Model infrastructureSecurity

Credentials and state

Configure workload identity, capability maps, and the non-secret journal without widening the secret boundary.

Credentials and state — contract and behavior

  • SKARBIEC_CAP_SOCKET, SKARBIEC_WORKLOAD_ID, and SKARBIEC_WORKLOAD_SIGNING_KEY_FILE form the canonical workload identity.
  • The signing-key file must be a regular owner-owned file with no group or other permissions.
  • BRAMA_REQUEST_SIGN_CAPABILITY_IDS binds agents to request-sign capabilities; BRAMA_PROVIDER_CAPABILITY_IDS binds providers or subscriptions to credential capabilities.
  • Capability IDs are opaque 64-character lowercase hexadecimal handles; missing, malformed, or mistargeted bindings fail closed.
  • BRAMA_STATE_DIR defaults to $HOME/.brama and may contain only retirement and task-quality records.

Stay in the loop. Never miss out.

Subscribe to our newsletter and unlock Wisent insights.