Human Identity and Workload Identity Should Not Share an Auth Method
OIDC fits interactive operators; AppRole fits non-interactive services. Combining them weakens both lifecycle models.
TOPIC
Lessons, explainers, experiments, and implementation notes.
OIDC fits interactive operators; AppRole fits non-interactive services. Combining them weakens both lifecycle models.
Separating the main secret authority from the Transit seal service improves trust boundaries, but both still share the same physical host failure domain.
Scanning the QR code transfers long-lived secret material; it should be treated more carefully than an ordinary setup screen.
One identity portal can protect many subdomains only if browser cookie scope and request behavior match the intended trust boundary.
Keeping versions makes rotation and rollback explicit instead of overwriting the only known credential value.
I can send SSH packets over the tailnet without asking Tailscale to become the SSH authentication system.
Synthetic health checks normally have no browser cookie, so anonymous AuthRequest logs can be completely healthy behavior.
OpenBao adds identity, policy, versioning, leases and audit around secrets instead of merely moving plaintext to a different file.
The same-host seal service removes manual unseal entry, but its static key remains a temporary bootstrap root of trust on the same failure domain.
The difference between operator, runtime and backup identities is visible in the exact OpenBao paths and capabilities they receive.
A session can have an idle timeout, a hard lifetime and a trusted-browser persistence policy at the same time.
A correct TOTP secret can still fail when the verifier and authenticator disagree about time.
Losing the authenticator device creates a second-factor recovery problem that should not silently collapse to the password path.
TOTP is not a random six-digit number every half minute; it is a deterministic moving-factor calculation with a strict verifier window.
Human federation should be added after the secret authority is stable, not mixed into the initial bootstrap trust ceremony.
The six-digit code comes from a shared TOTP secret and time step; Google Authenticator is only one compatible client.
We often treat a phone number as if it were a permanent identity. In reality, it is a communication address whose user can change, whose access can be lost, and whose presentation can be misleading.
Workloads should authenticate to the secret authority with narrow machine identities rather than one credential copied across services.
Persistent SSO works better when ephemeral session state and durable identity-provider state are not confused.
Once the tailnet becomes a real operational network, who can reach which host and service should not live only in memory.
Putting MFA in front of each application separately creates duplicated policy; Authelia gives the protected subdomains one identity boundary.
The server needs its TLS private key to operate, while the CA private key is more powerful and should remain off-host.
A successful secret request is operationally normal and still important enough to leave durable evidence.