Files
orca/docs/webauthn.md
T
Jon Chery 0f7f9cf914 docs(P27): zero-trust + OIDC + WebAuthn + threat-model docs (REQ-142)
---ci---
project: orca
phase: 27
milestone: v0.12
status: execute
---/ci---

docs/threat-model.md (STRIDE + OS surface + residual risks),
docs/oidc.md (bundled Dex + BYO + claim mapping + offline),
docs/webauthn.md (passkeys + RP ID + bootstrap sequence),
docs/security-runbook.md (seal/unseal + rotation + incident response).
2026-08-07 11:33:58 +00:00

960 B

WebAuthn / Passkeys (v0.12)

Overview

The bundled Dex uses a custom WebAuthn connector for password-free authentication. Passkeys are public-key credentials — the private key never leaves the authenticator (TPM/security key/phone Secure Enclave).

Registration

orca auth register opens the browser to the Dex WebAuthn endpoint. After the ceremony (biometric/security key), Dex maps the credential ID to an OIDC sub. Credentials stored at ClusterDir()/webauthn-credentials.db (0600, public keys only).

RP ID

The relying-party ID is the cluster's Traefik-served domain (--rp-id on orca auth init-idp). HTTPS secure context is provided by Traefik (step-ca cert, R-017).

Bootstrap Sequence

  1. orca init bootstraps the cluster CA (step-ca, mTLS-only).
  2. orca auth init-idp deploys Dex behind Traefik (step-ca cert).
  3. First operator registers a passkey via the mTLS-authenticated session.
  4. Subsequent operators use WebAuthn.