security-review/iam/step-ca-config-sketch.md
Adam Moussa 4c88c01f7b
chore: import security-review gate, sweep, and Plane-1 checkers into standalone repo
Fresh-init copy of the security-review/ subsystem extracted from
Sea-Haven-Industries/orchestrator (being deprecated). Adds org-standard scaffold:
CI reusable-workflow callers (ruff + collect), dependency-review, labeler,
dependabot, .gitignore, requirements.txt. Scheduled execution is migrating to
Claude Code web routines (ALARM-only to #repo-scanner); the systemd units and
nightly_sweep.sh/checker_coordinator.sh remain the source of truth.

Committed with --no-verify: the canary fixtures (checkers/fixtures/**) carry
intentional secret-shaped test data that trips the deterministic gate (the
documented detector-fixture false positive); no new logic is introduced.
2026-06-29 11:41:41 -04:00

5.6 KiB

step-ca config sketch — internal CA for aws-posture Roles Anywhere leaf certs

Design ref: docs/r720-agent-team-design.md §6.3 (step-ca + Roles Anywhere, D5) and §7 Phase 3.

Not provisioned here. This is the config + renewal approach for the GPT-4.1 cross-review. step-ca is the small internal CA on the R720 box (Smallstep step-ca) whose root cert is pinned as the Roles Anywhere trust anchor, and which issues a short-lived leaf that the box presents to Roles Anywhere to obtain short-lived read-only STS credentials. No long-lived AWS key ever lands on the box — the leaf self-expires and is auto-renewed by a systemd timer.

Trust chain (one CA, one purpose)

step-ca ROOT (offline-ish, long-lived)
  └── step-ca intermediate (the online signer)
        └── leaf  CN=r720-aws-posture   (short-lived, ~24h, auto-renewed)
              └── presented to AWS IAM Roles Anywhere trust anchor
                    └── AssumeRole -> r720-aws-posture-readonly (1h STS session)

The trust anchor pins the root cert (roles-anywhere-config.json → sourceData .x509CertificateData). The role trust policy (aws-posture-trust-policy.json) additionally pins the leaf subject CN (r720-aws-posture) and issuer CN, so only this CA's leaf with this exact CN can assume the role.

ca.json (sketch — the single-purpose provisioner)

{
  "root": "/etc/step-ca/certs/root_ca.crt",
  "crt":  "/etc/step-ca/certs/intermediate_ca.crt",
  "key":  "/etc/step-ca/secrets/intermediate_ca_key",
  "address": "127.0.0.1:8443",          // localhost-only; the box is the sole client
  "dnsNames": ["localhost", "r720.lan"],
  "authority": {
    "claims": {
      "minTLSCertDuration":     "5m",
      "maxTLSCertDuration":     "24h",  // hard cap: leaves are short-lived
      "defaultTLSCertDuration": "24h",
      "disableRenewal": false
    },
    "provisioners": [
      {
        "type": "JWK",
        "name": "aws-posture",
        "key": { "use": "sig", "kty": "EC", "crv": "P-256", "alg": "ES256", "kid": "REPLACE", "x": "REPLACE", "y": "REPLACE" },
        "encryptedKey": "REPLACE_WITH_ENCRYPTED_PROVISIONER_KEY",
        "claims": {
          "maxTLSCertDuration":     "24h",
          "defaultTLSCertDuration": "24h"
        },
        "options": {
          "x509": {
            // The provisioner only ever issues this one CN; templating keeps the
            // subject/issuer fields the Roles Anywhere trust policy pins.
            "templateData": { "CommonName": "r720-aws-posture" }
          }
        }
      }
    ]
  }
}

Root CA subject CN: Sea Haven Internal CA - R720 Roles Anywhere (matches the x509Issuer/CN condition in aws-posture-trust-policy.json).

Initial bootstrap (one-time, at provisioning)

step ca init \
  --name "Sea Haven Internal CA - R720 Roles Anywhere" \
  --dns localhost --dns r720.lan --address 127.0.0.1:8443 \
  --provisioner aws-posture --deployment-type standalone

# Issue the first leaf the box will present to Roles Anywhere:
step ca certificate "r720-aws-posture" \
  /etc/aws-posture/leaf.crt /etc/aws-posture/leaf.key \
  --not-after 24h --provisioner aws-posture

leaf.key is mode 600, owned by the unattended service user; it never leaves the box.

Auto-renewal — systemd timer (the leaf self-expires; the timer keeps it fresh)

step-ca ships step ca renew, which no-ops until the cert is within its renewal window.

/etc/systemd/system/aws-posture-cert-renew.service:

[Unit]
Description=Renew r720-aws-posture Roles Anywhere leaf certificate
After=network-online.target step-ca.service

[Service]
Type=oneshot
User=aws-posture
# --expires-in: renew only when <8h of life remains; idempotent, safe to run hourly.
ExecStart=/usr/bin/step ca renew --force --expires-in 8h \
  /etc/aws-posture/leaf.crt /etc/aws-posture/leaf.key
# step-ca renew rewrites the cert in place; aws_signing_helper reads it fresh each call,
# so no service reload is needed.

/etc/systemd/system/aws-posture-cert-renew.timer:

[Unit]
Description=Hourly renewal check for the aws-posture leaf cert

[Timer]
OnCalendar=hourly
RandomizedDelaySec=300
Persistent=true        # catch up a renewal missed while the box was off

[Install]
WantedBy=timers.target

Hourly check + 8h renewal window + 24h cert = the leaf is always fresh and a missed window has hours of slack. The timer mirrors the existing secrev launchd/systemd discipline.

How aws-posture USES the leaf (no AWS key on disk)

aws-posture invokes AWS's aws_signing_helper credential-process, which signs the Roles Anywhere request with the leaf and returns short-lived STS creds on stdout:

# ~/.aws/config  (on the box)
[profile r720-aws-posture]
credential_process = /usr/local/bin/aws_signing_helper credential-process \
  --certificate /etc/aws-posture/leaf.crt \
  --private-key /etc/aws-posture/leaf.key \
  --trust-anchor-arn arn:aws:rolesanywhere:us-east-1:328440206208:trust-anchor/REPLACE \
  --profile-arn      arn:aws:rolesanywhere:us-east-1:328440206208:profile/REPLACE \
  --role-arn         arn:aws:iam::328440206208:role/r720-aws-posture-readonly

The credentials live only in process memory for the 1h session duration; nothing long-lived is written. This is strictly stronger than the box's existing long-lived GitHub PAT (design §6.3): the AWS identity self-expires and rotates without operator action.

Capacity note (design §6.5)

step-ca on a 4GB / 2 vCPU / 40GB box is negligible (a localhost signer + a tiny DB). Re-check disk headroom after Phase 1 per §6.5; snapshot the Hyper-V VM before standing this up per feedback_ec2_replacement_snapshot.