key-cape/workplans/KEY-WP-0011-live-secret-exposure-recovery.md
tegwick 6a996bd71e security: rotate exposed KeyCape credentials
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e3f-7301-7622-9be1-12e5f352881c
2026-08-23 14:26:36 +02:00

2.3 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
KEY-WP-0011 workplan Recover from live KeyCape Secret output exposure infotech key-cape finished codex netkingdom 2026-08-23 2026-08-23 158aa957-8818-52ea-b7a5-3962cf30ba5e

KEY-WP-0011 — Live KeyCape Secret exposure recovery

Recover safely after the base64 data map of Kubernetes Secret sso/keycape-config was mistakenly rendered in agent tool output during a metadata check. Never reproduce, decode, or store the exposed payload.

Contain and notify owners

id: KEY-WP-0011-T01
status: done
priority: high
state_hub_task_id: "a8f5e33d-c725-5181-849e-a42bba34d3d8"

Stopped live rollout work, treated the payload as exposed, and notified railiance-platform and NetKingdom without values. The affected classes are the KeyCape RS256 signing private key and credentials embedded in config.yaml (LLDAP bind credential, Authelia client credential, and privacyIDEA admin token). No value was decoded, reused, or intentionally repeated and no live mutation was attempted.

Approve and execute coordinated rotation

id: KEY-WP-0011-T02
status: done
priority: high
state_hub_task_id: "9d60569c-a0f1-53a9-b4dc-01687ab92bcc"

Approved by the operator on 2026-08-23, accepting deliberate invalidation of active sessions and a brief SSO interruption. The RS256 key, LLDAP bind/admin credential, Authelia-KeyCape client credential, and privacyIDEA application signing secret were replaced without rendering values. The exposed privacyIDEA admin JWT was removed from live use. Replacement material is recoverable only through the NetKingdom age recipient in the encrypted recovery overlay under history/.

Verify recovery without values

id: KEY-WP-0011-T03
status: done
priority: high
state_hub_task_id: "a079573d-97fd-5c6c-b1f9-c0af65e2933a"

Verified changed resource versions and public JWKS fingerprints, four Ready deployments, successful replacement LLDAP and Authelia authentication, wrong-secret rejection, explicit privacyIDEA fail-closed denial, issuer discovery, and the OpenBao callback handoff to Authelia. The temporary LLDAP force-reset flag was removed. No Kubernetes Secret payload or authentication value was rendered during recovery.