Skip to content

docs: why not RBAC; server-side review caveats; warn on trusted source identities - #37

Merged
moneytool merged 1 commit into
mainfrom
docs-review-feedback
Oct 9, 2026
Merged

moneytool merged 1 commit into
mainfrom
docs-review-feedback

Conversation

@moneytool

Copy link
Copy Markdown
Owner

This applies two of the specs from the promotion session (build/promo/SPEC-readme-why-not-rbac.md and SPEC-server-side-review-notes.md). The third spec, the kubectl gaps, changes decisions and comes as its own PR.

README: "Why not RBAC, or the agent's own permission settings?"

  • Placement: the new section sits immediately before "Why not OPA/Gatekeeper?", and the intro paragraph gets one line linking to it. The anchor matches the heading GitHub generates.
  • Table re-run: I ran every row again on 2026-10-08 against current main.
    • All seven kubectl spellings and the git row still BLOCK with the stated rule. The first six kubectl rows also cite plan-k8s-delete-ratio, so they still read "same rule".
    • K=kubectl; $K … makes aegis check exit 64. The hook denies it with "without shell expansion".
    • The header now says "Aegis with the example policy" without a version number. A new test, test_readme_spelling_table_still_holds, runs every row, so the table can't go stale silently.
  • The Claude Code quote: it is verbatim on the live page under "What a Bash rule doesn't match", checked 2026-10-08, and now links to #bash-rule-limits.
  • Other claims: I checked these against the code. The impersonation rule exists (block-kubectl-impersonation), as does the database plan rule (plan-no-db-deletes). audit-identity kubernetes checks impersonation, admission-policy writes and escalate.
  • docs/index.md: it has no comparison sections, so the spec's optional change 3 doesn't apply.

Server-side caveats (review of the AWS SCP article by dev.to reader mickyarun)

  • Second layer: docs/server-side.md now says what the second layer adds and what it doesn't. It is one signed policy enforced twice, not a second opinion. Keep an independently written guardrail alongside it.
  • Source identities: a new section, "Trusted source identities", explains that a source identity survives role chaining, so an agent started in a developer's session inherits the exemption. The self-protection block only stops an agent setting one.
  • Warning in agents.yaml:
    • The spec asked for a warning whenever a source identity is trusted. aegis agents exits 1 on any warning, though, so an always-on warning could never be cleared.
    • Instead, a trusted AWS source-identity warns (source-identity-inherited) until its entry says no_agents: true. That is an explicit, signed statement that no agent runs under it.
    • The field is valid only on a trusted source-identity; anywhere else it is a load error. The example agents.yaml uses it, with a comment, and is re-signed with the example key.
  • Roadmap: PLAN item 12 adds denial reporting from CloudTrail. I checked the message format in the IAM guide first: "with an explicit deny in a service control policy", sometimes followed by the policy ARN, with no statement ID, and some services use a different format. The item says attribution is exact only when the ARN is present.

Tests

The full suite passes locally (1,913) and ruff is clean. New tests: the README table, the warning, the acknowledgement, and the places no_agents is rejected.

…e identities

- README: 'Why not RBAC, or the agent's own permission settings?' with
  the spelling table, re-run against main; test keeps it true
- docs/server-side.md: second layer is one policy enforced twice; a
  trusted source identity must never carry an agent
- agents.yaml: source-identity-inherited warning, cleared by an explicit
  'no_agents: true' on the entry; example updated and re-signed
- PLAN: denial reporting from CloudTrail (SCP explicit-deny message
  format checked in the IAM guide)
@moneytool
moneytool merged commit 8e5fca2 into main Oct 9, 2026
9 checks passed
@moneytool
moneytool deleted the docs-review-feedback branch October 9, 2026 02:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant