Trust begins with separation

Human authentication, SCIM provisioning, password delivery, OIDC token exchange, FreeIPA writes, Foreman enrichment, SSH and Guacamole access, power control, and database maintenance use different credentials, protocols, and privilege boundaries.

Secret and evidence controls

Control boundaries

BoundaryAuthority and control
Human identityExternal identity provider and MFA; FreeSCIM validates trust and governs the application session.
ProvisioningSCIM bearer ingress with schema, filter, mapping, lifecycle, password, and replay controls.
Linux identityFreeIPA remains the directory, Kerberos/POSIX, HBAC, group, and authorization authority.
Host enrichmentForeman and Puppet facts enrich inventory without silently replacing reviewed operational records.
Remote supportDedicated jump and relay paths, scoped identities, short-lived launches, and workstation-specific readiness.
DatabasePreview, approval, backup, advisory locking, destructive-SQL blocking, retention policy, and verification are implemented. Current schema and maintenance findings remain visible as needs-attention state rather than being hidden behind a healthy label.

Evidence status

The public site separates Core, Operational, Governed, Needs attention, and Roadmap. A feature can be implemented while still blocked from production authority, and a provider can exist in the onboarding framework without being a live integration.

Review the runtime truth ledger.

Password authority remains staged

Password material is handled only inside an eligible transaction and is excluded from durable evidence. Observe and dry-run controls have direct proof. The real upstream password event, real directory password write, and post-write rollback have not yet earned end-to-end proof, so the trust model keeps those milestones visibly blocked rather than treating implemented machinery as completed authority migration.

Fail closed, explain clearly

Missing policy, route readiness, privilege, jump reachability, migration safety, or proof evidence should block the action and tell the operator why. A visible gate is a security feature, not an unfinished product state.