Skip to content

docs: keyless clearance — Tailscale login via AWS Roles Anywhere + STS OIDC#16

Merged
jonatw merged 6 commits into
mainfrom
docs-keyless-clearance
Jul 25, 2026
Merged

docs: keyless clearance — Tailscale login via AWS Roles Anywhere + STS OIDC#16
jonatw merged 6 commits into
mainfrom
docs-keyless-clearance

Conversation

@jonatw-eagle

@jonatw-eagle jonatw-eagle Bot commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

Aviation/diplomacy-flavored foreign-policy note: how an openab agent gets a keyless identity — no long-lived AWS key, tailnet auth-key, or GitHub PAT.

Chain: IAM Roles Anywhere (X.509 → AWS identity) → sts:GetWebIdentityToken (AWS Outbound Identity Federation; STS as managed OIDC IdP) → Tailscale Workload Identity Federation (tag-scoped short-lived token).

Quality: facts cross-checked vs official AWS/Tailscale docs; adversarially reviewed by the advisor panel (facts / security / honesty); claims tagged Today / Proposed / Vision; blast-radius & residual-risk section included.

Redaction: account, client-id, exact ARNs, cert expiry, host & role names placeholdered for this public copy; local redaction scanner run — no HARD hits.

Human-gated — review & merge at your discretion.

🤖 Generated with Claude Code

jonatw-eagle Bot and others added 6 commits July 25, 2026 04:26
…ywhere × STS OIDC)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…nverified storage-path assertion)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
… add NOTAM reference link

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…obroker#54 refs

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…lders)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@jonatw
jonatw merged commit 4c7d91b into main Jul 25, 2026
2 checks passed
@jonatw
jonatw deleted the docs-keyless-clearance branch July 25, 2026 04:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant