key-cape/workplans
tegwick 1dc11b8448 Record live custody admission and re-verify the new rule against it
Read-only inspection shows KEY-WP-0013-T02's custody gate has moved since
yesterday: both approval clients are registered in sso/keycape-config, both
secrets exist in the namespace and are wired into the pod, and the image is
pinned to the digest T06 published. The live issuer passes every conformance
check that needs no credential.

That does not establish the claim contract. Subject, tenant, roles, scopes,
lifetime and excess-scope denial are what keycape verify-client proves, and it
needs the client secret in the environment. Reading either secret is client-side
retrieval, which the provisioning packet records as not admitted, so that run is
an attended operator action. T02 now waits on the run, not on custody.

Also re-verified the KEY-WP-0028 rule against the deployed config, after a peer
noted it fails closed at startup with a rollout imminent. The three browser
clients there carry neither serviceSubject nor roles; the three service clients
carry both legitimately. Kept as errors rather than warnings on that evidence.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NV9oijZukGyGbRQGGKnK4P

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 713576@bnt-lap001
Assistant-Session: 384c511d-9bce-4cb8-a676-2aef6c0c8df6
2026-09-09 14:44:38 +02:00
..
ADHOC-2026-09-05.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
ADHOC-2026-09-07.md chore(consistency): register KEY-WP-0017 and ADHOC-2026-09-07 [auto] 2026-09-07 00:23:58 +02:00
KEY-WP-0001-keycape-implementation.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
KEY-WP-0002-container-image-gitea.md Add bounded resource audiences and enforce browser scope grants 2026-09-05 00:41:17 +02:00
KEY-WP-0003-bootstrap-console-oidc-mfa-login.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:27 +02:00
KEY-WP-0004-binky-hedgehog-tenant-onboarding.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0005-iam-profile-core-claims.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0006-client-credentials-service-tokens.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0007-user-engine-portal-oidc-client.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0008-registration-handoff-and-client-mfa-policy.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:13:23 +02:00
KEY-WP-0009-provider-capabilities-and-service-identities.md Close the KEY-WP-0009 handoff gap and deliver the two blocked admissions 2026-09-08 10:22:52 +02:00
KEY-WP-0010-openbao-operator-loopback-callback.md chore(registrar): assign State Hub identifiers 2026-08-23 13:19:35 +02:00
KEY-WP-0011-live-secret-exposure-recovery.md security: rotate exposed KeyCape credentials 2026-08-23 14:26:36 +02:00
KEY-WP-0012-userinfo-canonical-subject-resolution.md repo.work.assign_missing_identifiers 2026-09-01 01:36:20 +02:00
KEY-WP-0013-approval-engine-resource-audience.md Record live custody admission and re-verify the new rule against it 2026-09-09 14:44:38 +02:00
KEY-WP-0014-native-credential-lane-handoff.md Answer the approver-client questions, and fix what checking them turned up 2026-09-09 14:25:38 +02:00
KEY-WP-0015-scope-intent-assessment.md Align approval registrations to the tenant:platform decision 2026-09-06 22:30:32 +02:00
KEY-WP-0016-authorization-code-protocol-hardening.md chore(consistency): register KEY-WP-0016 and refresh work records [auto] 2026-09-06 22:44:55 +02:00
KEY-WP-0017-canonical-model-and-discovery-conformance.md chore(consistency): register KEY-WP-0017 and ADHOC-2026-09-07 [auto] 2026-09-07 00:23:58 +02:00
KEY-WP-0018-export-completeness-evidence.md chore(consistency): register KEY-WP-0018 and refresh work records [auto] 2026-09-07 08:47:00 +02:00
KEY-WP-0019-upstream-provider-token-verification.md Record what the consolidated verifier's tests actually establish 2026-09-07 09:05:16 +02:00
KEY-WP-0020-migration-contract-preservation.md chore(consistency): register KEY-WP-0020 and refresh work records [auto] 2026-09-07 13:49:40 +02:00
KEY-WP-0021-snapshot-attribute-validation.md chore(consistency): register KEY-WP-0021 [auto] 2026-09-07 23:23:38 +02:00
KEY-WP-0022-replacement-harness-and-external-conformance.md chore(consistency): register KEY-WP-0022 [auto] 2026-09-07 23:32:51 +02:00
KEY-WP-0023-live-migration-proof.md chore(consistency): register KEY-WP-0023 [auto] 2026-09-08 08:55:52 +02:00
KEY-WP-0024-tenant-roles-opt-in-wiring.md chore(consistency): register KEY-WP-0024 [auto] 2026-09-08 09:00:39 +02:00
KEY-WP-0025-runtime-lifecycle-and-readiness.md chore(consistency): register KEY-WP-0025 [auto] 2026-09-08 09:44:33 +02:00
KEY-WP-0026-packaging-bootstrap-and-credential-handling.md chore(consistency): register KEY-WP-0026 [auto] 2026-09-08 09:52:42 +02:00
KEY-WP-0027-rollout-readiness-and-live-state.md docs(identity): record verified live upstream issuer and completed cleanup 2026-09-08 23:50:54 +02:00
KEY-WP-0028-browser-client-field-validation.md Record live custody admission and re-verify the new rule against it 2026-09-09 14:44:38 +02:00