Skip to content

The CA and the role

The CA key is generated inside OpenBao (generate_signing_key = true, ed25519) and cannot be read out of it — not by an admin, not by OpenTofu. Losing OpenBao's storage therefore means a new CA on the next apply. Hosts pick the new public key up on their next fetch, within fifteen minutes, and certificates signed by the old one stop working; at a five-hour lifetime that costs one re-sign.

The admin signing role:

Setting Value Why
allowed_users root,cbc the accounts that exist on the hosts; no default, so the caller always names one
ttl, max_ttl 5h expiry replaces revocation
allowed_extensions permit-pty an interactive shell and nothing else — no forwarding
key_id_format {{token_display_name}} oidc-<username> for an OIDC login; OpenBao does not allow identity templates here

The policy ssh-sign-admin grants update on ssh/sign/admin and nothing more. 50_authentik-config attaches it to the OIDC role by name, so the two roots can be applied in either order: until the policy exists, tokens simply lack it.