Add NetKingdom SSO credential routing lanes
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0217e-8c4c-7383-be6b-f50a6e485306
This commit is contained in:
parent
c8fa02adf0
commit
c374d41a49
4 changed files with 130 additions and 0 deletions
|
|
@ -733,6 +733,70 @@ entries:
|
|||
- "Write the same value to OpenBao and sso/keycape-rapp-qonto-client, then restart KeyCape."
|
||||
- "Verify positive qonto:read exchange plus wrong-secret and excessive-scope denial without printing tokens."
|
||||
|
||||
- id: net-kingdom-lldap-bind-credential
|
||||
title: NetKingdom LLDAP bind credential for identity and privacyIDEA resolver
|
||||
need_keywords: [net-kingdom, netkingdom, sso, lldap, ldap, bind, directory, resolver, privacyidea, privacyIDEA, credential, password]
|
||||
owner_repo: railiance-platform
|
||||
subsystem: OpenBao + NetKingdom SSO/MFA
|
||||
warden_executes: false
|
||||
wiki_ref: wiki/playbooks/net-kingdom-sso-bind-credentials.md#worker-checklist
|
||||
canon_ref: net-kingdom/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md
|
||||
reviewed: "2026-08-23"
|
||||
status: active
|
||||
delegation:
|
||||
mode: native
|
||||
intended_owner: railiance-platform
|
||||
blocked_on: "Concrete OpenBao path, field contract, owner update procedure, and approved attended reconciliation handoff are not published yet; do not enable fetch or proxy execution."
|
||||
reviewed: "2026-08-23"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Provider/control-plane bind credential; identity-provisioner and privacyIDEA consumers are governed by NetKingdom rather than a single declared workload."
|
||||
auth_method: "Owner-approved railiance-platform OpenBao custody path; provider reconciliation remains an attended NetKingdom operation"
|
||||
lane: secret
|
||||
exec_capable: false
|
||||
rotation:
|
||||
method: re-establish
|
||||
owner: railiance-platform
|
||||
automatable: false
|
||||
steps:
|
||||
- "Rotate through the owner-approved OpenBao/provider procedure; never export the live Kubernetes Secret or place a value in argv, logs, State Hub, or chat."
|
||||
- "Reload identity-provisioner and reconcile privacyIDEA's lldap-coulomb resolver in the same approved window."
|
||||
- "Verify replacement lookup, predecessor denial, readiness, and cleanup using sanitized evidence only."
|
||||
|
||||
- id: net-kingdom-privacyidea-admin-token
|
||||
title: NetKingdom privacyIDEA administrative token for attended resolver reconciliation
|
||||
need_keywords: [net-kingdom, netkingdom, sso, mfa, privacyidea, privacyIDEA, pi-admin, admin, token, resolver, lldap, credential]
|
||||
owner_repo: railiance-platform
|
||||
subsystem: OpenBao + privacyIDEA
|
||||
warden_executes: false
|
||||
wiki_ref: wiki/playbooks/net-kingdom-sso-bind-credentials.md#worker-checklist
|
||||
canon_ref: net-kingdom/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md
|
||||
reviewed: "2026-08-23"
|
||||
status: active
|
||||
delegation:
|
||||
mode: native
|
||||
intended_owner: railiance-platform
|
||||
blocked_on: "Concrete OpenBao path, field contract, token expiry/revocation contract, and approved attended reconciliation handoff are not published yet; do not enable fetch or proxy execution."
|
||||
reviewed: "2026-08-23"
|
||||
verified: unverified
|
||||
risk: high
|
||||
workload_ref:
|
||||
applicability: not-applicable
|
||||
reason: "Provider-admin credential for attended privacyIDEA reconciliation, not a workload delivery lane."
|
||||
auth_method: "Owner-approved railiance-platform OpenBao custody path; privacyIDEA reconciliation remains an attended NetKingdom operation"
|
||||
lane: secret
|
||||
exec_capable: false
|
||||
rotation:
|
||||
method: rotate
|
||||
owner: railiance-platform
|
||||
automatable: false
|
||||
steps:
|
||||
- "Obtain a fresh owner-approved privacyIDEA administrative token through the sanctioned custody path; never print or persist it in the routing layer."
|
||||
- "Run only the reviewed NetKingdom attended resolver reconciliation with explicit apply and bounded cleanup."
|
||||
- "Verify MFA/provider health, predecessor rejection or expiry, and sanitized cleanup evidence."
|
||||
|
||||
- id: agent-harness-forgejo-deploy
|
||||
title: agent-harness Forgejo deploy key (write sandbox; binky-control at cutover)
|
||||
need_keywords: [agent-harness, forgejo, deploy, key, ssh, executor-sandbox, railiance, binky-control, deploy-key]
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue