Headless multi-application, multi-tenant secrets mangement engine.
Find a file
tegwick c44306b1b2
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
feat: bind the destroy gate to approval_binding_digest and pdp_path
The vocabulary mapping this path was waiting on is not coming: gate-house
rejected it in GH-DEC-2026-008, because a translation can be confidently
wrong and fails open by accepting a claim approved for a different action.
The stronger option arrived instead, and both halves are enforced here.

flex-auth published binding.approval_binding_digest (FLEX-DEC-2026-007) to
fix the circularity this repo reported: a pdp_digest recorded at issue time
can never equal the request_digest of the request that carries the claim in
its hashed context, so with GH-DEC-2026-008 requiring that equality, destroy
would have failed closed forever on a check no correct record could pass.

- authorization.approval_binding_digest implements the published exclusion
  rule, including Go's context,omitempty behaviour when stripping empties
  the context; digest_material drops an empty context for the same reason.
- validate_decision_envelope recomputes the field rather than trusting it,
  refuses a claim-bearing request whose decision records none, and compares
  the claim's digest from step 1 against it -- never against request_digest,
  which still covers the claim so it stays a sound replay identity.
- validate_approval_claim requires binding.pdp_path true before using
  pdp_digest at all. Path intent is never inferred from a digest that
  happens to be present; pre-schema-v3 approvals carry pdp_path false
  regardless of any digest they hold.

Replay fixtures re-vendored from dd3ce4c. The destroy pins moved a second
and final time; approval_binding_digest did not, which is the point. The
fixture now demonstrates the property instead of asserting it: we rederive
fa07becf... from its own request through our canonical implementation,
proving we hash the same material flex-auth does rather than pinning a
constant we cannot reproduce.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E4tNMAYcSQmZWUE4wqP4ij

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715726@bnt-lap001
Assistant-Session: 80a42b32-cba6-4b23-8be0-68819b1a6092
2026-09-06 20:39:59 +02:00
.claude/rules Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
.decisions Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:37:57 +02:00
catalog docs: record whynot-design lane pointer discrepancy from ops-warden 2026-09-06 00:46:02 +02:00
docs feat: bind the destroy gate to approval_binding_digest and pdp_path 2026-09-06 20:39:59 +02:00
history Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
intakes chore(registrar): assign State Hub identifiers 2026-08-29 12:00:51 +02:00
policies Harden secret provisioning and lifecycle controls 2026-08-23 12:05:58 +02:00
registry Initial commit 2026-06-28 09:03:37 +00:00
scripts Implement SECRETS-WP-0008 unblocked layer-model obligations 2026-08-29 12:52:55 +02:00
src/secrets_engine feat: bind the destroy gate to approval_binding_digest and pdp_path 2026-09-06 20:39:59 +02:00
tests feat: bind the destroy gate to approval_binding_digest and pdp_path 2026-09-06 20:39:59 +02:00
workplans feat: bind the destroy gate to approval_binding_digest and pdp_path 2026-09-06 20:39:59 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-06 14:56:45 +02:00
.gitignore Ignore local repo-manager index 2026-08-29 11:59:33 +02:00
.repo-classification.yaml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
AGENTS.md Declare Engine/Lifecycle against security layer model v0.7 2026-08-29 11:57:47 +02:00
CLAUDE.md Regenerate agent instructions from state-hub templates (CUST-WP-0055 T01) 2026-07-08 14:50:36 +02:00
evidence-classification.yaml Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
INTENT.md Implement GH-DEC-2026-003 consume-before-OpenBao PEP gate 2026-09-02 01:06:50 +02:00
layer.yaml Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 01:04:47 +02:00
pep-stance.yaml Implement SECRETS-WP-0008 unblocked layer-model obligations 2026-08-29 12:52:55 +02:00
ProductRequirementsDocument.md Add value-safe verification and audit reporting 2026-08-23 12:33:38 +02:00
pyproject.toml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
README.md Prepare WP-0006 first-lane native cutover packet 2026-09-03 23:36:42 +02:00
SCOPE.md Add native rotate and persistent lane overlay states 2026-09-02 13:09:10 +02:00
uv.lock Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
WORK-RECORDS.md docs: index Glas native credential delivery workplan 2026-09-06 00:30:10 +02:00

secrets-engine

Headless, multi-application, multi-tenant secrets workflow and automation layer for approved secret custody, delivery, and lifecycle work across build, test, and production stages.

Layer: Engine / Lifecycle under the accepted NetKingdom Security Layer Model (layer.yaml). OpenBao remains the custody and enforcement backend. secrets-engine is the deterministic API over it: catalog, decision consumption, plan/apply, guarded provisioning, verification, delivery, evidence, lifecycle metadata, and native-access deactivation. It does not render authorization decisions. Local evidence can be inspected through an allowlisted per-lane audit summary without exposing record detail.

Start Here

Core Direction

The MVP proves the whynot-design-npm-publish lane end to end:

  1. describe the lane in a non-secret catalog (catalog/);
  2. verify an approved decision (State Hub or local fixture);
  3. apply OpenBao policy/auth metadata through a stage-aware role;
  4. provision and verify the value without printing it;
  5. run a workload command through safe exec-time delivery.

Target command shape:

secrets-engine exec --catalog whynot-design-npm-publish -- npm publish

Quickstart

uv venv && uv pip install -e ".[dev]"
source .venv/bin/activate
secrets-engine catalog list

# Run the whole pilot chain live against a throwaway OpenBao dev server:
SECRETS_ENGINE_HUB_URL="" bash scripts/demo-e2e.sh

The implementation is a Python package (src/secrets_engine/). OpenBao is reached only through the bao CLI adapter (openbao.py); the rest of the code speaks in lanes and guarded plans.

Security Rules

  • Do not put raw secret values in Git, State Hub, chat, prompts, issue comments, workplans, or normal logs.
  • OpenBao is the backend custody and audit authority.
  • Build, test, and production have separate policy boundaries.
  • Production live actions fail closed until the durable State Hub action-authorization endpoint is available; local approval mirrors are throwaway-demo material only.
  • A privileged production OpenBao call also requires a successful approval-engine CAS consume first. Conflict or unavailability means do not write.
  • Temporary bootstrap OpenBao credentials must live outside repos, use mode 0600, be revocable, and be removed after narrower auth is working.