Pin KeyCape main-911e9de (fresh-MFA freshness fix) as deployed
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Operator-run rollout 2026-09-27: fixes INFD-IN-0005 — completeAuthorization
was reusing an existing kc_login cookie's IssuedAt as authTime even after
a freshly-validated MFA token in the same request, which understated
freshness for downstream binding-grade checks (flex-auth's 900s review
window denied informed-decision's infd-20260927-b01 approval as a result).
See key-cape commit 911e9de and workplans/ADHOC-2026-09-27.md.
Rollback digest: sha256:7c99cd6c6fdf63afaf22e47dad31e20dcb3a8b2079206f198cb425047be495b3

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 169987@bnt-lap001
Assistant-Session: 322ef1ef-9048-4021-8570-b6d6f6347999
This commit is contained in:
tegwick 2026-09-27 19:20:06 +02:00
parent 2f1e6c3369
commit 17a66fe236

View file

@ -51,10 +51,11 @@ spec:
containers: containers:
- name: keycape - name: keycape
# Image published to the self-hosted Forgejo OCI registry (KEY-WP-0002). # Image published to the self-hosted Forgejo OCI registry (KEY-WP-0002).
# NK-WP-0041-T02 path B, key-cape@3b0446e: the in-cluster token call # key-cape@911e9de: completeAuthorization no longer backdates a
# sends the public HTTPS origin. Staged while Authelia stays 4.38. # freshly-verified MFA to a stale kc_login cookie's IssuedAt
# Rollback: sha256:82f1e5ac481e4f963dbd4b05256aee75412c9e9b465d31c9356f5d17f26a6897 # (INFD-IN-0005).
image: forgejo.coulomb.social/coulomb/key-cape@sha256:7c99cd6c6fdf63afaf22e47dad31e20dcb3a8b2079206f198cb425047be495b3 # Rollback: sha256:7aefcee9b79eb3285997066b323ae1772e13d58f875aacc6eb5e9407bd1c1185
image: forgejo.coulomb.social/coulomb/key-cape@sha256:248e449a031c972529f829ff36aa3faa92f8894a41e873beadcb0de34e7c3b9e
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
ports: ports: