Consume verified owner configuration pin before custody rollout

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-09 00:40:23 +02:00
parent e30ba7b3c0
commit cf23469ead
3 changed files with 113 additions and 5 deletions

View file

@ -8,7 +8,7 @@ status: blocked
owner: codex
topic_slug: approval-engine-resource-audience
created: "2026-09-05"
updated: "2026-09-08"
updated: "2026-09-09"
state_hub_workstream_id: "6e815d88-b0e3-5ce0-be5d-13ab15917f7f"
---
@ -42,7 +42,8 @@ state_hub_task_id: "607897c5-bad9-55e5-86df-7802f592d6e8"
```
Needs deployment-owned custody for both new service secret references and the
configuration-owner pin to the now-verified upstream issuer. Deploy the implementation and service registrations together,
compatible image/configuration rollout. The upstream issuer is now verified and
pinned by NetKingdom (2026-09-09). Deploy the implementation and service registrations together,
then prove live JWKS verification and denied excess scopes without logging values.
Local signature proof is not live rollout evidence. See docs/approval-engine-auth-contract.md.
The separate human UI callback gate is retained in T05; a bearer-only resource
@ -134,6 +135,19 @@ The diagnostic did not prove downstream KeyCape MFA/application login and did
not activate custody. Do not repeat discovery or request another observation
unless the provider/configuration or proof context changes.
2026-09-09 configuration-owner return: NetKingdom's exercised, revision-guarded
issuer-only helper inserted `authelia.issuer: https://auth.coulomb.social` into
`sso/keycape-config`; resourceVersion `51346058` -> `58713343`. Independent
readback matches. Every other configuration byte and Secret data entry, including
the private key, was preserved. Thirteen tests passed. Receipt:
`docs/evidence/2026-09-09-upstream-issuer-pin.json`.
The stored issuer configuration prerequisite is closed. No process restart,
image rollout, custody activation or downstream login proof occurred. T02 stays
wait for the named CCR reviews, attended custody and compatible rollout. The
single-instance replacement and existing-human-login checks remain mandatory.
## Reconcile tenant vocabularies across approval layers
```task