fix(openbao-session): use a token role for entity-alias minting

entity-alias only works with -role; add OPENBAO_SESSION_ROLE so session tokens
can carry the user entity (and read humans/self) via the openbao-session role.
Bump 0.1.2.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-09-01 11:28:38 +07:00
parent 5699bf7259
commit 0f77ad534e
4 changed files with 19 additions and 8 deletions

View File

@@ -37,6 +37,7 @@ BAO_VER="${OPENBAO_SESSION_BAO_VER:-2.6.2}"
SESSION_POLICY="${OPENBAO_SESSION_POLICY:-claude-session}"
SESSION_TTL="${OPENBAO_SESSION_TTL:-4h}"
SESSION_ENTITY="${OPENBAO_SESSION_ENTITY:-}" # OpenBao entity name; ties the session token to the user (enables humans/self via {{identity.entity.id}})
SESSION_ROLE="${OPENBAO_SESSION_ROLE:-}" # token role (required when SESSION_ENTITY is set; entity-alias only works with a role)
SECRETS_HELPER="${OPENBAO_SESSION_SECRETS_HELPER:-$HOME/.config/devops-secrets/manage.py}"
BOOTSTRAP_TOOL="${OPENBAO_SESSION_BOOTSTRAP_TOOL:-openbao}"
BOOTSTRAP_KEY="${OPENBAO_SESSION_BOOTSTRAP_KEY:-bootstrap_token}"
@@ -102,14 +103,17 @@ read_bootstrap() {
mint_session_token() {
local bootstrap json
local -a entity_args=()
local -a create_args=()
bootstrap="$(read_bootstrap)" || return 1
if [ -n "$SESSION_ENTITY" ]; then
entity_args+=("-entity-alias=$SESSION_ENTITY")
if [ -n "$SESSION_ROLE" ]; then
# token role governs policy + allows entity-alias (entity-alias needs a role)
create_args+=(-role="$SESSION_ROLE")
[ -n "$SESSION_ENTITY" ] && create_args+=(-entity-alias="$SESSION_ENTITY")
else
create_args+=(-policy="$SESSION_POLICY" -ttl="$SESSION_TTL")
fi
json="$(BAO_ADDR="$BAO_ADDR_URL" BAO_CACERT="$CACERT" BAO_TLS_SERVER_NAME="$TLS_NAME" BAO_TOKEN="$bootstrap" \
"$BAO_BIN" token create -policy="$SESSION_POLICY" -ttl="$SESSION_TTL" -renewable \
"${entity_args[@]}" \
"$BAO_BIN" token create "${create_args[@]}" -renewable \
-display-name="openbao-session-$(hostname)" -format=json)" || { log "token create failed"; return 1; }
SESSION_TOKEN="$(printf '%s' "$json" | jq -r '.auth.client_token // empty')"
[ -n "$SESSION_TOKEN" ] || { log "no client_token in token create response"; return 1; }