Add informed-decision-sitting-requester reader login lane.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Exact CCR-2026-0027 OIDC role. No secret fetch. Platform owns the
reviewed exchange-proof child.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
tegwick 2026-09-15 20:38:47 +02:00
parent c8be24b940
commit 308409bff1
3 changed files with 46 additions and 4 deletions

View file

@ -238,6 +238,30 @@ entries:
exec_capable: true
lane: login
- id: informed-decision-sitting-requester-login
title: Attended Informed Decision sitting-requester reader login
risk: high
workload_ref:
applicability: not-applicable
reason: "Attended operator identity for the exact CCR-2026-0027 reader."
need_keywords: [informed-decision, sitting-requester, reader, login, ccr-2026-0027]
owner_repo: railiance-platform
subsystem: OpenBao scoped operator OIDC via KeyCape
warden_executes: false
wiki_ref: wiki/playbooks/informed-decision-sitting-requester-login.md
canon_ref: railiance-platform/credential-change-requests/CCR-2026-0027-informed-decision-sitting-requester-reader.yaml
reviewed: "2026-09-15"
status: active
delegation:
mode: native
intended_owner: railiance-platform
reviewed: "2026-09-15"
verified: source-read
auth_method: "attended KeyCape OIDC, netkingdom role informed-decision-sitting-requester-workload-kv-read"
fetch_command: "bao login -no-print -method=oidc -path=netkingdom role=informed-decision-sitting-requester-workload-kv-read"
exec_capable: true
lane: login
- id: openbao-shamir-recovery-ceremony
title: Attended OpenBao Shamir seal and unseal recovery ceremony
# A ceremony pointer, not a credential-value lane. Approval coordinates