Verifier + attended reader on a new informed-decision KV path, not a widening of CCR-2026-0024/0025. Intents still match approval-engine canonical binding. No secret, no apply, no bind. Assistant: grok Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267
51 lines
1.7 KiB
YAML
51 lines
1.7 KiB
YAML
# Request only. railiance-platform allocates the CCR id.
|
|
# status is requested — not applied, not approved, no secret values.
|
|
id: unallocated
|
|
kind: credential-change-request
|
|
schema_version: 1
|
|
request_type: workload-kv-read
|
|
title: Informed Decision sitting-requester KeyCape client secret (verifier + attended reader)
|
|
status: requested
|
|
created: "2026-09-14"
|
|
updated: "2026-09-14"
|
|
origin: INFD-WP-0002-T03
|
|
origin_ref: informed-decision/docs/keycape-sitting-requester-registration.md
|
|
requester:
|
|
agent: grok
|
|
reason: >-
|
|
Compact sitting needs a create-only presenter whose binding.actor is
|
|
informed-decision. Do not widen CCR-2026-0024/0025 or secrets-engine-requester.
|
|
review:
|
|
required: true
|
|
required_approvers:
|
|
- platform-operator
|
|
- key-cape-owner
|
|
target:
|
|
domain: infotech
|
|
tenant: platform
|
|
workload: informed-decision
|
|
environment: production
|
|
purpose: create-only sitting requester; work-record decisions, not PEP consume
|
|
openbao:
|
|
mount: platform
|
|
kv_path: platform/workloads/informed-decision/sitting-requester
|
|
fields:
|
|
- CLIENT_SECRET
|
|
delivery:
|
|
surface: external-secrets
|
|
env_name: KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
|
|
risk:
|
|
classification: high
|
|
notes:
|
|
- Scope must remain approval:create only.
|
|
- Human disposition uses informed-decision-approver (public PKCE).
|
|
- infd-20260914-c01 may stay on secrets-engine-requester if consume is in-scope.
|
|
verification:
|
|
negative:
|
|
- approval:approve and approval:consume refused at token exchange
|
|
- sibling secrets-engine/approval-requester denied
|
|
- parent listing denied
|
|
activation_conditions:
|
|
- KeyCape row exists
|
|
- attended CAS=0 write to this path only
|
|
- no sitting POST until exchange proof exists
|