Close NK-WP-0033 on the attended resolver --check PASS receipt
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

KEYCAPE-EXPOSURE-20260823-01 closes under the operator ruling: green
read-only receipt with both values from operators custody; predecessor
disposition by recorded observation. Runbook exercise status updated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 299762@bnt-lap001
Assistant-Session: d3d3cea1-869c-44f1-be2a-3d6d3550e72e
This commit is contained in:
tegwick 2026-09-23 20:31:16 +02:00
parent 6096c39539
commit 487c7abf65
2 changed files with 38 additions and 4 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Contain and rotate the exposed KeyCape credential bundle"
domain: infotech
repo: net-kingdom
status: active
status: finished
flavor: implementation
owner: codex
topic_slug: net-kingdom
@ -96,7 +96,7 @@ unrelated routes do not authorize execution.
```task
id: NK-WP-0033-T03
status: progress
status: done
priority: high
state_hub_task_id: "f0f6d6c3-9c45-56b7-9fd6-52fb0ea9054a"
```
@ -159,7 +159,7 @@ privacyIDEA resolver still awaits attended provider-admin reconciliation.
```task
id: NK-WP-0033-T05
status: progress
status: done
priority: high
state_hub_task_id: "41e55d5c-ae28-5ee2-be25-b9a3758428f7"
```
@ -231,3 +231,37 @@ nothing else is required.
The custody gap (rotation does not retain the outgoing value) is a
rotation-runbook fix. It is not a reason to reopen this incident.
### Attended receipt 2026-09-23 — incident closed
Operator Bernd Worsch was both the attended driver and the abort operator.
That is acceptable because `--check` performs no mutation. The run used
railiance01 checkout `6096c395` (script `4a38511` plus the shared transport),
platform contract `453fed3` and owner receipt `45b236c8`. The command was:
`reconcile-lldap-resolver-live.sh --check --predecessor-unavailable`
Both values were taken from operator custody: `operators/privacyidea/pi-admin`,
and `operators/lldap/admin` version 1, created 2026-08-28. Sanitized receipt:
> NK-WP-0033 receipt PASS: read-only resolver lookup, privacyIDEA MFA,
> predecessor denial=NOT-PROVEN, readiness, health, cleanup=PASS
Two earlier attempts in the same session failed closed, and cleanup passed
on both. Neither was a defect in the script:
1. `phase=replacement-lldap-auth`: an LLDAP admin value that was not current
was typed. A probe with a known-wrong value returned 401, which confirmed
the endpoint was healthy.
2. `phase=privacyidea-auth`: the pi-admin prompt got the wrong value.
The lesson for the runbook is to take both values from `operators` custody,
not from memory.
Custody gap closed: `operators/lldap/admin` exists (KV v2; delete is withheld
by the `operator-custody` policy, so predecessors are retained as versions).
The 2026-09-11 identity-provisioner repair confirmed
`provider_password_changed: false`, so version 1 is current.
Predecessor disposition follows the operator ruling above. T03 and T05 are
done, and the incident `KEYCAPE-EXPOSURE-20260823-01` is closed.