Add informed-decision-sitting-requester reader login lane.
Exact CCR-2026-0027 OIDC role. No secret fetch. Platform owns the reviewed exchange-proof child. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
parent
c8be24b940
commit
308409bff1
3 changed files with 46 additions and 4 deletions
17
wiki/playbooks/informed-decision-sitting-requester-login.md
Normal file
17
wiki/playbooks/informed-decision-sitting-requester-login.md
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
# Sitting-requester reader session
|
||||
|
||||
CCR-2026-0027 admits only
|
||||
`platform/workloads/informed-decision/sitting-requester`. The contained Warden
|
||||
login uses `informed-decision-sitting-requester-workload-kv-read`. Its owner
|
||||
command checks exact reader policies, sibling denial of
|
||||
`secrets-engine/approval-requester`, and a create-only KeyCape token exchange.
|
||||
It does not POST sittings and never prints the client secret.
|
||||
|
||||
Use the current source catalog explicitly:
|
||||
|
||||
`WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml`
|
||||
|
||||
The reviewed child is
|
||||
`/home/worsch/railiance-platform/scripts/prove-sitting-requester-exchange.sh`.
|
||||
OpenBao is reached through `http://127.0.0.1:18200`. Warden self-revokes after
|
||||
the child exits.
|
||||
Loading…
Add table
Add a link
Reference in a new issue