Model infrastructureSecurity
Credentials and state
Configure workload identity, capability maps, and the non-secret journal without widening the secret boundary.
Credentials and state — contract and behavior
- SKARBIEC_CAP_SOCKET, SKARBIEC_WORKLOAD_ID, and SKARBIEC_WORKLOAD_SIGNING_KEY_FILE form the canonical workload identity.
- The signing-key file must be a regular owner-owned file with no group or other permissions.
- BRAMA_REQUEST_SIGN_CAPABILITY_IDS binds agents to request-sign capabilities; BRAMA_PROVIDER_CAPABILITY_IDS binds providers or subscriptions to credential capabilities.
- Capability IDs are opaque 64-character lowercase hexadecimal handles; missing, malformed, or mistargeted bindings fail closed.
- BRAMA_STATE_DIR defaults to $HOME/.brama and may contain only retirement and task-quality records.