docs: runbook for learner-records partner credentials - #82
Open
blarghmatey wants to merge 2 commits into
Open
blarghmatey wants to merge 2 commits into
blarghmatey wants to merge 2 commits into
Conversation
The provider-authorization doc left issuance, handoff, rotation and contract-end removal of the per-contract Keycloak clients unassigned. This writes them down: opt-in recorded on the MITx Online contract, anyone files the ol-infrastructure PR and platform engineering reviews, handoff by Vault response wrapping with LastPass and GPG email as fallbacks, and rotation by bumping secret_version. QA and Production Keycloak deploys are gated on closing a bot issue, so revocation takes effect at that deploy plus the 300-second token lifespan, not at merge. Claude-Session: https://claude.ai/code/session_01S7nfyd7Pky17JRQS3fUy1C
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The handoff commands expose a credential token in process arguments, and removal timing conflicts with the documented inclusive contract end date.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds an operational runbook for learner-records partner credentials.
Changes:
- Documents credential issuance, secure handoff, rotation, and revocation.
- Links the authorization design document to the new runbook.
| File | Description |
|---|---|
docs/b2b-learner-records-credential-runbook.md |
Adds the credential lifecycle runbook. |
docs/b2b-learner-records-provider-authorization.md |
Links to the runbook. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
The partner's lookup and unwrap commands passed the wrapping token as a curl argument, where another local process could read it and unwrap first. They now read it without echo and pipe it on stdin. Planned removal said "on the end date", which cuts a partner off before the inclusive, Anywhere-on-Earth cutoff #73 enforces; it now deploys after 12:00 UTC the following day. Claude-Session: https://claude.ai/code/session_01S7nfyd7Pky17JRQS3fUy1C
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


What are the relevant tickets?
N/A. Follows the "client lifecycle" follow-up in
docs/b2b-learner-records-provider-authorization.md.Description (What does it do?)
Issuance, handoff, rotation and removal of the per-contract learner-records Keycloak clients had no owner. This adds
docs/b2b-learner-records-credential-runbook.mdand points the provider-authorization doc's follow-up at it.Decisions recorded in it (maintainer, 2026-09-30):
Revocation and rotation take effect when the Keycloak stack deploys, not at merge: QA and Production in
docker-packer-pulumi-keycloakwait on closing aready to deploybot issue. After that, issued tokens live up to 300 seconds (330 with #69's clock leeway). Rotation usessecret_version, which I added to mitodl/ol-infrastructure#5939 in this pass. Contract-end behaviour is written against #73 and says what holds until it merges.How can this be tested?
Docs only. Config keys, the Vault path and its fields, the 300-second lifespan, the deploy gate, the API mount and the #69/#73 behaviour were checked against source, and a separate review pass checked the Vault wrap/lookup/unwrap and token commands against the Vault CLI source.
vault-production.odl.mit.eduresolves on public DNS, but unwrapping from a partner's network hasn't been tried, and the smoke test hasn't run against a live client (none is configured in any environment yet).https://claude.ai/code/session_01S7nfyd7Pky17JRQS3fUy1C