diff --git a/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md b/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md index 5deb74d..15a9185 100644 --- a/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md +++ b/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md @@ -111,11 +111,11 @@ identity-provisioner restart, privacyIDEA resolver `lldap-coulomb`, the Authelia client hash, and the privacyIDEA JWT expiry disposition. Static or dry-run tests must prove replacements do not enter argv or stdout. -The source-of-truth reconciliation is now in progress: Authelia 4.38 OIDC -client entries cannot consume `*_FILE` environment overrides because clients -are a list. NetKingdom is switching the verifier to Authelia's supported -template filter over the Secret-mounted file before this revision is applied -again. +The source-of-truth reconciliation completed in revision `c956ceb`: Authelia +4.38 OIDC client entries cannot consume `*_FILE` environment overrides because +clients are a list, so the verifier now uses Authelia's supported template +filter over the Secret-mounted file. The revision was applied live and +Authelia returned Ready with startup complete. Do not use `sso-mfa/bootstrap/creds-rotate.sh` through an agent as currently written: it prints generated replacement values and its signing-key path @@ -141,7 +141,9 @@ complete. Completed by the KeyCape owner-controlled recovery path on 2026-08-23. The owner reported all four affected deployments Ready and positive/negative -checks passing. NetKingdom made no live mutation. +checks passing. NetKingdom additionally restarted identity-provisioner after +the LLDAP bind rotation and applied the Authelia template-filter fix. The +privacyIDEA resolver still awaits attended provider-admin reconciliation. ## T05 — Prove replacement, predecessor rejection, and cleanup