AuthBox documentation — Scenarios

Documentation embedded in this build.

A federation across organisations

What it is for

Headquarters, a region and a partner lab: three organisations that have to work together and cannot merge their directories, because none of them will hand the others the keys to its own people. Each keeps its own authority and issues its own certificates.

A chain of authorities: headquarters publishes a signed bundle to a region, which republishes to an enclave, and every bundle carries an origin mark; a side lab on the other diagonal keeps its own authority, with its root appended to the trust pool rather than its data adopted

Records carry the origin they came from, so nobody is asked to believe a record without knowing whose it is, and trusting a partner's certificates for the handshake never means adopting the partner's data. A lapse anywhere is visible rather than silent: when one authority goes quiet, what it published stops conferring anything past its budget, and the console names which authority went stale and when.

This is not one directory with tenants in it. Each authority is its own box.

The topology

A chain of authorities, and one peer beside it that is trusted for the handshake only.

   HQ  --signed bundle-->  REGION  --republished-->  ENCLAVE
   own authority           own authority            own authority
                           carries HQ's records     carries both,
                           with HQ's origin         origins intact

   SIDE LAB                (on the other diagonal)
   own authority  --root appended to the trust pool-->  the handshake only
                    its DATA is never adopted

Every bundle carries an origin mark that survives each hop, and every hop has a freshness budget of its own.

Stand it up

$ make all-in-one-federated        # HQ, region, the enclave and a partner lab
$ make kind-all-in-one-federated   # the same chain on a kind cluster

Both leave a stack running and print a directory of every URL at the end. Expect a long first run: the composition mints its own PKI, stages every mount, pre-mints the first bundles and then walks its smokes in order.

What the smoke proves

The composition's first smoke is the cascade, and it is the federation's whole claim in one act: a record made live at headquarters through a door with no published port is drawn by the proxied console two hops away. Its Go twin is test/integration/federation/cascade_test.go, which proves the cascade and its provenance against the compiled binaries in seconds; the composed run asserts only what a composition adds — the port that is published, the address that is fixed, the mount that landed where the process reads.

Then, in order: a partner's credential refused at an edge whose trust pool is fixture only (cross_ca_login_test.go); two hierarchy models over artifacts minted at staging; a revocation list that reaches a container and comes into force on restart, with the responder answering on its published port (revocation_test.go); the authority lens, fetched at a fixed address, naming every authority and how fresh it is (lens_test.go); and the blast radius, which pauses one box and shows the two published readiness ports answering differently — the centre reports itself stale, the edge stays ready (blast_radius_test.go). The narrowness is the point being proved.

make kind-all-in-one-federated translates the same composition to manifests, applies it in waves, and runs the same phases against it.

Read on