Skip to content

test: validate tenant OpenBao authorization#106

Merged
devantler merged 5 commits into
mainfrom
codex/tenant-openbao-auth-contract-105
Jul 22, 2026
Merged

test: validate tenant OpenBao authorization#106
devantler merged 5 commits into
mainfrom
codex/tenant-openbao-auth-contract-105

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

The tenant scaffold could prove its SecretStore shape while missing drift in Platform's actual OpenBao policy and Kubernetes-auth role. That allowed a newly adopted tenant to pass template validation and discover a secret-authorization failure only during reconciliation.

What

  • Bind the renamed scaffold role, ServiceAccount, and app-secret path to Platform's live tenant authorization contract.
  • Require the exact tenant data/metadata scopes, capabilities, policy attachment, ServiceAccount, and namespace.
  • Keep the existing weekly and pull-request gate, adding no new workflow or adopter input.

Security floor: cross-tenant/widened secret paths, incomplete capabilities, duplicate declarations, and mismatched identities now fail before merge.

Developer experience: the normal rename-and-deploy path is unchanged; adopters get the failure earlier in the existing validation gate.

Fixes #105
Part of #6

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Readiness evidence

Reviewed commit: 0d2a369306edb85330bb121a9a4ed2224be42ed8

  • RED: the strengthened envelope contract failed before implementation because the Platform sparse checkout lacked the OpenBao authorization source.
  • GREEN: platform-tenant-envelope-contract.test.sh passes its happy path plus 15 structural mutations.
  • GREEN: platform-tenant-envelope.test.sh passes against Platform main 6b67c945 with 70 behavioral mutations covering paths, capabilities, duplicate policy/role declarations, Platform role/policy/ServiceAccount/namespace drift, and scaffold role/ServiceAccount/path drift.
  • GREEN: the complete documented local validation suite passes: Kustomize render, rename, agent instructions, tenant CI, Pod Security, tenant RBAC, Platform envelope, Platform network floor, and Actionlint.
  • GREEN: ShellCheck passes on both changed shell scripts and git diff --check is clean. A broad optional shellcheck scripts/*.sh also reports the unchanged SC2016 baseline in platform-network-floor-contract.test.sh:202; this change does not touch that script.
  • USER EVALUATION: from a separate checkout pinned to this exact commit, the real rename helper changed the scaffold to the reference tenant, kubectl kustomize deploy/ rendered successfully, and the effective role, ServiceAccount, and apps/<tenant>/config path matched the live Platform contract. The 70 negative controls then passed from that renamed checkout.
  • SELF-REVIEW: an independent static pass found one missing wrong-Platform-role mutation; commit 0d2a369 adds it. The final pass reported no remaining correctness, fail-open, POSIX shell, workflow-security, or simplification findings.

Security floor: widened/cross-tenant paths, incomplete permissions, duplicate declarations, and identity mismatches now fail before merge.

Developer experience: adopters still run the same rename and deploy flow; feedback moves into the existing pull-request/weekly gate with no new input or production step.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown

@devantler I’ll review the OpenBao tenant-authorization validation changes and their security boundaries.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@devantler, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 24 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 138db530-07f6-4495-88f8-078364a206f4

📥 Commits

Reviewing files that changed from the base of the PR and between 0d2a369 and fa7db78.

📒 Files selected for processing (3)
  • .github/workflows/validate-scaffold.yaml
  • scripts/platform-tenant-envelope-contract.test.sh
  • scripts/platform-tenant-envelope.test.sh

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/validate-scaffold.yaml (1)

324-336: 🚀 Performance & Scalability | 🟡 Minor | ⚡ Quick win

Set this sparse checkout to non-cone mode. This list includes file-level paths, but actions/checkout leaves cone mode enabled by default. Add sparse-checkout-cone-mode: false (or switch these entries to directories) to keep the checkout narrow.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/validate-scaffold.yaml around lines 324 - 336, Update the
checkout step identified by “Checkout Platform contracts” to set
sparse-checkout-cone-mode to false, preserving the existing file-level
sparse-checkout entries and narrow checkout scope.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/platform-tenant-envelope.test.sh`:
- Around line 92-121: Anchor role_header to the role command’s trailing
continuation marker, matching the complete declaration rather than a tenant-name
substring. Update both the role_count grep and the role_block awk search around
role_header so only the exact tenant role command is counted and captured, while
preserving the existing role block extraction and validation.

---

Outside diff comments:
In @.github/workflows/validate-scaffold.yaml:
- Around line 324-336: Update the checkout step identified by “Checkout Platform
contracts” to set sparse-checkout-cone-mode to false, preserving the existing
file-level sparse-checkout entries and narrow checkout scope.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: d2a88bb0-91f3-4852-b0a0-4b68d443e08e

📥 Commits

Reviewing files that changed from the base of the PR and between 8b95c7e and 0d2a369.

📒 Files selected for processing (4)
  • .github/workflows/validate-scaffold.yaml
  • README.md
  • scripts/platform-tenant-envelope-contract.test.sh
  • scripts/platform-tenant-envelope.test.sh
📜 Review details
🧰 Additional context used
🧠 Learnings (1)
📚 Learning: 2026-07-21T19:05:11.308Z
Learnt from: devantler
Repo: devantler-tech/gitops-tenant-template PR: 96
File: scripts/platform-network-floor.test.sh:186-187
Timestamp: 2026-07-21T19:05:11.308Z
Learning: When reviewing this repository’s shell scripts under scripts/, do not flag `yq eval -r` as an unsupported option. The repo uses Mike Farah `yq` v4.53.3, where `-r` is supported as `--unwrapScalar` (e.g., `yq eval -r ...`), and this usage is covered/validated by the Platform Admissibility CI job.

Applied to files:

  • scripts/platform-tenant-envelope-contract.test.sh
  • scripts/platform-tenant-envelope.test.sh
🔇 Additional comments (6)
.github/workflows/validate-scaffold.yaml (1)

18-18: LGTM!

Also applies to: 38-39

README.md (1)

77-77: LGTM!

scripts/platform-tenant-envelope-contract.test.sh (1)

39-42: LGTM!

Also applies to: 67-107, 216-219, 229-231, 243-243

scripts/platform-tenant-envelope.test.sh (3)

132-148: LGTM!

Also applies to: 242-242


351-465: LGTM!

Also applies to: 580-580


66-71: 🎯 Functional Correctness

No issue: rename-placeholders.sh already anchors deploy/ to its own directory.

			> Likely an incorrect or invalid review comment.

Comment thread scripts/platform-tenant-envelope.test.sh
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Updated readiness evidence

Reviewed commit: 767e3af06d7c2782b27cf8c188864823bf0415f2

  • CodeRabbit's prior-head finding reproduced: an unrelated ascoachingogvaner-legacy role caused a false duplicate. The new compatibility control failed before the fix and passes after anchoring the role command to its continuation boundary.
  • The complete documented local suite passes: Kustomize render, rename, agent instructions, tenant CI, Pod Security, tenant RBAC, Platform envelope, Platform network floor, Actionlint, changed-script ShellCheck, and git diff --check.
  • The behavioral contract passes against Platform main 6b67c9454e73fe7faf94d3be39bf874ba194b8e1 with 70 negative mutations plus the new prefix-isolation control.
  • From a separate archive pinned to this exact commit, the real rename helper changed eight files, Kustomize rendered, and the effective role, ServiceAccount, and apps/ascoachingogvaner/config key matched Platform. The complete behavioral contract then passed from that renamed checkout.
  • The prior review thread is answered and resolved. This comment requests a fresh exact-head review before promotion.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown

@devantler I’ll review the current PR head, focusing on the OpenBao authorization validation and its fail-closed tenant-isolation guarantees.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 767e3af06d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/validate-scaffold.yaml Outdated
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Updated readiness evidence

Reviewed commit: fa7db78c150bc64cbe70c5abd6965226ac513e15

  • CodeRabbit's prior-head finding reproduced: an unrelated ascoachingogvaner-legacy role caused a false duplicate. The new compatibility control failed before the fix and passes after anchoring the role command to its continuation boundary.
  • The complete documented local suite passes: Kustomize render, rename, agent instructions, tenant CI, Pod Security, tenant RBAC, Platform envelope, Platform network floor, Actionlint, changed-script ShellCheck, and git diff --check.
  • The behavioral contract passes against Platform main 6b67c9454e73fe7faf94d3be39bf874ba194b8e1 with 70 negative mutations plus the new prefix-isolation control.
  • From a separate archive pinned to this exact commit, the real rename helper changed eight files, Kustomize rendered, and the effective role, ServiceAccount, and apps/ascoachingogvaner/config key matched Platform. The complete behavioral contract then passed from that renamed checkout.
  • Codex's cone-mode sparse-checkout finding reproduced as a structural-contract failure. The checkout now selects the containing vault-config directory; a separate cone-mode sparse checkout at Platform 6b67c9454e73fe7faf94d3be39bf874ba194b8e1 materialized job.yaml successfully.
  • Both prior review threads are answered and resolved. This comment requests a fresh exact-head review before promotion.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@codex review

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown

@devantler I’ll review the current PR head, with particular attention to the OpenBao authorization contract and tenant-isolation safeguards.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: fa7db78c15

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Promotion gate

Reviewed commit: fa7db78c150bc64cbe70c5abd6965226ac513e15

  • Exact-head required CI: green; mergeability: MERGEABLE / CLEAN.
  • Review: Codex reported no major issues at fa7db78c15.
  • Hygiene: zero unresolved review threads and no current-head review findings.
  • CodeRabbit: final-head review was rate-limited after an internal provider error; its context is now success with Review rate limited. This is provider quota, not a code verdict, and is excluded per the repository contract / monorepo #2344.
  • Pre-merge: not-posted at the final head because CodeRabbit demonstrably did not review it; the green came from the Codex lane.
  • User evaluation: a real cone-mode Platform sparse checkout materialized vault-config/job.yaml; a separate exact-head tenant archive renamed, rendered, exposed the expected OpenBao identity/path, and passed the 70-mutation behavioral contract.

All genuine-readiness conditions are satisfied; promoting this routine-owned draft.

@devantler
devantler marked this pull request as ready for review July 22, 2026 08:18
@devantler
devantler requested a review from a team as a code owner July 22, 2026 08:18
@devantler
devantler merged commit daedcb4 into main Jul 22, 2026
15 checks passed
@devantler
devantler deleted the codex/tenant-openbao-auth-contract-105 branch July 22, 2026 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate tenant OpenBao authorization against Platform

1 participant