# Proposed non-secret admission packet. This is not executable authorization. # Tenant for both requests is tenant:platform per decision # 5ed3fb35-eca9-413a-82b9-95171ba85bf6 (landlord zone). Exact spelling required # across the approval store, these JWT claims and the lifecycle CheckRequest; # no alias to platform or tenant:coulomb. status: awaiting-custody-admission owner: key-cape resource_audience: approval-engine issuer: https://kc.coulomb.social registration_source: config/service-clients.example.yaml requests: - client_id: secrets-engine-approval subject: service:secrets-engine tenant: tenant:platform scopes: [approval:read, approval:consume] lifetime: 15m proposed_openbao_path: platform/workloads/secrets-engine/approval-client field: CLIENT_SECRET proposed_kubernetes_secret: sso/keycape-secrets-engine-approval-client kubernetes_key: client-secret keycape_environment: KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET custody_owner: railiance-platform consumer: secrets-engine - client_id: approval-engine-operator subject: service:approval-engine-operator tenant: tenant:platform scopes: [approval:create, approval:read, approval:approve, approval:revoke, approval:supersede, approval:observe, approval:emit] lifetime: 15m proposed_openbao_path: platform/workloads/approval-engine/operator-client field: CLIENT_SECRET proposed_kubernetes_secret: sso/keycape-approval-engine-operator-client kubernetes_key: client-secret keycape_environment: KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET custody_owner: railiance-platform consumer: approval-engine-operator human_registration: status: awaiting-exact-callback blocks_service_client_rollout: false # Owner identified 2026-09-09: informed-decision (hub repo cf4c7da8). It # supplies client_id and callback URI from INFD-WP-0001-T07 once it has a # deployed origin. approval-engine is a bearer-only resource server and never # owned those strings. owner: informed-decision # approval:read added 2026-09-09 on approval-engine's finding: the surface # cannot render a decision without GET /v1/approvals/{id} and /claim, so the # earlier scope set let an approver submit what they could not display. scopes: [openid, approval:read, approval:approve] mfa_required: true client_type: public grant: authorization_code + S256 PKCE never: [approval:consume] blocked_on_keycape_side: | A human access token cannot carry tenant:platform today. The tenant claim on a human token is resolved from the directory user (effectiveTenant in src/internal/server/oidc/token.go), not from the client registration, and no adapter populates User.Tenant -- so every human token defaults to tenant:coulomb. approval-engine compares tenant by exact string equality and refuses near-miss spellings, so an approver token would be rejected. This must be resolved before the registration is issued, not after. verification: # The first two lines are now one runnable command per client; see # docs/native-authentication.md, "Verifying a live registration". It writes # nothing and prints no value, so it is safe to run against production. - command: | keycape verify-client -issuer https://kc.coulomb.social -client-id secrets-engine-approval -audience approval-engine -scope "approval:read approval:consume" -secret-env KEYCAPE_SECRETS_ENGINE_APPROVAL_CLIENT_SECRET -expect-subject service:secrets-engine -expect-tenant tenant:platform -expect-roles secrets-engine -deny-scope "approval:approve approval:revoke approval:supersede" - command: | keycape verify-client -issuer https://kc.coulomb.social -client-id approval-engine-operator -audience approval-engine -scope "approval:create approval:read approval:approve approval:revoke approval:supersede approval:observe approval:emit" -secret-env KEYCAPE_APPROVAL_ENGINE_OPERATOR_CLIENT_SECRET -expect-subject service:approval-engine-operator -expect-tenant tenant:platform -expect-roles approval-operator -deny-scope "approval:consume" - Check KeyCape and consumer readiness without emitting secrets or tokens. - Preserve existing registrations and signing key; record versions and image digest. - Human consume denial is approval-engine's to verify at its resource; KeyCape proves only that the human client is never issued a consume grant. blockers: - Admit exact custody paths, field delivery, consumer identities and lifecycle authority. - Resolve attended first-provision authority through the custody owner. - Verify the actual upstream ID-token issuer before production image rollout. custody_return: owner_record: railiance-platform/workplans/RPF-WP-0035-credential-lane-implementation.md#Admit-KeyCape-approval-engine-client-custody-and-delivery requests: [CCR-2026-0017, CCR-2026-0018] status: proposed-awaiting-owner-approval field_correction: CLIENT_SECRET scope: KeyCape verifier-side copies only; client-side retrieval is not admitted. human_registration_gate: - The approver UI owner must supply its real client ID and exact callback. - This gate blocks human approval entry; it does not block the two independent client_credentials registrations or service startup.