ops-warden/wiki/playbooks/informed-decision-sitting-requester-login.md
tegwick 308409bff1
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Add informed-decision-sitting-requester reader login lane.
Exact CCR-2026-0027 OIDC role. No secret fetch. Platform owns the
reviewed exchange-proof child.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
2026-09-15 20:38:47 +02:00

737 B

Sitting-requester reader session

CCR-2026-0027 admits only platform/workloads/informed-decision/sitting-requester. The contained Warden login uses informed-decision-sitting-requester-workload-kv-read. Its owner command checks exact reader policies, sibling denial of secrets-engine/approval-requester, and a create-only KeyCape token exchange. It does not POST sittings and never prints the client secret.

Use the current source catalog explicitly:

WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml

The reviewed child is /home/worsch/railiance-platform/scripts/prove-sitting-requester-exchange.sh. OpenBao is reached through http://127.0.0.1:18200. Warden self-revokes after the child exits.