Automation Needs a Permission Model
Automation should be fast inside a narrow authority boundary rather than powerful enough to mutate anything.
Automation should be fast inside a narrow authority boundary rather than powerful enough to mutate anything.
Convenient arbitrary shell access would collapse the separation between reviewed operations and unrestricted host control.
The strictest-looking file mode is not automatically the safest usable mode when a non-root service must read the key.
Least-privilege monitoring sometimes cannot read protected backup evidence, and treating that access failure as healthy would be dangerous.
Browser-side health checks needed cross-origin access, but the fix was two explicit origins rather than a broad wildcard.
The difference between operator, runtime and backup identities is visible in the exact OpenBao paths and capabilities they receive.
Copying every application database password into the observability stack would have expanded the secret blast radius just to collect metrics.
Protected evidence that a low-privilege checker cannot read should not be reported as healthy or corrupt.
Workloads should authenticate to the secret authority with narrow machine identities rather than one credential copied across services.
Operators need evidence that backups succeeded without necessarily gaining access to the protected data itself.