informed-decision/docs/sitting-requester-custody-request.md

40 lines
1.9 KiB
Markdown
Raw Normal View History

# Sitting requester custody — requested, not allocated
**Workplan:** `INFD-WP-0002-T03`
**Owner:** `railiance-platform` (OpenBao KV + ESO + attended reader)
**Peer:** `key-cape` (client row; not yet registered)
**Status:** requested 2026-09-14. **No CCR id is allocated here. No secret
is in this repository. Do not apply from this file.**
Same split as `CCR-2026-0024` / `CCR-2026-0025` for
`secrets-engine-requester`: one KeyCape **verifier** path (ESO) and one
**attended operator reader**. Do not widen those CCRs or that KV path.
## What to allocate
Platform assigns the next CCR pair. Suggested shape, names only:
| Piece | Suggested value |
| --- | --- |
| KV path | `platform/workloads/informed-decision/sitting-requester` |
| Field | `CLIENT_SECRET` only |
| Verifier policy | read that path; Kubernetes auth for `external-secrets` in `external-secrets` |
| Reader policy | read that path; OIDC attended operator; sibling paths and parent listing denied |
| ESO / env | `KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET` (already the `secretRef` name in the KeyCape request) |
| Workload | `informed-decision` |
| Tenant | `platform` / `tenant:platform` |
Do not put `approval:approve` or `approval:consume` material on this path.
The human PKCE client stays public and secretless.
## Activation conditions (when platform and key-cape accept)
1. KeyCape owns `informed-decision-sitting-requester` (`applied: false` today).
2. Attended authority writes CAS=0 custody to the new path only.
3. Exact policy/auth readback; sibling `secrets-engine/approval-requester` denied.
4. Excess scopes (`approval:approve`, `approval:consume`, `approval:read`) refused at token exchange.
5. Wrong secret refused. No human entry synthesized. No POST of sitting intents until that proof exists.
Registration contract: `docs/keycape-sitting-requester-registration.md`.
Create intents (not posted): `docs/batches/2026-09-14/approval-create-intents.json`.