Route attended T03 requester login to scoped owner reader
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
tegwick 2026-09-14 02:47:32 +02:00
parent edbe95fe15
commit 73e40af6ca
2 changed files with 40 additions and 0 deletions

View file

@ -214,6 +214,30 @@ entries:
exec_capable: true
lane: login
- id: secrets-engine-requester-login
title: Attended T03 create-only requester reader login
risk: high
workload_ref:
applicability: not-applicable
reason: "Attended operator identity for the exact CCR-2026-0025 reader."
need_keywords: [secrets-engine, approval-requester, reader, login, ccr-2026-0025]
owner_repo: railiance-platform
subsystem: OpenBao scoped operator OIDC via KeyCape
warden_executes: false
wiki_ref: wiki/playbooks/secrets-engine-requester-login.md
canon_ref: railiance-platform/credential-change-requests/CCR-2026-0025-t03-requester-reader.yaml
reviewed: "2026-09-14"
status: active
delegation:
mode: native
intended_owner: railiance-platform
reviewed: "2026-09-14"
verified: source-read
auth_method: "attended KeyCape OIDC, netkingdom role secrets-engine-requester-workload-kv-read"
fetch_command: "bao login -no-print -method=oidc -path=netkingdom role=secrets-engine-requester-workload-kv-read"
exec_capable: true
lane: login
- id: openbao-shamir-recovery-ceremony
title: Attended OpenBao Shamir seal and unseal recovery ceremony
# A ceremony pointer, not a credential-value lane. Approval coordinates

View file

@ -0,0 +1,16 @@
# T03 requester session
CCR-2026-0025 admits only the new requester path. The contained Warden login
uses `secrets-engine-requester-workload-kv-read`. Its owner command checks exact
reader policies and denial of the existing consumer path, obtains one in-memory
create-only token and submits only the three frozen T03 records. It cannot bind
or consume an approval and never reads the KeyCape verifier Secret.
Use the current source catalog explicitly while the installed bundle is older:
`WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml`.
The reviewed child is
`/home/worsch/informed-decision/.venv/bin/python -B /home/worsch/railiance-platform/scripts/create-t03-approval-requests.py`.
It requires the owner-bound Approval Engine tunnel at 127.0.0.1:18281 and frozen
native evaluator receipts. Its output is metadata-only persisted by the owner;
Warden self-revokes and removes the reader helper after the child exits.