Exact CCR-2026-0027 OIDC role. No secret fetch. Platform owns the reviewed exchange-proof child. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
17 lines
737 B
Markdown
17 lines
737 B
Markdown
# Sitting-requester reader session
|
|
|
|
CCR-2026-0027 admits only
|
|
`platform/workloads/informed-decision/sitting-requester`. The contained Warden
|
|
login uses `informed-decision-sitting-requester-workload-kv-read`. Its owner
|
|
command checks exact reader policies, sibling denial of
|
|
`secrets-engine/approval-requester`, and a create-only KeyCape token exchange.
|
|
It does not POST sittings and never prints the client secret.
|
|
|
|
Use the current source catalog explicitly:
|
|
|
|
`WARDEN_ROUTING_CATALOG=/home/worsch/ops-warden/registry/routing/catalog.yaml`
|
|
|
|
The reviewed child is
|
|
`/home/worsch/railiance-platform/scripts/prove-sitting-requester-exchange.sh`.
|
|
OpenBao is reached through `http://127.0.0.1:18200`. Warden self-revokes after
|
|
the child exits.
|