Track KeyCape live secret exposure recovery

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e3f-7301-7622-9be1-12e5f352881c
This commit is contained in:
tegwick 2026-08-23 13:56:09 +02:00
parent d150be1097
commit b7b4985baa

View file

@ -0,0 +1,62 @@
---
id: KEY-WP-0011
type: workplan
title: "Recover from live KeyCape Secret output exposure"
domain: infotech
repo: key-cape
status: blocked
owner: codex
topic_slug: netkingdom
created: "2026-08-23"
updated: "2026-08-23"
---
# KEY-WP-0011 — Live KeyCape Secret exposure recovery
Recover safely after the base64 data map of Kubernetes Secret
`sso/keycape-config` was mistakenly rendered in agent tool output during a
metadata check. Never reproduce, decode, or store the exposed payload.
## Contain and notify owners
```task
id: KEY-WP-0011-T01
status: done
priority: high
```
Stopped live rollout work, treated the payload as exposed, and notified
railiance-platform and NetKingdom without values. The affected classes are the
KeyCape RS256 signing private key and credentials embedded in `config.yaml`
(LLDAP bind credential, Authelia client credential, and privacyIDEA admin
token). No value was decoded, reused, or intentionally repeated and no live
mutation was attempted.
## Approve and execute coordinated rotation
```task
id: KEY-WP-0011-T02
status: wait
priority: high
```
Requires an approved owner-coordinated rotation plan. KeyCape signing-key
rollover must account for JWT/JWKS continuity or deliberate invalidation;
backend credential rotations must update each issuing system and every
consumer atomically enough to avoid an authentication outage. Secret values
must use approved custody transports and never enter Git, State Hub, chat,
arguments, or ordinary logs.
## Verify recovery without values
```task
id: KEY-WP-0011-T03
status: wait
priority: high
```
After rotation, verify new resource versions and non-secret fingerprints,
KeyCape readiness/discovery/JWKS, LLDAP lookup, Authelia authorization handoff,
privacyIDEA fail-closed MFA, and invalidation of the superseded credentials.
Verification must not render any Kubernetes Secret data or authentication
value.