Cov kev tswj hauv ntu 14 ntawm 21-compliance.md uas tus tshuaj xyuas thov npe meej. Nplooj no yog txheej txheem; cov ntaub ntawv uas nws tsim yog pov thawj.
Cov key
Txhua credential khaws cia raug foob siv data encryption key (DEK) tshiab. Master key (KEK) qhwv DEK, thiab nws tus cim khaws ib sab (key_ref, lossis tus cim hauv packed value). Hloov master key tsuas rov qhwv DEK xwb. Nws tsis decrypt lossis rov encrypt credential.
| Chaw teeb tsa | Lub ntsiab lus |
|---|---|
QUIRE_MASTER_KEY |
Master key tam sim no: 32 byte, base64. Secret tshiab raug qhwv hauv qab nws |
QUIRE_MASTER_KEY_VERSION |
Cim version. Yog tsis teeb ces v1. Nce thaum twg hloov key |
QUIRE_MASTER_KEY_RETIRED |
Key qub uas tej secret tseem siv tau: v1=<base64>,v0=<base64>. Nyeem xwb, tsis sau |
Web tier, worker thiab command bun run kek:rotate nyeem tib peb qhov setting. Lawv yuav tsum muaj tib tus nqi, yog tsis li ib qhov qhib tsis tau yam uas lwm qhov foob.
Yog tsis muaj QUIRE_MASTER_KEY, txhua subsystem khaws key uas nws tsim los ntawm QUIRE_SECRET_KEY. Qhov no ua haujlwm, nplooj System health qhia tias qib kev noj qab haus huv poob, thiab tom qab koj teeb master key nws tseem nyeem tau; thawj qhov hloov key siv qhov no tshem txhua yam tawm. Txhua tus nyeem process environment tau decrypt tau txhua credential khaws cia, yog li production installation yuav tsum muaj master key hauv secret store, tsis txhob khaws nrog database hauv tib thaub qab.
Hloov key
Hnub nyoog key qhia hauv Platform console, Security, Master key thiab metric quire.secrets.master_key.age (hnub). Txhua hnub schedule platform.key_age (03:41 UTC) ntxiv lus ceeb toom rau platform audit chain thaum key muaj 365 hnub, ces rov ceeb toom txhua 30 hnub txog thaum hloov. Hloov thaum ceeb toom tuaj thiab txhua zaus uas tej zaum key xau.
- Tsim key tshiab:
openssl rand -base64 32. - Teem
QUIRE_MASTER_KEYua key ntawd thiabQUIRE_MASTER_KEY_VERSIONua cim tom ntej (v2). Muab key qub tso rauQUIRE_MASTER_KEY_RETIREDuav1=<old base64>. Khaws ob key lwm qhov uas tsis yog host no. - Deploy web tier thiab worker nrog setting tshiab. Secret tshiab raug qhwv hauv
env:QUIRE_MASTER_KEY:v2; secret qub tseem qhib tau ntawm key retired. - Thov hloov key nrog laj thawj uas yuav khaws hauv audit trail:
- hauv console: Security, Master key, Rotate the master key; lossis
- hauv shell siv environment tib yam:
bun run kek:rotate request --reason "Annual rotation, ticket SEC-114".
- Worker rov qhwv ib feem txhua feeb (schedule
platform.key_rotation) thiab rov ua haujlwm tom qab restart. Xav ua kom tag ib zaum:bun run kek:rotate run. Saib xwm txheej sivbun run kek:rotate status. - Thaum record qhia tias hloov tiav nrog zero unresolved thiab zero failed, rho key retired ntawm
QUIRE_MASTER_KEY_RETIREDthiab deploy dua. Txog thaum ntawd cia nws nyob: tus nqi uas txav tsis tau tseem raug qhwv nrog key qub.
Yam uas haujlwm ntsuam
Txhua store uas muaj DEK qhwv: cov uas teev hauv SEALED_STORES (apps/worker/src/key-rotation.ts). Taug cov store ntawm control database hauv control database; taug cov store koom haum ib koom haum zuj zus raws row-level security, hauv database uas khaws koom haum ntawd, kom tenant pinned rau database tshwj xeeb hloov hauv database ntawd. Test yuav poob yog schema ntxiv wrapped-key column uas daim npe tsis hais txog; lwm test poob yog credential review cais sealed column uas daim npe plam.
Daim record
ops.key_rotation: ib kab rau txhua qhov hloov key, nrog laj thawj, tus thov, xwm txheej thiab tag nrho lej (rov qhwv, twb tshiab, daws tsis tau, poob).ops.key_rotation_progress: ib kab rau txhua store thiab scope tom qab taug, nrog key reference uas nyeem tsis tau thiab pes tsawg tus nqi hauv qab txhua reference. Thaum rov khiav qhov hloov, hla cov no.- Platform audit chain:
platform/key_rotation_request(nrog laj thawj), ibplatform/key_rotation_storerau txhua store nrog nws cov lej, thiabplatform/key_rotation_completelossisplatform/key_rotation_fail; lus ceeb toom yogplatform/key_age_reminder. - Metrics:
quire.secrets.master_key.agethiabquire.secrets.rewrap.outstanding(cov nqi uas hloov zaum kawg txav tsis tau).
Thaum muaj tus nqi daws tsis tau
Tus nqi daws tsis tau yog raug qhwv nrog key reference uas qhov kev nruab no tsis muaj, lossis nws daim ntawv tsis phim qhov column cog lus. Progress record qhia reference (piv txwv env:QUIRE_MASTER_KEY:v0 (unreadable)). Ntxiv key ntawd rov rau QUIRE_MASTER_KEY_RETIRED thiab hloov dua, lossis yog key ploj lawm tiag tiag, kom tus thawj coj ntawm koom haum sau credential tshiab; nws mam raug foob siv key tam sim no. Kev hloov uas poob qhia error hauv record; kho qhov ua rau thiab thov dua.
Signing key
Cais ntawm master key: txhua koom haum kos npe rau OpenID Connect token thiab LTI lus nrog RSA key nyias, tshaj tawm ntawm /.well-known/jwks.json. Tus operator tsis tas ua dab tsi ntawm no. Schedule platform.signing_keys khiav txhua teev tshaj tus successor xya hnub ua ntej key tam sim no muaj cuaj caum hnub; ib lim tiam tom qab successor pib kos npe thiab key qub hloov ua retiring; cuaj caum hnub tom qab ntawd key qub raug rho tawm thiab ploj ntawm key set. Txhua kauj ruam teev ua platform/signing_key_advance hauv platform audit chain.
Yog xav hloov key ntawm koom haum ua ntej, xws li key xau:
- hauv console: Security, Master key, Publish a new signing key (xav tau
platform/keys_manage); lossis - hauv shell nrog environment ntawm worker:
bun run kek:rotate signing-keys rotate --tenant <slug or id> --reason "Key exposed, INC-3310".bun run kek:rotate signing-keys statusteev key koom haum txhua qhov raws theem.
Key tshiab tshaj tawm tam sim thiab pib kos npe tom qab xya hnub, thaum key tam sim no so. Tos ib lim tiam yog txhob lam: relying party cache key set, thiab lub sijhawm sib tshooj luv dua yuav ua rau txhua tool poob ib zaug. Key retiring tseem nyob hauv key set cuaj caum hnub ntxiv kom token uas nws twb kos tseem kuaj tau; yog qhov xau txhais tias yuav tsum tso kev ntseeg tseg sai dua, rho nws row yog ib qho hloov uas ua nrog operator tus database access raws change record (break-glass access nyeem xwb), ces token kos nrog key ntawd kuaj tsis dhau. Kev hloov yuam yog platform/signing_key_rotate hauv audit chain nrog laj thawj. Worker yuav tsum muaj QUIRE_MASTER_KEY settings tib yam li web tier kom qhwv key tshiab; bun run kek:rotate rau master key kuj rov qhwv signing key nrog lwm yam (oauth_signing_key nyob hauv SEALED_STORES).
Kev nkag production thaum muaj xwm ceev
Tsis muaj leej twg muaj kev nkag production tas mus li. Thaum muaj teeb meem tos tsis tau, owner muab break-glass grant: Platform console, Security, Break-glass access.
- Grant muaj scope (ib lub koom haum lossis platform registry), laj thawj tsawg kawg 20 cim uas teev incident lossis ticket, thiab sijhawm 5 txog 240 feeb. Nws tas cia li; xyuas lub sijhawm txhua zaus khiav statement.
- Muab rau owner uas thov lossis lwm owner tau (ob tug neeg). Tsuas tus neeg tau txais siv tau. Kev muab yuav tsum muaj
platform/break_glass_issue, kev siv yuav tsum muajplatform/break_glass_use; raws qhov qub ob qho tsuas yog owner. - Statement khiav ntawm gateway, tsis yog database login: nyeem xwb, ib zaug zuj zus, txwv rau koom haum lossis control registry, timeout tsib vib nas this thiab ntau kawg 500 row. Binary value qhia raws loj.
- Platform audit chain sau kev muab (nrog laj thawj), kev rho tawm, txhua statement ua ntej khiav (
platform/break_glass_statement, qhov tsis txais teev outcomedenied) thiab txhua txiaj ntsig (platform/break_glass_result).ops.break_glass_statementkhaws audit entry ID kom record muab txuas rau audit entries. - Tsis muaj write. Hloov uas tos tsis tau release yuav siv operator tus kheej database access raws change record, sab nraum product no, thiab record yuav tsum hais txog incident reference ntawm no.
Vim li cas tsis muab database credential: Postgres login nyob ntev dua session thov nws, hla row-level security uas app siv, thiab sau tsis tau rau audit chain ntawm product, ces statement tsuas raug tshuaj xyuas txog thaum ib tug xa server log xwb. Gateway ua kom audit trail yog ib feem ntawm kev nkag, es tsis yog ib qho kev coj ua nyob ib sab.
Teb audit request: teev grant hauv lub sijhawm ntawd (Break-glass access), qhib keeb kwm grant saib statement thiab audit entry ID, ces nyeem cov entry hauv platform audit chain (bun run audit:verify --platform ua pov thawj tias chain tseem ruaj).