Skip to content

Add 03-use-cases/keyless-clearance.md (keyless access for off-cloud a…#3

Open
jonatw wants to merge 1 commit into
shaun-agent:mainfrom
jonatw:keyless-clearance-usecase
Open

Add 03-use-cases/keyless-clearance.md (keyless access for off-cloud a…#3
jonatw wants to merge 1 commit into
shaun-agent:mainfrom
jonatw:keyless-clearance-usecase

Conversation

@jonatw

@jonatw jonatw commented Jul 25, 2026

Copy link
Copy Markdown

Adds a new 03-use-cases/ page: Keyless Access for Off-Cloud Agents — how an openab agent running outside AWS obtains scoped, short-lived credentials for AWS, a Tailscale tailnet, and GitHub with no long-lived secret in the container (IAM Roles Anywhere → STS Outbound Identity Federation → Tailscale WIF).

Source

Converted from an existing writeup — keyless-clearance.md — and rewritten to fit openab-map's use-case conventions:

  • Neutral, third-person technical voice matching the other 03-use-cases pages (schedule-agent-tasks, deploy-multi-agent) — no first-person or personal attribution.
  • Dropped the source's extended metaphor; kept the mechanics, the [Today] / [Proposed] / [Vision] maturity tags, a reference config, an adversarial risk section, and a component table.
  • Framed explicitly as a community-contributed pattern, not an openab-official standard.
  • Cross-repo references use full URLs; a Related footer links the sibling use-cases and the core "own the layers above" doc.

Review ask

Please review for fit and accuracy — happy to adjust voice, depth, or placement.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant