Verifier + attended reader on a new informed-decision KV path, not a widening of CCR-2026-0024/0025. Intents still match approval-engine canonical binding. No secret, no apply, no bind. Assistant: grok Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
1.9 KiB
Sitting requester custody — requested, not allocated
Workplan: INFD-WP-0002-T03
Owner: railiance-platform (OpenBao KV + ESO + attended reader)
Peer: key-cape (client row; not yet registered)
Status: requested 2026-09-14. No CCR id is allocated here. No secret
is in this repository. Do not apply from this file.
Same split as CCR-2026-0024 / CCR-2026-0025 for
secrets-engine-requester: one KeyCape verifier path (ESO) and one
attended operator reader. Do not widen those CCRs or that KV path.
What to allocate
Platform assigns the next CCR pair. Suggested shape, names only:
| Piece | Suggested value |
|---|---|
| KV path | platform/workloads/informed-decision/sitting-requester |
| Field | CLIENT_SECRET only |
| Verifier policy | read that path; Kubernetes auth for external-secrets in external-secrets |
| Reader policy | read that path; OIDC attended operator; sibling paths and parent listing denied |
| ESO / env | KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET (already the secretRef name in the KeyCape request) |
| Workload | informed-decision |
| Tenant | platform / tenant:platform |
Do not put approval:approve or approval:consume material on this path.
The human PKCE client stays public and secretless.
Activation conditions (when platform and key-cape accept)
- KeyCape owns
informed-decision-sitting-requester(applied: falsetoday). - Attended authority writes CAS=0 custody to the new path only.
- Exact policy/auth readback; sibling
secrets-engine/approval-requesterdenied. - Excess scopes (
approval:approve,approval:consume,approval:read) refused at token exchange. - Wrong secret refused. No human entry synthesized. No POST of sitting intents until that proof exists.
Registration contract: docs/keycape-sitting-requester-registration.md.
Create intents (not posted): docs/batches/2026-09-14/approval-create-intents.json.