Consume verified owner configuration pin before custody rollout

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-09 00:40:23 +02:00
parent e30ba7b3c0
commit cf23469ead
3 changed files with 113 additions and 5 deletions

View file

@ -28,9 +28,10 @@ verification. Provider response bodies and tokens are never printed.
at 21:44:44 UTC. Signature, audience, validity window and nonce passed; the
Job exited 0 and every temporary resource was removed. See
[the live receipt](evidence/2026-09-08-upstream-issuer-live-proof.json).
NetKingdom must now ensure that exact value is pinned in `authelia.issuer`
through its contained configuration path. This run left the config unchanged.
Preserve the existing signing key and client registrations. Prove an existing
NetKingdom pinned that exact value in `authelia.issuer` on 2026-09-09
through its exercised issuer-only helper; Secret revision `58713343`.
[Pin receipt](evidence/2026-09-09-upstream-issuer-pin.json) proves all other
config bytes and Secret data unchanged. The running Deployment was unchanged. Prove an existing
human login before and after cutover; the probe established upstream identity
only, while this image also changes redirect and grant binding.
3. The platform-owned attended first-provision command uses only