Require typed issuer refusals in live registration verification
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 40s
Assistant: codex Assistant-Model: gpt-5.6-luna Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
471465df22
commit
dcebd46fa6
6 changed files with 168 additions and 13 deletions
|
|
@ -15,7 +15,7 @@ requests:
|
|||
scopes: [approval:read, approval:consume]
|
||||
lifetime: 15m
|
||||
proposed_openbao_path: platform/workloads/secrets-engine/approval-client
|
||||
field: client_secret
|
||||
field: CLIENT_SECRET
|
||||
proposed_kubernetes_secret: sso/keycape-secrets-engine-approval-client
|
||||
kubernetes_key: client-secret
|
||||
keycape_environment: KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET
|
||||
|
|
@ -27,7 +27,7 @@ requests:
|
|||
scopes: [approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:observe, approval:emit]
|
||||
lifetime: 15m
|
||||
proposed_openbao_path: platform/workloads/approval-engine/operator-client
|
||||
field: client_secret
|
||||
field: CLIENT_SECRET
|
||||
proposed_kubernetes_secret: sso/keycape-approval-engine-operator-client
|
||||
kubernetes_key: client-secret
|
||||
keycape_environment: KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET
|
||||
|
|
@ -35,6 +35,8 @@ requests:
|
|||
consumer: approval-engine-operator
|
||||
human_registration:
|
||||
status: awaiting-exact-callback
|
||||
blocks_service_client_rollout: false
|
||||
owner: unassigned-approver-ui
|
||||
scopes: [openid, approval:approve]
|
||||
mfa_required: true
|
||||
client_type: public
|
||||
|
|
@ -65,4 +67,13 @@ verification:
|
|||
blockers:
|
||||
- Admit exact custody paths, field delivery, consumer identities and lifecycle authority.
|
||||
- Resolve attended first-provision authority through the custody owner.
|
||||
- Supply exact human client ID and callback URI.
|
||||
- Verify the actual upstream ID-token issuer before production image rollout.
|
||||
custody_return:
|
||||
owner_record: railiance-platform/workplans/RPF-WP-0035-credential-lane-implementation.md#Admit-KeyCape-approval-engine-client-custody-and-delivery
|
||||
requests: [CCR-2026-0017, CCR-2026-0018]
|
||||
status: proposed-awaiting-owner-approval
|
||||
field_correction: CLIENT_SECRET
|
||||
scope: KeyCape verifier-side copies only; client-side retrieval is not admitted.
|
||||
human_registration_gate:
|
||||
- The approver UI owner must supply its real client ID and exact callback.
|
||||
- This gate blocks human approval entry; it does not block the two independent client_credentials registrations or service startup.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue