Commit graph

2 commits

Author SHA256 Message Date
Tyler J King
24eefe1699 feat(credentials): add Entra and Stub credential backends
Entra backend resolves OAuth tokens via MSAL client_credentials
(OBO flow wired in future sprint) and passes ACs through for
Bascule. Kerberos stubbed pending hybrid environment config.
Stub backend for dev/testing without real IdP.

Signed-off-by: Tyler King <tking@guildhouse.dev>
2026-04-14 05:57:52 -04:00
Tyler J King
043693652a feat(credentials): add CredentialResolver and Credential types
Zero-credential-storage architecture. The broker holds ACs
(authorization). Pluggable CredentialBackend implementations
hold secrets. Transports acquire short-lived, scoped credentials
at invocation time and discard after use.

Credential types: BasculeCredential, KerberosCredential,
OAuthCredential, SSHCertCredential.

Signed-off-by: Tyler King <tking@guildhouse.dev>
2026-04-14 05:57:00 -04:00