From edee5c28ab89d2fd7cb55c9a8d621702201592ef Mon Sep 17 00:00:00 2001 From: tegwick Date: Sun, 23 Aug 2026 14:42:59 +0200 Subject: [PATCH] docs: record downstream rotation follow-up Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e3f-7301-7622-9be1-12e5f352881c --- .../NK-WP-0033-keycape-secret-exposure-rotation.md | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md b/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md index 5deb74d..15a9185 100644 --- a/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md +++ b/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md @@ -111,11 +111,11 @@ identity-provisioner restart, privacyIDEA resolver `lldap-coulomb`, the Authelia client hash, and the privacyIDEA JWT expiry disposition. Static or dry-run tests must prove replacements do not enter argv or stdout. -The source-of-truth reconciliation is now in progress: Authelia 4.38 OIDC -client entries cannot consume `*_FILE` environment overrides because clients -are a list. NetKingdom is switching the verifier to Authelia's supported -template filter over the Secret-mounted file before this revision is applied -again. +The source-of-truth reconciliation completed in revision `c956ceb`: Authelia +4.38 OIDC client entries cannot consume `*_FILE` environment overrides because +clients are a list, so the verifier now uses Authelia's supported template +filter over the Secret-mounted file. The revision was applied live and +Authelia returned Ready with startup complete. Do not use `sso-mfa/bootstrap/creds-rotate.sh` through an agent as currently written: it prints generated replacement values and its signing-key path @@ -141,7 +141,9 @@ complete. Completed by the KeyCape owner-controlled recovery path on 2026-08-23. The owner reported all four affected deployments Ready and positive/negative -checks passing. NetKingdom made no live mutation. +checks passing. NetKingdom additionally restarted identity-provisioner after +the LLDAP bind rotation and applied the Authelia template-filter fix. The +privacyIDEA resolver still awaits attended provider-admin reconciliation. ## T05 — Prove replacement, predecessor rejection, and cleanup