Add resource secret epoch metadata

This commit is contained in:
Eric Wendland 2026-05-16 22:18:49 +02:00
commit a05112e6a2
12 changed files with 287 additions and 13 deletions

View file

@ -139,7 +139,9 @@ for CLI/control output, but it is not the signed representation.
The payload access plane is `geth-secrets`: resource master secrets, epochs,
key envelopes, bearer secrets, and rotation. Revocation for private data is
modeled initially as secret epoch rotation.
modeled initially as secret epoch rotation. The daemon persists resource secret
epoch metadata through `secret create/rotate/status`, but it does not yet store
payload key material, encrypt resource data, or distribute key envelopes.
## Multi-User Direction

View file

@ -174,12 +174,16 @@ resource-scoped capability decisions.
- `[ ]` Future completion requires signed-op validation before accepting
replicated auth ops.
- `[ ]` Resource secrets and bearer invites.
- `[~]` Resource secrets and bearer invites.
Acceptance criteria:
- Bearer secrets grant only resource-scoped capabilities.
- Bearer principals cannot mutate trust graph state by default.
- Secret epoch rotation is represented in durable metadata.
- Tests verify bearer access does not imply node identity.
- `[x]` `geth secret create <resource>` records resource secret epoch 1
metadata.
- `[x]` `geth secret rotate <resource>` records the next resource secret
epoch.
- `[x]` Secret epoch rotation is represented in durable metadata.
- `[ ]` Bearer secrets grant only resource-scoped capabilities.
- `[ ]` Bearer principals cannot mutate trust graph state by default.
- `[ ]` Tests verify bearer access does not imply node identity.
- `[~]` SSH certificate and revocation lifecycle.
Acceptance criteria: