eigenstate-ipa

Documentation Map

Use this page when you know the problem category but do not yet know which collection page should be your first stop.

Current release: 1.10.3

Reading Model

The docs are organized on purpose:

That keeps the decision pages from turning into reference dumps and keeps the reference pages from wandering into broad architectural prose.

First Route By Intent

I am evaluating the collection overall

  1. TOP README
  2. DOCS HOME
  3. choose one workflow from High-Value Workflows

I use Vault or CyberArk today

  1. VAULT/CYBERARK PRIMER
  2. ROTATION CAPABILITIES
  3. AAP INTEGRATION
  4. EPHEMERAL ACCESS CAPABILITIES

I run OpenShift, OpenShift Virtualization, or RHOSO

  1. OPENSHIFT ECOSYSTEM PRIMER
  2. AAP INTEGRATION
  3. OPENSHIFT OPERATOR USE CASES
  4. OPENSHIFT RHOSO USE CASES
  5. RHOSO OPERATOR USE CASES
  6. RHOSO TENANT USE CASES
  7. OPENSHIFT RHACM USE CASES
  8. OPENSHIFT RHACS USE CASES
  9. OPENSHIFT QUAY USE CASES
  10. OPENSHIFT DEVELOPER USE CASES

I already know the plugin and just need syntax

Go straight to Reference By Area.

High-Value Workflows

These are the collection combinations worth learning as flows.

Need Best starting point Why
IdM-backed targeting and scoped inventory Inventory Use Cases combines host data, hostgroups, netgroups, HBAC scope, and host metadata
Service onboarding and key material Principal Use Cases principal pre-flight is the gate before keytab and cert work
TLS bootstrap and renewal Cert Use Cases cert issuance, retrieval, renewal, and vault-backed private-key handling
Static secret lifecycle in Controller Rotation Use Cases vault_write, vault, keytab, and cert in scheduled jobs
Lease-like temporary access in IdM Ephemeral Access Capabilities user_lease for delegated temporary users plus Kerberos key retirement patterns without pretending they are dynamic secret leases
Host enrollment OTP Use Cases OTP bootstrap plus official IdM enrollment modules and post-checks
Policy validation before privileged change AAP Integration hbacrule, selinuxmap, sudo, principal, and dns as controller-side gates
Vault or CyberArk displacement analysis Vault/CyberArk Primer comparison framing without pretending the collection is a lease engine or PAM suite
OpenShift platform and app workflows OpenShift Ecosystem Primer routes cluster admins, virtualization operators, RHOSO operators, RHOSO tenant admins, developers, RHACM operators, RHACS operators, and Quay operators into the right IdM-backed workflow pages
RHOSO operator and tenant workflows OpenShift RHOSO Use Cases RHOSO cloud operations and tenant-facing identity boundaries become cleaner AAP workflows instead of a mix of standing admin access and side-channel onboarding
RHACM event-driven remediation OpenShift RHACM Use Cases RHACM policy violations and lifecycle hooks become AAP jobs that verify real IdM identity, policy, and supporting artifacts before they run
RHACS findings and enforcement OpenShift RHACS Use Cases RHACS alerts, admission controls, and network-policy output become governed workflows instead of generic follow-up tickets
Quay identity and repo automation OpenShift Quay Use Cases Quay team access, mirroring, notifications, and registry onboarding become IdM-aware workflows instead of local credential sprawl

Choose By Problem

Inventory and targeting

Static secrets and vault lifecycle

Kerberos, certificates, and enrollment

DNS and policy validation

Controller workflows and comparison framing

Reference By Area

Area Reference Capabilities Use cases
Inventory Inventory Plugin Inventory Capabilities Inventory Use Cases
Vault retrieval Vault Plugin Vault Capabilities Vault Use Cases
Vault lifecycle Vault Write Module Vault Write Capabilities Vault Write Use Cases
Principal state Principal Plugin Principal Capabilities Principal Use Cases
Keytabs Keytab Plugin Keytab Capabilities Keytab Use Cases
User lease User Lease Module User Lease Capabilities User Lease Use Cases
Certificates Cert Plugin Cert Capabilities Cert Use Cases
OTP OTP Plugin OTP Capabilities OTP Use Cases
DNS DNS Plugin DNS Capabilities DNS Use Cases
SELinux maps SELinux Map Plugin SELinux Map Capabilities SELinux Map Use Cases
Sudo policy Sudo Plugin Sudo Capabilities Sudo Use Cases
HBAC rules HBAC Rule Plugin HBAC Rule Capabilities HBAC Rule Use Cases

Keep The Flow Clean

To avoid circular writing: