feat(openbao-session): tie session token to the user entity
Mint the session token with -entity-alias from OPENBAO_SESSION_ENTITY so
{{identity.entity.id}} resolves and the session can read humans/self (read-only)
in addition to shared/*. Document the claude-session policy with humans/self.
Bump 0.1.1.
Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -36,6 +36,7 @@ TLS_NAME="${OPENBAO_SESSION_TLS_NAME:-mbu-backup-jumphost}"
|
||||
BAO_VER="${OPENBAO_SESSION_BAO_VER:-2.6.2}"
|
||||
SESSION_POLICY="${OPENBAO_SESSION_POLICY:-claude-session}"
|
||||
SESSION_TTL="${OPENBAO_SESSION_TTL:-4h}"
|
||||
SESSION_ENTITY="${OPENBAO_SESSION_ENTITY:-}" # OpenBao entity name; ties the session token to the user (enables humans/self via {{identity.entity.id}})
|
||||
SECRETS_HELPER="${OPENBAO_SESSION_SECRETS_HELPER:-$HOME/.config/devops-secrets/manage.py}"
|
||||
BOOTSTRAP_TOOL="${OPENBAO_SESSION_BOOTSTRAP_TOOL:-openbao}"
|
||||
BOOTSTRAP_KEY="${OPENBAO_SESSION_BOOTSTRAP_KEY:-bootstrap_token}"
|
||||
@@ -101,9 +102,14 @@ read_bootstrap() {
|
||||
|
||||
mint_session_token() {
|
||||
local bootstrap json
|
||||
local -a entity_args=()
|
||||
bootstrap="$(read_bootstrap)" || return 1
|
||||
if [ -n "$SESSION_ENTITY" ]; then
|
||||
entity_args+=("-entity-alias=$SESSION_ENTITY")
|
||||
fi
|
||||
json="$(BAO_ADDR="$BAO_ADDR_URL" BAO_CACERT="$CACERT" BAO_TLS_SERVER_NAME="$TLS_NAME" BAO_TOKEN="$bootstrap" \
|
||||
"$BAO_BIN" token create -policy="$SESSION_POLICY" -ttl="$SESSION_TTL" -renewable \
|
||||
"${entity_args[@]}" \
|
||||
-display-name="openbao-session-$(hostname)" -format=json)" || { log "token create failed"; return 1; }
|
||||
SESSION_TOKEN="$(printf '%s' "$json" | jq -r '.auth.client_token // empty')"
|
||||
[ -n "$SESSION_TOKEN" ] || { log "no client_token in token create response"; return 1; }
|
||||
|
||||
Reference in New Issue
Block a user