Authorize and issue OpenBao identity leases #12
Labels
No labels
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Meta/Campaign
Meta/Epic
Meta/Session
Priority/Critical
Priority/High
Priority/Low
Priority/Medium
Reviewed/Confirmed
Reviewed/Curated
Reviewed/Duplicate
Reviewed/Invalid
Reviewed/Won't Fix
Scope/Campaign
Status/Abandoned
Status/Blocked
Status/Conflicted
Status/In Progress
Status/In Review
Status/Need Grooming
Status/Need More Info
Status/Ready
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Depends on
Reference
Ting/Vedanta#12
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Proposal
Implement OpenBao authorization, provisional lease creation, private mint dispatch, commit, and one-shot wrapped delivery for initial identity leases.
Delivery class
agent-unit— addopenbao-plugin/src/issue.rswith authorization-table and private-service capture doubles.Design
Evaluate caller, claimant, grant, principal, assignment, isolation, resource, operation, audience, TTL, active limit, digest, and projection freshness in order. Persist pre-mutation intent, call Vedanta through the private contract, and commit only after mint succeeds.
Tasks
IssueLeaserequest, response, and stable error classes.Specification Delta
Requirement: failed internal mint creates no lease
Scenario: Vedanta or Kanidm refuses the operation
OpenSpec
OpenSpec 20
Structural parent
Vedanta#20
Grooming state: Clarified by later authority
Evidence: Ratified OpenSpec 61 v0.1.4, current OpenSpec 20, and the refined #12/#22 records now define one-shot wrapped delivery and a dedicated authenticated, signed OpenBao→Vedanta private-command boundary.
The former Q1 delivery-contract and Q2 plugin-authority questions are no longer open. #12 remains the initial OpenBao authorization and lease-issue implementation unit governed by its current body; #22 owns private peer and command validation.
Larandar: no owner decision remains on this record.
OpenBao plugin: expose Vedanta-backed agent credentialsto OpenBao lease backend for Vedanta-backed Forge identity credentialsOpenBao lease backend for Vedanta-backed Forge identity credentialsto Authorize and issue OpenBao identity leaseslarandar referenced this issue2026-08-30 08:55:04 +00:00
larandar referenced this issue2026-09-02 19:23:32 +00:00