DreamLake

Prefix KMS policy

Status: In progress, not released or deployed. Vault #241.

Managed KMS is already available in the configured hosted runtime. Ordinary users need no cloud account. This slice adds personal-owner policy inspection, preview, and activation for an empty prefix using an operator-approved key reference. It does not onboard arbitrary customer keys, migrate populated prefixes, or change cloud permissions. Scoped Vault access keys cannot manage policies; project membership grants no additional authority.

The operator sets DREAMLAKE_VAULT_KMS_PREFIX_KEYS to a JSON array of {ref, tenantId, keyId} records. Every key must already belong to the runtime's explicit KMS allowlist, provider and supported region. The immutable key identifier remains operator configuration; callers submit the tenant-authorized reference. A missing or denied customer key never falls back to managed encryption.

Proposed commands (source implementation under review):

shell
dreamlake vault -p alice/research kms show
dreamlake vault -p alice/research kms preview --key research-key
# Persist this request ID with the prefix/key; reuse all three after any uncertainty.
dreamlake vault -p alice/research kms activate --key research-key --request-id research-kms-001
dreamlake vault kms status research-kms-001

Preview is metadata-only and does not reserve a prefix or probe its key. Activation probes the approved key, then atomically checks emptiness/overlaps and records both boundary and immutable receipt. A failed/uncertain probe activates nothing. A lost commit response can be reconciled with the original operation ID; a missing receipt is not proof that an in-flight transaction will never commit. Libraries never prompt or invent a replacement request ID. Persist the original account, server, prefix, reference and ID outside the request before sending it.

Parent boundaries dominate; alice covers its subtree, while alice/work does not cover alice/workshop. An ancestor or descendant policy conflicts. Retired entries, expired entries, and retained write/HOTP receipts all prevent empty-prefix activation. Mongo's shared per-tenant write guard serializes policy creation with entry creation across processes. A create sealed under an old default cannot commit under a newly activated customer boundary. There are at most 128 boundaries/activation receipts per tenant in this slice; no policy deletion or receipt expiry is offered yet.

The tenant guard trades write throughput for an activation race guarantee. High concurrency can exhaust the 10-second transaction budget and returns redacted HTTP 503 VAULT_UNAVAILABLE; it does not establish whether a write committed. Bound caller concurrency and reconcile/retry the same immutable request ID and payload. A policy-free read cannot safely skip this guard because the first activation can race it. Future finer-grained admission must preserve owner-root activation conflicts.

Remaining full migration and verification

  • [vault/kms/populated-migration] Preview affected entries and receipts; serialized policy epochs and resumable bounded migration with identity/envelope CAS, restart and partial outcomes. Cover create/write/retire/restore/purge and competing migration races.
  • [vault/kms/recovery-retention] Preserve active HOTP counters and outstanding intent tuples, host-binding revisions, 30-day write receipts and 24-hour HOTP receipts. Migration must not generate an OTP or replace a logical credential. Account for retained retired entries and actual backup retention before any old-key retirement recommendation.
  • [vault/kms/customer-bootstrap] Explicit customer IAM/grants and workload identity outside this Vault. Same-provider allowlisting is not completed BYOKMS onboarding; cross-region/provider routing remains unavailable.
  • [vault/kms/live-outage-recovery] Dedicated disposable AWS key/role: deny/timeout, assert no mutation/fallback/plaintext, then recover; unauthorized tenant requests cause zero KMS calls. Never fault the shared production/staging keys.
  • [vault/kms/gcp-live] Explicit GCP project/API/keyring/key and workload-identity setup, narrow permissions, live integrity/denial/historical-version tests and cleanup. Current GCP provider tests are synthetic; the inspected project returned KMS API disabled.
  • [vault/kms/operator-ui] Governing prefix, trusted key reference and migration/outage states in advanced UI; do not imply unsupported migration is available.

Reuse provider HTTP/Mongo tests, kmsPolicy.e2e.test.ts, test-vault-kms-clients.py, and the existing EKS/KMS fixture. KMS automatic rotation is different from re-encrypting stored data: AWS, GCP.

The empty-prefix foundation merged in workspace353 / CLI57 / Python43; it remains unreleased and undeployed. Follow the populated-prefix migration implementation plan for the next slice.