Record exercised live issuer pin and unchanged production deployment
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-09 00:40:23 +02:00
parent ad9979b159
commit 896c1200c0
2 changed files with 102 additions and 1 deletions

View file

@ -1,6 +1,6 @@
# Pin KeyCape's verified upstream issuer
Exercise status: read-only check exercised 2026-09-09 by codex; guarded write unexercised.
Exercise status: read-only check and guarded live write exercised 2026-09-09 by codex under user continuation authorization.
Owner implementation: `sso-mfa/k8s/keycape/openbao-client-config.py`.
Dependency: KEY-WP-0013-T02 / HFACT-WP-0001-T03. The actual signed upstream
@ -50,3 +50,11 @@ passes 13 tests, covering byte preservation, duplicate/alias rejection, stale
revision refusal, atomic preconditions, readback conflict and secret-free failure
output. The first live check on 2026-09-09 found the pin absent at resourceVersion
`51346058`, UID `2e94519d-1550-41c7-9701-2efe47fe1fd3`.
Live result: the guarded write at 2026-09-08T22:23:58Z (00:23:58 Berlin on
September 9) inserted the missing issuer, advancing the Secret resourceVersion
from `51346058` to `58713343`. Independent check returned `issuer_matches=true`;
all other configuration bytes and Secret data entries were unchanged. The
Deployment stayed at generation 29 with one ready/available replica.
[Receipt](evidence/2026-09-09-keycape-upstream-issuer-pin.json).