Headless multi-application, multi-tenant secrets mangement engine.
Find a file
tegwick 80eafafe5b fix: send the tenant the policy package scopes us to, and adopt v2
build_action_request emitted no tenant field at all. The deployed
secrets-engine.catalog-lane.lifecycle v2 package reads

  known_tenant   := "tenant:platform"
  request_tenant := object.get(input, "tenant", "")

so an absent tenant is not an ignored field, it matches the wrong_tenant
first-denial branch. Every gated action this engine sent would have been
denied -- and the omission also produced a request_digest that could match
no correctly issued decision, since tenant is hashed material. That is the
same class of defect as hashing excluded fields, arriving from the other
direction, and again only a real artifact exposed it.

Found by answering the GLAS-WP-0015 tenant-alignment question instead of
assuming the values lined up.

- REQUEST_TENANT is pinned against the vendored allow envelopes, so a
  package retenanting fails a test rather than denying production.
- An empty tenant is refused at build time.
- Accepted policy version moves v1 -> v2. v1 had no tenant rule and failed
  open: a rotate under tenant:coulomb returned allow against the deployed
  package. flex-auth superseded rather than amended it, because a fail-open
  correction has to be visible as a version change. A test pins that a v1
  decision is refused.
- Vendored decision_wrong_tenant_deny.json as the denial evidence glas
  asked for, with tests that we refuse it on effect before anything else
  and that a deny legally carries no lifetime.

docs/tenant-alignment.md states the three tenant values as this repo holds
them. It does not resolve the JWT/store mapping: service_auth.TENANT is
tenant:coulomb, which is exactly the value the package denies. That is
either two layers sharing a namespace format or one wrong constant, and
picking between them without an owner ruling is the fail-open shape
GH-DEC-2026-008 rejected for action vocabularies. Both constants stay as
they are, deliberately not unified.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E4tNMAYcSQmZWUE4wqP4ij

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715726@bnt-lap001
Assistant-Session: 80a42b32-cba6-4b23-8be0-68819b1a6092
2026-09-06 22:32:54 +02:00
.claude/rules Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
.decisions Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:37:57 +02:00
catalog docs: record whynot-design lane pointer discrepancy from ops-warden 2026-09-06 00:46:02 +02:00
docs fix: send the tenant the policy package scopes us to, and adopt v2 2026-09-06 22:32:54 +02:00
history Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
intakes chore(registrar): assign State Hub identifiers 2026-08-29 12:00:51 +02:00
policies Harden secret provisioning and lifecycle controls 2026-08-23 12:05:58 +02:00
registry Initial commit 2026-06-28 09:03:37 +00:00
scripts Implement SECRETS-WP-0008 unblocked layer-model obligations 2026-08-29 12:52:55 +02:00
src/secrets_engine fix: send the tenant the policy package scopes us to, and adopt v2 2026-09-06 22:32:54 +02:00
tests fix: send the tenant the policy package scopes us to, and adopt v2 2026-09-06 22:32:54 +02:00
workplans feat: bind the destroy gate to approval_binding_digest and pdp_path 2026-09-06 20:39:59 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-06 14:56:45 +02:00
.gitignore Ignore local repo-manager index 2026-08-29 11:59:33 +02:00
.repo-classification.yaml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
AGENTS.md Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
CLAUDE.md Regenerate agent instructions from state-hub templates (CUST-WP-0055 T01) 2026-07-08 14:50:36 +02:00
evidence-classification.yaml Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
INTENT.md Implement GH-DEC-2026-003 consume-before-OpenBao PEP gate 2026-09-02 01:06:50 +02:00
layer.yaml Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 01:04:47 +02:00
pep-stance.yaml Implement SECRETS-WP-0008 unblocked layer-model obligations 2026-08-29 12:52:55 +02:00
ProductRequirementsDocument.md Add value-safe verification and audit reporting 2026-08-23 12:33:38 +02:00
pyproject.toml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
README.md Prepare WP-0006 first-lane native cutover packet 2026-09-03 23:36:42 +02:00
SCOPE.md Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
uv.lock Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
WORK-RECORDS.md docs: index Glas native credential delivery workplan 2026-09-06 00:30:10 +02:00

secrets-engine

Headless, multi-application, multi-tenant secrets workflow and automation layer for approved secret custody, delivery, and lifecycle work across build, test, and production stages.

Layer: Engine / Lifecycle under the accepted NetKingdom Security Layer Model (layer.yaml). OpenBao remains the custody and enforcement backend. secrets-engine is the deterministic API over it: catalog, decision consumption, plan/apply, guarded provisioning, verification, delivery, evidence, lifecycle metadata, and native-access deactivation. It does not render authorization decisions. Local evidence can be inspected through an allowlisted per-lane audit summary without exposing record detail.

Start Here

Core Direction

The MVP proves the whynot-design-npm-publish lane end to end:

  1. describe the lane in a non-secret catalog (catalog/);
  2. verify an approved decision (State Hub or local fixture);
  3. apply OpenBao policy/auth metadata through a stage-aware role;
  4. provision and verify the value without printing it;
  5. run a workload command through safe exec-time delivery.

Target command shape:

secrets-engine exec --catalog whynot-design-npm-publish -- npm publish

Quickstart

uv venv && uv pip install -e ".[dev]"
source .venv/bin/activate
secrets-engine catalog list

# Run the whole pilot chain live against a throwaway OpenBao dev server:
SECRETS_ENGINE_HUB_URL="" bash scripts/demo-e2e.sh

The implementation is a Python package (src/secrets_engine/). OpenBao is reached only through the bao CLI adapter (openbao.py); the rest of the code speaks in lanes and guarded plans.

Security Rules

  • Do not put raw secret values in Git, State Hub, chat, prompts, issue comments, workplans, or normal logs.
  • OpenBao is the backend custody and audit authority.
  • Build, test, and production have separate policy boundaries.
  • Production live actions fail closed until the durable State Hub action-authorization endpoint is available; local approval mirrors are throwaway-demo material only.
  • A privileged production OpenBao call also requires a successful approval-engine CAS consume first. Conflict or unavailability means do not write.
  • Temporary bootstrap OpenBao credentials must live outside repos, use mode 0600, be revocable, and be removed after narrower auth is working.