fix(openbao-session): use a token role for entity-alias minting
entity-alias only works with -role; add OPENBAO_SESSION_ROLE so session tokens can carry the user entity (and read humans/self) via the openbao-session role. Bump 0.1.2. Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "openbao-session",
|
"name": "openbao-session",
|
||||||
"version": "0.1.1",
|
"version": "0.1.2",
|
||||||
"description": "Provisions a short-lived OpenBao session token for interactive agent sessions.",
|
"description": "Provisions a short-lived OpenBao session token for interactive agent sessions.",
|
||||||
"author": { "name": "Senkensha" },
|
"author": { "name": "Senkensha" },
|
||||||
"hooks": "./hooks/claude-codex-hooks.json"
|
"hooks": "./hooks/claude-codex-hooks.json"
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "openbao-session",
|
"name": "openbao-session",
|
||||||
"version": "0.1.1+codex.20260901111859",
|
"version": "0.1.2+codex.20260901112838",
|
||||||
"description": "Provisions a short-lived OpenBao session token for interactive agent sessions.",
|
"description": "Provisions a short-lived OpenBao session token for interactive agent sessions.",
|
||||||
"author": {
|
"author": {
|
||||||
"name": "Local developer"
|
"name": "Local developer"
|
||||||
|
|||||||
@@ -49,7 +49,13 @@ path "humans/metadata/{{identity.entity.id}}/*" { capabilities = ["read", "list"
|
|||||||
EOF
|
EOF
|
||||||
bao policy write claude-session /tmp/claude-session.hcl
|
bao policy write claude-session /tmp/claude-session.hcl
|
||||||
|
|
||||||
# 3. Issue bootstrap token (TTL panjang, renewable) dan simpan NILAINYA ke secrets store LOKAL:
|
# 3. Token roles (wajib utk -entity-alias). Perluas allowed_entity_aliases sesuai tim.
|
||||||
|
bao write auth/token/roles/openbao-session \
|
||||||
|
allowed_policies=claude-session \
|
||||||
|
allowed_entity_aliases=adnan,rizal \
|
||||||
|
ttl=4h renewable=true
|
||||||
|
|
||||||
|
# 4. Issue bootstrap token (TTL panjang, renewable) dan simpan NILAINYA ke secrets store LOKAL:
|
||||||
bao token create -policy=openbao-session-creator -ttl=720h -renewable \
|
bao token create -policy=openbao-session-creator -ttl=720h -renewable \
|
||||||
-display-name=openbao-session-bootstrap -format=json
|
-display-name=openbao-session-bootstrap -format=json
|
||||||
# → ambil auth.client_token, lalu di Mac Anda:
|
# → ambil auth.client_token, lalu di Mac Anda:
|
||||||
@@ -83,6 +89,7 @@ python3 ~/.config/devops-secrets/manage.py set openbao bootstrap_token --descrip
|
|||||||
| `OPENBAO_SESSION_POLICY` | `claude-session` | policy token sesi |
|
| `OPENBAO_SESSION_POLICY` | `claude-session` | policy token sesi |
|
||||||
| `OPENBAO_SESSION_TTL` | `4h` | umur token sesi |
|
| `OPENBAO_SESSION_TTL` | `4h` | umur token sesi |
|
||||||
| `OPENBAO_SESSION_ENTITY` | *(kosong)* | nama entity OpenBao pemakai (mis. `adnan`, `rizal`) → token sesi diikat ke entity (aktifkan `humans/self`) |
|
| `OPENBAO_SESSION_ENTITY` | *(kosong)* | nama entity OpenBao pemakai (mis. `adnan`, `rizal`) → token sesi diikat ke entity (aktifkan `humans/self`) |
|
||||||
|
| `OPENBAO_SESSION_ROLE` | *(kosong)* | token role utk sesi (mis. `openbao-session`). Wajib diisi jika `OPENBAO_SESSION_ENTITY` diset (`-entity-alias` hanya bekerja dgn `-role`) |
|
||||||
| `OPENBAO_SESSION_BAO_VER` | `2.6.2` | versi binary bao (auto-download jika belum ada) |
|
| `OPENBAO_SESSION_BAO_VER` | `2.6.2` | versi binary bao (auto-download jika belum ada) |
|
||||||
| `OPENBAO_SESSION_SECRETS_HELPER` | `~/.config/devops-secrets/manage.py` | helper baca bootstrap |
|
| `OPENBAO_SESSION_SECRETS_HELPER` | `~/.config/devops-secrets/manage.py` | helper baca bootstrap |
|
||||||
| `OPENBAO_SESSION_BOOTSTRAP_TOOL` / `_KEY` | `openbao` / `bootstrap_token` | lokasi bootstrap di secrets store |
|
| `OPENBAO_SESSION_BOOTSTRAP_TOOL` / `_KEY` | `openbao` / `bootstrap_token` | lokasi bootstrap di secrets store |
|
||||||
|
|||||||
@@ -37,6 +37,7 @@ BAO_VER="${OPENBAO_SESSION_BAO_VER:-2.6.2}"
|
|||||||
SESSION_POLICY="${OPENBAO_SESSION_POLICY:-claude-session}"
|
SESSION_POLICY="${OPENBAO_SESSION_POLICY:-claude-session}"
|
||||||
SESSION_TTL="${OPENBAO_SESSION_TTL:-4h}"
|
SESSION_TTL="${OPENBAO_SESSION_TTL:-4h}"
|
||||||
SESSION_ENTITY="${OPENBAO_SESSION_ENTITY:-}" # OpenBao entity name; ties the session token to the user (enables humans/self via {{identity.entity.id}})
|
SESSION_ENTITY="${OPENBAO_SESSION_ENTITY:-}" # OpenBao entity name; ties the session token to the user (enables humans/self via {{identity.entity.id}})
|
||||||
|
SESSION_ROLE="${OPENBAO_SESSION_ROLE:-}" # token role (required when SESSION_ENTITY is set; entity-alias only works with a role)
|
||||||
SECRETS_HELPER="${OPENBAO_SESSION_SECRETS_HELPER:-$HOME/.config/devops-secrets/manage.py}"
|
SECRETS_HELPER="${OPENBAO_SESSION_SECRETS_HELPER:-$HOME/.config/devops-secrets/manage.py}"
|
||||||
BOOTSTRAP_TOOL="${OPENBAO_SESSION_BOOTSTRAP_TOOL:-openbao}"
|
BOOTSTRAP_TOOL="${OPENBAO_SESSION_BOOTSTRAP_TOOL:-openbao}"
|
||||||
BOOTSTRAP_KEY="${OPENBAO_SESSION_BOOTSTRAP_KEY:-bootstrap_token}"
|
BOOTSTRAP_KEY="${OPENBAO_SESSION_BOOTSTRAP_KEY:-bootstrap_token}"
|
||||||
@@ -102,14 +103,17 @@ read_bootstrap() {
|
|||||||
|
|
||||||
mint_session_token() {
|
mint_session_token() {
|
||||||
local bootstrap json
|
local bootstrap json
|
||||||
local -a entity_args=()
|
local -a create_args=()
|
||||||
bootstrap="$(read_bootstrap)" || return 1
|
bootstrap="$(read_bootstrap)" || return 1
|
||||||
if [ -n "$SESSION_ENTITY" ]; then
|
if [ -n "$SESSION_ROLE" ]; then
|
||||||
entity_args+=("-entity-alias=$SESSION_ENTITY")
|
# token role governs policy + allows entity-alias (entity-alias needs a role)
|
||||||
|
create_args+=(-role="$SESSION_ROLE")
|
||||||
|
[ -n "$SESSION_ENTITY" ] && create_args+=(-entity-alias="$SESSION_ENTITY")
|
||||||
|
else
|
||||||
|
create_args+=(-policy="$SESSION_POLICY" -ttl="$SESSION_TTL")
|
||||||
fi
|
fi
|
||||||
json="$(BAO_ADDR="$BAO_ADDR_URL" BAO_CACERT="$CACERT" BAO_TLS_SERVER_NAME="$TLS_NAME" BAO_TOKEN="$bootstrap" \
|
json="$(BAO_ADDR="$BAO_ADDR_URL" BAO_CACERT="$CACERT" BAO_TLS_SERVER_NAME="$TLS_NAME" BAO_TOKEN="$bootstrap" \
|
||||||
"$BAO_BIN" token create -policy="$SESSION_POLICY" -ttl="$SESSION_TTL" -renewable \
|
"$BAO_BIN" token create "${create_args[@]}" -renewable \
|
||||||
"${entity_args[@]}" \
|
|
||||||
-display-name="openbao-session-$(hostname)" -format=json)" || { log "token create failed"; return 1; }
|
-display-name="openbao-session-$(hostname)" -format=json)" || { log "token create failed"; return 1; }
|
||||||
SESSION_TOKEN="$(printf '%s' "$json" | jq -r '.auth.client_token // empty')"
|
SESSION_TOKEN="$(printf '%s' "$json" | jq -r '.auth.client_token // empty')"
|
||||||
[ -n "$SESSION_TOKEN" ] || { log "no client_token in token create response"; return 1; }
|
[ -n "$SESSION_TOKEN" ] || { log "no client_token in token create response"; return 1; }
|
||||||
|
|||||||
Reference in New Issue
Block a user