From 31d7a6a42774f8a65e87132c18205ccddee992b8 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Wed, 19 Aug 2026 23:34:15 +1000 Subject: [PATCH] Restore ghp secret backend + roles (config now seeded) Reverts the temporary removal in #129. The ghp config KV path kv/data/service/vault/au/syd1/secret_backend/ghp/config (key admin_token) is now seeded, and the ghp service secret carries the matching service_token, so data.vault_kv_secret_v2.config resolves and the backend + role can be created. Restore config/ghp_secret_backend/ghp.yaml. Restore config/ghp_secret_backend_role/ghp/agent.yaml. Net diff vs master is exactly the re-addition of those two files (mirror-inverse of #129). Final step of the remove -> grant -> seed -> add-back sequence. --- config/ghp_secret_backend/ghp.yaml | 15 +++++++++++++++ config/ghp_secret_backend_role/ghp/agent.yaml | 15 +++++++++++++++ 2 files changed, 30 insertions(+) create mode 100644 config/ghp_secret_backend/ghp.yaml create mode 100644 config/ghp_secret_backend_role/ghp/agent.yaml diff --git a/config/ghp_secret_backend/ghp.yaml b/config/ghp_secret_backend/ghp.yaml new file mode 100644 index 0000000..ecff20b --- /dev/null +++ b/config/ghp_secret_backend/ghp.yaml @@ -0,0 +1,15 @@ +# Mounts the ghp token secrets engine at "ghp" and writes its config. +# The seeded ghp service token is sensitive and read from KV, not stored here: +# kv/service/vault/au/syd1/secret_backend/ghp/config +# -> key: admin_token (required) the shared ghpsvc_... service token +# +# admin_token is a static shared secret provisioned into KV by an operator. The +# SAME token value must also be present in the running ghp deployment's accepted +# service tokens (GHP_AUTH_SERVICE_TOKENS) so ghp ACCEPTS what this engine +# PRESENTS. ghp has no rotate endpoint, so the engine never rotates it in place; +# the mount uses ignore_changes=[admin_token], making the KV seed create-only +# (re-reading a stale KV value never re-pushes it to a live mount). +description: "ghp ephemeral scoped agent token engine" +base_url: "https://ghp.unkin.net" +tls_skip_verify: false +request_timeout_seconds: 30 diff --git a/config/ghp_secret_backend_role/ghp/agent.yaml b/config/ghp_secret_backend_role/ghp/agent.yaml new file mode 100644 index 0000000..b5653c7 --- /dev/null +++ b/config/ghp_secret_backend_role/ghp/agent.yaml @@ -0,0 +1,15 @@ +# Role minting ephemeral, scoped ghp agent tokens. Reading ghp/creds/agent mints +# a lease-bound token deleted from ghp on revoke/expiry. token_type "agent" binds +# the minted token to a ghp App installation, so installation_id is REQUIRED. +# +# installation_id below is a PLACEHOLDER (0) and MUST be set to the real ghp App +# installation id before this role can mint usable tokens. scopes are ghp +# permission:level pairs; contents:read is the least-privilege default. +--- +token_type: agent +installation_id: 0 # PLACEHOLDER - set to the real ghp App installation id +scopes: + - contents:read +session_prefix: vault +ttl: 3600 # 1h +max_ttl: 86400 # 24h -- 2.47.3