Skip to content

docs: runbook for learner-records partner credentials - #82

Open
blarghmatey wants to merge 2 commits into
mainfrom
docs/learner-records-credential-runbook
Open

blarghmatey wants to merge 2 commits into
mainfrom
docs/learner-records-credential-runbook

Conversation

@blarghmatey

Copy link
Copy Markdown
Member

What are the relevant tickets?

N/A. Follows the "client lifecycle" follow-up in docs/b2b-learner-records-provider-authorization.md.

Description (What does it do?)

Issuance, handoff, rotation and removal of the per-contract learner-records Keycloak clients had no owner. This adds docs/b2b-learner-records-credential-runbook.md and points the provider-authorization doc's follow-up at it.

Decisions recorded in it (maintainer, 2026-09-30):

  • The organization's opt-in is recorded on its contract in MITx Online. That field doesn't exist yet, so until it does the client PR links the written request.
  • Anyone files the ol-infrastructure PR. Platform engineering reviews it.
  • Handoff is Vault response wrapping first, then a LastPass share, then GPG-encrypted email.

Revocation and rotation take effect when the Keycloak stack deploys, not at merge: QA and Production in docker-packer-pulumi-keycloak wait on closing a ready to deploy bot issue. After that, issued tokens live up to 300 seconds (330 with #69's clock leeway). Rotation uses secret_version, which I added to mitodl/ol-infrastructure#5939 in this pass. Contract-end behaviour is written against #73 and says what holds until it merges.

How can this be tested?

Docs only. Config keys, the Vault path and its fields, the 300-second lifespan, the deploy gate, the API mount and the #69/#73 behaviour were checked against source, and a separate review pass checked the Vault wrap/lookup/unwrap and token commands against the Vault CLI source. vault-production.odl.mit.edu resolves on public DNS, but unwrapping from a partner's network hasn't been tried, and the smoke test hasn't run against a live client (none is configured in any environment yet).

https://claude.ai/code/session_01S7nfyd7Pky17JRQS3fUy1C

The provider-authorization doc left issuance, handoff, rotation and
contract-end removal of the per-contract Keycloak clients unassigned. This
writes them down: opt-in recorded on the MITx Online contract, anyone files
the ol-infrastructure PR and platform engineering reviews, handoff by Vault
response wrapping with LastPass and GPG email as fallbacks, and rotation by
bumping secret_version. QA and Production Keycloak deploys are gated on
closing a bot issue, so revocation takes effect at that deploy plus the
300-second token lifespan, not at merge.

Claude-Session: https://claude.ai/code/session_01S7nfyd7Pky17JRQS3fUy1C

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The handoff commands expose a credential token in process arguments, and removal timing conflicts with the documented inclusive contract end date.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds an operational runbook for learner-records partner credentials.

Changes:

  • Documents credential issuance, secure handoff, rotation, and revocation.
  • Links the authorization design document to the new runbook.
File Description
docs/​b2b-learner-records-credential-runbook.md Adds the credential lifecycle runbook.
docs/​b2b-learner-records-provider-authorization.md Links to the runbook.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/b2b-learner-records-credential-runbook.md Outdated
Comment thread docs/b2b-learner-records-credential-runbook.md Outdated
The partner's lookup and unwrap commands passed the wrapping token as a curl
argument, where another local process could read it and unwrap first. They
now read it without echo and pipe it on stdin. Planned removal said "on the
end date", which cuts a partner off before the inclusive, Anywhere-on-Earth
cutoff #73 enforces; it now deploys after 12:00 UTC the following day.

Claude-Session: https://claude.ai/code/session_01S7nfyd7Pky17JRQS3fUy1C

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants