Consume verified owner configuration pin before custody rollout
Assistant: codex Assistant-Model: gpt-5.6-luna Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
e30ba7b3c0
commit
cf23469ead
3 changed files with 113 additions and 5 deletions
|
|
@ -8,7 +8,7 @@ status: blocked
|
|||
owner: codex
|
||||
topic_slug: approval-engine-resource-audience
|
||||
created: "2026-09-05"
|
||||
updated: "2026-09-08"
|
||||
updated: "2026-09-09"
|
||||
state_hub_workstream_id: "6e815d88-b0e3-5ce0-be5d-13ab15917f7f"
|
||||
---
|
||||
|
||||
|
|
@ -42,7 +42,8 @@ state_hub_task_id: "607897c5-bad9-55e5-86df-7802f592d6e8"
|
|||
```
|
||||
|
||||
Needs deployment-owned custody for both new service secret references and the
|
||||
configuration-owner pin to the now-verified upstream issuer. Deploy the implementation and service registrations together,
|
||||
compatible image/configuration rollout. The upstream issuer is now verified and
|
||||
pinned by NetKingdom (2026-09-09). Deploy the implementation and service registrations together,
|
||||
then prove live JWKS verification and denied excess scopes without logging values.
|
||||
Local signature proof is not live rollout evidence. See docs/approval-engine-auth-contract.md.
|
||||
The separate human UI callback gate is retained in T05; a bearer-only resource
|
||||
|
|
@ -134,6 +135,19 @@ The diagnostic did not prove downstream KeyCape MFA/application login and did
|
|||
not activate custody. Do not repeat discovery or request another observation
|
||||
unless the provider/configuration or proof context changes.
|
||||
|
||||
|
||||
2026-09-09 configuration-owner return: NetKingdom's exercised, revision-guarded
|
||||
issuer-only helper inserted `authelia.issuer: https://auth.coulomb.social` into
|
||||
`sso/keycape-config`; resourceVersion `51346058` -> `58713343`. Independent
|
||||
readback matches. Every other configuration byte and Secret data entry, including
|
||||
the private key, was preserved. Thirteen tests passed. Receipt:
|
||||
`docs/evidence/2026-09-09-upstream-issuer-pin.json`.
|
||||
|
||||
The stored issuer configuration prerequisite is closed. No process restart,
|
||||
image rollout, custody activation or downstream login proof occurred. T02 stays
|
||||
wait for the named CCR reviews, attended custody and compatible rollout. The
|
||||
single-instance replacement and existing-human-login checks remain mandatory.
|
||||
|
||||
## Reconcile tenant vocabularies across approval layers
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue