informed-decision/docs/sitting-requester-custody-request.md
tegwick 8c03eb85c0 Request sitting-requester OpenBao custody without allocating a CCR.
Verifier + attended reader on a new informed-decision KV path, not a
widening of CCR-2026-0024/0025. Intents still match approval-engine
canonical binding. No secret, no apply, no bind.

Assistant: grok
Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
2026-09-15 01:04:10 +02:00

1.9 KiB

Sitting requester custody — requested, not allocated

Workplan: INFD-WP-0002-T03 Owner: railiance-platform (OpenBao KV + ESO + attended reader) Peer: key-cape (client row; not yet registered) Status: requested 2026-09-14. No CCR id is allocated here. No secret is in this repository. Do not apply from this file.

Same split as CCR-2026-0024 / CCR-2026-0025 for secrets-engine-requester: one KeyCape verifier path (ESO) and one attended operator reader. Do not widen those CCRs or that KV path.

What to allocate

Platform assigns the next CCR pair. Suggested shape, names only:

Piece Suggested value
KV path platform/workloads/informed-decision/sitting-requester
Field CLIENT_SECRET only
Verifier policy read that path; Kubernetes auth for external-secrets in external-secrets
Reader policy read that path; OIDC attended operator; sibling paths and parent listing denied
ESO / env KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET (already the secretRef name in the KeyCape request)
Workload informed-decision
Tenant platform / tenant:platform

Do not put approval:approve or approval:consume material on this path. The human PKCE client stays public and secretless.

Activation conditions (when platform and key-cape accept)

  1. KeyCape owns informed-decision-sitting-requester (applied: false today).
  2. Attended authority writes CAS=0 custody to the new path only.
  3. Exact policy/auth readback; sibling secrets-engine/approval-requester denied.
  4. Excess scopes (approval:approve, approval:consume, approval:read) refused at token exchange.
  5. Wrong secret refused. No human entry synthesized. No POST of sitting intents until that proof exists.

Registration contract: docs/keycape-sitting-requester-registration.md. Create intents (not posted): docs/batches/2026-09-14/approval-create-intents.json.