Add NetKingdom SSO credential routing lanes
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0217e-8c4c-7383-be6b-f50a6e485306
This commit is contained in:
tegwick 2026-08-23 21:43:12 +02:00
parent c8fa02adf0
commit c374d41a49
4 changed files with 130 additions and 0 deletions

View file

@ -733,6 +733,70 @@ entries:
- "Write the same value to OpenBao and sso/keycape-rapp-qonto-client, then restart KeyCape."
- "Verify positive qonto:read exchange plus wrong-secret and excessive-scope denial without printing tokens."
- id: net-kingdom-lldap-bind-credential
title: NetKingdom LLDAP bind credential for identity and privacyIDEA resolver
need_keywords: [net-kingdom, netkingdom, sso, lldap, ldap, bind, directory, resolver, privacyidea, privacyIDEA, credential, password]
owner_repo: railiance-platform
subsystem: OpenBao + NetKingdom SSO/MFA
warden_executes: false
wiki_ref: wiki/playbooks/net-kingdom-sso-bind-credentials.md#worker-checklist
canon_ref: net-kingdom/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md
reviewed: "2026-08-23"
status: active
delegation:
mode: native
intended_owner: railiance-platform
blocked_on: "Concrete OpenBao path, field contract, owner update procedure, and approved attended reconciliation handoff are not published yet; do not enable fetch or proxy execution."
reviewed: "2026-08-23"
verified: unverified
risk: high
workload_ref:
applicability: not-applicable
reason: "Provider/control-plane bind credential; identity-provisioner and privacyIDEA consumers are governed by NetKingdom rather than a single declared workload."
auth_method: "Owner-approved railiance-platform OpenBao custody path; provider reconciliation remains an attended NetKingdom operation"
lane: secret
exec_capable: false
rotation:
method: re-establish
owner: railiance-platform
automatable: false
steps:
- "Rotate through the owner-approved OpenBao/provider procedure; never export the live Kubernetes Secret or place a value in argv, logs, State Hub, or chat."
- "Reload identity-provisioner and reconcile privacyIDEA's lldap-coulomb resolver in the same approved window."
- "Verify replacement lookup, predecessor denial, readiness, and cleanup using sanitized evidence only."
- id: net-kingdom-privacyidea-admin-token
title: NetKingdom privacyIDEA administrative token for attended resolver reconciliation
need_keywords: [net-kingdom, netkingdom, sso, mfa, privacyidea, privacyIDEA, pi-admin, admin, token, resolver, lldap, credential]
owner_repo: railiance-platform
subsystem: OpenBao + privacyIDEA
warden_executes: false
wiki_ref: wiki/playbooks/net-kingdom-sso-bind-credentials.md#worker-checklist
canon_ref: net-kingdom/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md
reviewed: "2026-08-23"
status: active
delegation:
mode: native
intended_owner: railiance-platform
blocked_on: "Concrete OpenBao path, field contract, token expiry/revocation contract, and approved attended reconciliation handoff are not published yet; do not enable fetch or proxy execution."
reviewed: "2026-08-23"
verified: unverified
risk: high
workload_ref:
applicability: not-applicable
reason: "Provider-admin credential for attended privacyIDEA reconciliation, not a workload delivery lane."
auth_method: "Owner-approved railiance-platform OpenBao custody path; privacyIDEA reconciliation remains an attended NetKingdom operation"
lane: secret
exec_capable: false
rotation:
method: rotate
owner: railiance-platform
automatable: false
steps:
- "Obtain a fresh owner-approved privacyIDEA administrative token through the sanctioned custody path; never print or persist it in the routing layer."
- "Run only the reviewed NetKingdom attended resolver reconciliation with explicit apply and bounded cleanup."
- "Verify MFA/provider health, predecessor rejection or expiry, and sanitized cleanup evidence."
- id: agent-harness-forgejo-deploy
title: agent-harness Forgejo deploy key (write sandbox; binky-control at cutover)
need_keywords: [agent-harness, forgejo, deploy, key, ssh, executor-sandbox, railiance, binky-control, deploy-key]