Skip to content

feat(auth): non-JWT admin/bootstrap API key for direct operator access #240

Description

@EricAndrechek

Area: auth · ops — gap (operability) · from Eric's notes

Expected: the devops person running WaveHouse has a simple, role-free credential (an admin API key) for bootstrapping and direct admin access — setting policies, schema ops, DLQ — without minting a JWT.

Actual: all elevated access goes through a JWT whose role claim matches admin_role. There's no static admin key / bootstrap credential, so even initial setup and break-glass operator access require the JWT plumbing.

Scope: a configured admin API key (header/bearer) that grants admin without a role claim, for bootstrap + operator/break-glass use. This is effectively an admin secret — pairs with the key→role-binding and revocation thinking in #228.

Related: auth-hardening epic #228; policy bootstrap seed-vs-SoT #229.


From Eric's notes scratchpad; triaged 2026-06-04.

Activity

  1. added
    enhancementNew feature or request
    area/apiHTTP handlers, routing, middleware
    area/policyAccess control policies (Hasura-style)
    securitySecurity-sensitive issue or fix
    on Jun 4, 2026
  2. coderabbitai commented on Jun 4, 2026

    @coderabbitai
    🔗 Related PRs

    #172 - feat(rbac)!: fail-closed authorization + default_role public access [merged]


    📝 Issue Planner

    Check the box below or use the @coderabbitai plan command to generate an implementation plan and prompts that you can use with your favorite coding assistant.

    • Create Plan

    🧪 Issue enrichment is currently in open beta.

    You can configure auto-planning by selecting labels in the issue_enrichment configuration.

    To disable automatic issue enrichment, add the following to your .coderabbit.yaml:

    issue_enrichment:
      auto_enrich:
        enabled: false

    💬 Have feedback or questions? Drop into our discord!

  3. moved this from Backlog to In progress in WaveHouse Task Boardon Jul 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/apiHTTP handlers, routing, middlewarearea/policyAccess control policies (Hasura-style)breaking-changeBreaking change to public API, CLI, or configenhancementNew feature or requestsecuritySecurity-sensitive issue or fix

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions