key-cape/docs/approval-clients-rollout.md

43 lines
2.7 KiB
Markdown
Raw Normal View History

# Approval service clients: live rollout accepted
KEY-WP-0013-T02 is complete on 2026-09-09. Both verifier-side credential requests,
CCR-2026-0017 and CCR-2026-0018, have explicit user approval as platform operator
and KeyCape owner and are now verified. [Live receipt](evidence/2026-09-09-keycape-verifier-admission.json).
Both clients run on one ready KeyCape replica using the immutable image
`forgejo.coulomb.social/coulomb/key-cape@sha256:7ff54c54e63ee172ae9e6e7fd2da96e427352f712343d74626ee6fe0f6f82611`.
NetKingdom owns the deployed manifest, `Recreate` strategy, `/readyz` readiness,
and exact client registrations. Both ESO-owned Secrets are synchronized from
OpenBao version 1. The signing key and unrelated configuration bytes are preserved.
Both clients passed the native verifier from that pinned image and independent
RS256/JWKS verification with exact issuer, audience, subject, tenant, roles,
scopes and a 900-second lifetime. Wrong secrets and excess scopes were refused;
the human OpenBao client was refused `approval:consume`. Existing human OpenBao
login passed before and after cutover, with attended sessions self-revoked.
The deployment owner exercised compatible rollback and version-preserving
resume. Its executable procedure and reproducible synthetic HTTPS exercise live
in `net-kingdom:sso-mfa/k8s/keycape/`, documented in
`net-kingdom:docs/keycape-approval-clients-rollout.md`. The verifier runs inside
the existing attended owner process; credentials stay in memory and a child
environment. The pod's internal-only egress policy remains unchanged.
Containerd readiness matches the manifest in `imageID`. Independent JWT checks
use the native contract's 30-second future-iat bound while retaining strict
not-before and expiry. Natural JWT expiry and actual predecessor rotation were
not exercised by this initial provision and remain required for their relevant
subsequent owner acceptance.
The original [candidate patch](approval-clients-deployment.patch.yaml) remains a
preparation reference; NetKingdom's manifest is deployment authority. Candidate
Go tests and vet passed previously; this window added eight real local OpenBao
checks, ten configuration/recovery/clock checks, 53 credential-change regressions,
and a complete pinned-image HTTPS/native-verifier exercise with synthetic keys.
KEY-WP-0013-T05 retains the real approval UI callback and MFA/PKCE proof.
RPF-WP-0035-T05 retains separate client-side credential delivery; AUDIT-WP-0009-T09
retains audit custody. APPROVAL-WP-0002 and SECRETS-WP-0009-T03 retain deployed
claim/consume, expiry/revocation and native credential delivery. These verifier
copies do not grant client retrieval or factory execution/spending.