|
stage: prod
|
|
description: >-
|
|
Scoped OpenBao AppRole used by ops-warden production smoke tests to call the
|
|
SSH secrets engine signing API over HTTP. This lane grants update only on the
|
|
exact SSH signing roles needed for FLEX-WP-0007 T4; it stores no KV value.
|
|
|
|
# Existing production OpenBao SSH secrets-engine mount and logical operation.
|
|
mount: ssh
|
|
path: sign
|
|
|
|
consumers:
|
|
- name: ops-warden-policy-smoke
|
|
auth: approle
|
|
claim: "agent:agt-state-hub-bridge"
|
|
purpose: >-
|
|
Run warden sign and the flex-auth policy-gate production smoke without
|
|
giving ops-warden standing custody of an OpenBao token.
|
|
allowed_actors:
|
|
- agt-state-hub-bridge
|
|
- agt-codex-interhub-bootstrap
|
|
- adm-example
|
|
- atm-backup-daily
|
|
|
|
# The deliverable is a freshly minted AppRole secret_id plus role_id handed to
|
|
# the operator out-of-band. There is no KV value and no from-file provisioning.
|
|
delivery_modes:
|
|
- approle-login
|
|
|
|
approval:
|
|
model: decision
|
|
decision_ref: "SECRETS-WP-0004"
|
|
notes: >-
|
|
Production auth-capability lane. Live apply and handoff require an approved
|
|
decision/workplan plus a mode-0600 bootstrap token outside any repo.
|
|
|
|
verification:
|
|
positive: "the warden-sign AppRole token has update on every allowlisted ssh/sign role"
|
|
negative: "the warden-sign AppRole token lacks update on ssh/admin/sys/auth/identity probes"
|
|
|
|
auth_capability:
|
|
policy_name: warden-sign
|
|
role_name: warden-sign
|
|
token_ttl: 15m
|
|
token_max_ttl: 15m
|
|
token_num_uses: 0
|
|
secret_id_ttl: 30m
|
|
secret_id_num_uses: 1
|
|
oidc:
|
|
auth_mount: netkingdom
|
|
role_name: warden-sign
|
|
role_path: auth/netkingdom/role/warden-sign
|
|
login_command: bao login -method=oidc -path=netkingdom role=warden-sign
|
|
policies: [warden-sign]
|
|
ttl: 15m
|
|
user_claim: sub
|
|
groups_claim: groups
|
|
bound_claims:
|
|
groups: [net-kingdom-admins]
|
|
oidc_scopes: [openid, profile, email, groups]
|
|
allowed_redirect_uris:
|
|
- https://bao.coulomb.social/ui/vault/auth/netkingdom/oidc/callback
|
|
- http://localhost:8250/oidc/callback
|
|
- http://127.0.0.1:8250/oidc/callback
|
|
allowed_paths:
|
|
- path: ssh/sign/agt-role
|
|
capabilities: [update]
|
|
- path: ssh/sign/adm-role
|
|
capabilities: [update]
|
|
- path: ssh/sign/atm-role
|
|
capabilities: [update]
|
|
denied_probe_paths:
|
|
- ssh/sign/unlisted-role
|
|
- ssh/roles/agt-role
|
|
- ssh/config/ca
|
|
- sys/policies/acl/warden-sign
|
|
- auth/token/create
|
|
- identity/entity/id
|
|
|
|
rotation:
|
|
expectation: >-
|
|
Mint a fresh single-use secret_id for each attended handoff; revoke the
|
|
resulting token by accessor after the FLEX-WP-0007 T4 smoke or when the 15m
|
|
TTL expires, whichever comes first.
|
|
ttl: 15m
|
|
|
|
deactivation:
|
|
expectation: >-
|
|
Delete the warden-sign AppRole and ACL policy, revoke outstanding token
|
|
accessors, and record non-secret evidence.
|
|
|
|
audit:
|
|
evidence: >-
|
|
policy name, AppRole name, mount, allowed paths, token TTL, role_id file path,
|
|
secret_id file path, timestamp, result — no token value or secret_id.
|