OIDC-Scoped RBAC & Workload Identity
Tenant-isolated, OIDC-scoped access control and SPIFFE/SPIRE workload identity.
- Every REST endpoint requires a JWT Bearer token with OIDC scopes and a mandatory tenant claim, validated before any scope check.
- Roles — Admin, Maintainer, Viewer — are pre-bundled scope sets, not role-name checks.
- A nested-trust-domain SPIRE deployment under the spiffe://penguintech.io/<env>/<service> scheme is wired into the Manager, PKI, s3scan, and vault-sync services.
- S3 credentials and other sensitive material are encrypted at rest; secrets are never persisted in plaintext.