52 lines
1.7 KiB
YAML
52 lines
1.7 KiB
YAML
|
|
# Request only. railiance-platform allocates the CCR id.
|
||
|
|
# status is requested — not applied, not approved, no secret values.
|
||
|
|
id: unallocated
|
||
|
|
kind: credential-change-request
|
||
|
|
schema_version: 1
|
||
|
|
request_type: workload-kv-read
|
||
|
|
title: Informed Decision sitting-requester KeyCape client secret (verifier + attended reader)
|
||
|
|
status: requested
|
||
|
|
created: "2026-09-14"
|
||
|
|
updated: "2026-09-14"
|
||
|
|
origin: INFD-WP-0002-T03
|
||
|
|
origin_ref: informed-decision/docs/keycape-sitting-requester-registration.md
|
||
|
|
requester:
|
||
|
|
agent: grok
|
||
|
|
reason: >-
|
||
|
|
Compact sitting needs a create-only presenter whose binding.actor is
|
||
|
|
informed-decision. Do not widen CCR-2026-0024/0025 or secrets-engine-requester.
|
||
|
|
review:
|
||
|
|
required: true
|
||
|
|
required_approvers:
|
||
|
|
- platform-operator
|
||
|
|
- key-cape-owner
|
||
|
|
target:
|
||
|
|
domain: infotech
|
||
|
|
tenant: platform
|
||
|
|
workload: informed-decision
|
||
|
|
environment: production
|
||
|
|
purpose: create-only sitting requester; work-record decisions, not PEP consume
|
||
|
|
openbao:
|
||
|
|
mount: platform
|
||
|
|
kv_path: platform/workloads/informed-decision/sitting-requester
|
||
|
|
fields:
|
||
|
|
- CLIENT_SECRET
|
||
|
|
delivery:
|
||
|
|
surface: external-secrets
|
||
|
|
env_name: KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
|
||
|
|
risk:
|
||
|
|
classification: high
|
||
|
|
notes:
|
||
|
|
- Scope must remain approval:create only.
|
||
|
|
- Human disposition uses informed-decision-approver (public PKCE).
|
||
|
|
- infd-20260914-c01 may stay on secrets-engine-requester if consume is in-scope.
|
||
|
|
verification:
|
||
|
|
negative:
|
||
|
|
- approval:approve and approval:consume refused at token exchange
|
||
|
|
- sibling secrets-engine/approval-requester denied
|
||
|
|
- parent listing denied
|
||
|
|
activation_conditions:
|
||
|
|
- KeyCape row exists
|
||
|
|
- attended CAS=0 write to this path only
|
||
|
|
- no sitting POST until exchange proof exists
|