Trust begins with separation

Human authentication, SCIM provisioning, password delivery, OIDC token exchange, FreeIPA writes, Foreman enrichment, SSH and Guacamole access, power control, and database maintenance use different credentials, protocols, and privilege boundaries.

Secret and evidence controls

Control boundaries

BoundaryAuthority and control
Human identityExternal identity provider and MFA; FreeSCIM validates trust and governs the application session.
ProvisioningSCIM bearer ingress with schema, filter, mapping, lifecycle, password, and replay controls.
Linux identityFreeIPA remains the directory, Kerberos/POSIX, HBAC, group, and authorization authority.
Host enrichmentForeman and Puppet facts enrich inventory without silently replacing reviewed operational records.
Remote supportDedicated jump and relay paths, scoped identities, short-lived launches, and workstation-specific readiness.
DatabasePreview, approval, backup, advisory locking, destructive-SQL blocking, retention policy, and verification.

Evidence status

The public site uses Proven, Operational, Governed, and Portable pattern rather than blending implemented code, enabled deployment, and end-to-end proof into one claim.

Review the capability matrix.

Fail closed, explain clearly

Missing policy, route readiness, privilege, jump reachability, migration safety, or proof evidence should block the action and tell the operator why. A visible gate is a security feature, not an unfinished product state.