net-kingdom/docs/attended-procedure-inventory.md
tegwick 4e07d60ff1
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Validate cadence contract and require functional MFA verification
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ea3-7939-7b63-8125-699f8b50bedd
2026-09-05 01:28:05 +02:00

5.5 KiB

Attended procedure inventory — 2026-09-05

Reviewed all 32 shell scripts under sso-mfa/k8s/ for NK-WP-0034-T03. Exercise status: unknown unless the row states otherwise. Existing deployment or task completion is not treated as proof that a particular script revision completed successfully with an identified operator. Unknown does not mean never run.

Runbook matching below requires an explicit script reference in the component runbook or a dedicated procedure. Missing runbooks are listed separately.

Script (under sso-mfa/k8s/) Runbook Exercise status
authelia/create-secrets.sh README.md, smooth-bootstrap-guide.md unknown
keycape/configure-openbao-oidc.sh README.md unknown
keycape/create-pi-token.sh README.md unknown
keycape/create-secrets.sh README.md, smooth-bootstrap-guide.md unknown
keycape/patch-openbao-client.sh README.md unknown
keycape/refresh-pi-token-live.sh README.md unknown
keycape/register-coulomb-social.sh None found unknown
keycape/verify-openbao-client.sh README.md, smooth-bootstrap-guide.md unknown
lldap/bootstrap-users.sh README.md, OPERATOR-GROUPS.md unknown
lldap/break-glass.sh platform-root-custody.md unknown
lldap/create-secrets.sh README.md, smooth-bootstrap-guide.md unknown
lldap/create-user.sh OPERATOR-GROUPS.md, smooth-bootstrap-guide.md unknown
lldap/dry-run-nonroot-user.sh smooth-bootstrap-guide.md unknown
lldap/manage-group-members.sh OPERATOR-GROUPS.md unknown
postgresql/create-secrets.sh README.md, smooth-bootstrap-guide.md unknown
privacyidea/bootstrap-admin.sh README.md unknown
privacyidea/bootstrap-realm.sh keycape-exposure-resolver-reconciliation.md unknown
privacyidea/check-user-mfa-state.sh smooth-bootstrap-guide.md unknown
privacyidea/create-secrets.sh README.md, smooth-bootstrap-guide.md unknown
privacyidea/enckey-bootstrap.sh README.md unknown
privacyidea/reconcile-lldap-resolver-live.sh keycape-exposure-resolver-reconciliation.md attempted by Bernd Worsch 2026-08-27; no completed PASS receipt
privacyidea/repair-realm-live.sh smooth-bootstrap-guide.md, keycape-exposure-resolver-reconciliation.md, verify-t06.md unknown
privacyidea/update-lldap-resolver-live.sh None found unknown
user-engine/verify-operability.sh None found unknown
verify-identity-cutover-dependencies.sh None found unknown
verify-t02.sh README.md unknown
verify-t03.sh DR-RUNBOOK.md unknown
verify-t04.sh DR-RUNBOOK.md unknown
verify-t05.sh DR-RUNBOOK.md unknown
verify-t06.sh verify-t06.md unexercised on provider; HTTP simulation passed
verify-t07.sh DR-RUNBOOK.md unknown
verify-t08.sh DR-RUNBOOK.md unknown

Scripts without a matching runbook

  • sso-mfa/k8s/keycape/register-coulomb-social.sh — header usage is available, but a runbook with prerequisites, verification and exercise history was not found in the reviewed runbook set.
  • sso-mfa/k8s/privacyidea/update-lldap-resolver-live.sh — header usage is available, but a runbook with prerequisites, verification and exercise history was not found in the reviewed runbook set.
  • sso-mfa/k8s/user-engine/verify-operability.sh — header usage is available, but a runbook with prerequisites, verification and exercise history was not found in the reviewed runbook set.
  • sso-mfa/k8s/verify-identity-cutover-dependencies.sh — header usage is available, but a runbook with prerequisites, verification and exercise history was not found in the reviewed runbook set.

Exercise evidence correction

The resolver reconciliation runbook previously called an attempted run “exercised” despite the incident explicitly recording no green receipt. Its header now says unexercised to successful completion. Existing incident authority/window requirements still apply; this documentation review does not authorize that attended cutover. The changed helper must be included in the revision recorded by the operator.