2026-08-23 14:10:06 +02:00
---
2026-08-26 19:44:46 +02:00
id: RPF-WP-0027
2026-08-23 14:10:06 +02:00
type: workplan
title: "Coordinate KeyCape live Secret exposure recovery"
domain: financials
repo: railiance-platform
status: active
owner: codex
topic_slug: railiance
created: "2026-08-23"
updated: "2026-08-23"
related:
- KEY-WP-0011
origin: routed
2026-08-23 14:37:36 +02:00
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4"
2026-08-26 19:44:46 +02:00
state_hub_workstream_id: "b2c25a01-4a80-55c1-90cf-8538000f7e0e"
2026-08-23 14:10:06 +02:00
---
2026-08-26 19:44:46 +02:00
# RPF-WP-0027 — KeyCape live Secret exposure recovery
2026-08-23 14:10:06 +02:00
## Goal
Coordinate a forward-only, value-safe rotation of every credential class in
the exposed `sso/keycape-config` bundle. Never reproduce or decode the exposed
payload and never treat repository access as live mutation authority.
## T01 — Contain and establish the recovery boundary
```task
2026-08-26 19:44:46 +02:00
id: RPF-WP-0027-T01
2026-08-23 14:10:06 +02:00
status: done
priority: high
2026-08-26 19:44:46 +02:00
state_hub_task_id: "53f47272-92ab-563b-9d69-5eafee733e6b"
2026-08-23 14:10:06 +02:00
```
Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection,
and routed custody through `warden route show openbao-api-key` . Metadata-only
preflight pinned Secret UID/resource version, Deployment generation/image, and
the public JWKS digest/kid. The legacy value-printing rotation helper is banned.
## T02 — Publish the governed bundle cutover
```task
2026-08-26 19:44:46 +02:00
id: RPF-WP-0027-T02
2026-08-23 14:10:06 +02:00
status: done
priority: high
2026-08-26 19:44:46 +02:00
state_hub_task_id: "3c55b1cd-8f6b-5a48-b416-18ab711954e3"
2026-08-23 14:10:06 +02:00
```
`docs/keycape-live-secret-exposure-recovery.md` defines owners, required
revision/window/operator receipts, private-file handling, one guarded bundle
apply, provider/consumer ordering, forward-only abort, positive/negative proof,
predecessor revocation, and sanitized evidence.
## T03 — Collect exact owner acknowledgements
```task
2026-08-26 19:44:46 +02:00
id: RPF-WP-0027-T03
2026-08-23 14:10:06 +02:00
status: progress
priority: high
2026-08-26 19:44:46 +02:00
state_hub_task_id: "714ae011-903d-55e2-ac47-801b8ef879d1"
2026-08-23 14:10:06 +02:00
```
2026-08-23 14:51:50 +02:00
KeyCape supplied source revision `93704fd2424503007c20b458b62a7f7d994bb288` ,
post-rotation JWKS SHA-256
`c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156` , and
rollout/predecessor evidence (messages `05b49688-76a8-4be9-a00d-95408c798697`
and `538046b9-2dbb-4704-b7b6-2dbf16c5e3bb` ). NetKingdom pinned the value-safe
dependency and provider sequence at `c24d67b` (message
`71b1008a-7fd7-4500-85c6-e8893a6d80d4` ). The persistent privacyIDEA
`lldap-coulomb` resolver still requires an attended provider-admin update, so
T04 remains blocked for that explicit follow-up. The digest-bound approval
2026-08-23 14:37:36 +02:00
template is published at
2026-08-23 14:51:50 +02:00
`docs/keycape-exposure-rotation-approval.example.json` ; no additional Secret
apply is authorized by this receipt.
2026-08-23 14:10:06 +02:00
2026-08-23 15:06:50 +02:00
NetKingdom has now pinned the remaining attended resolver procedure at
`eec7007` (procedure checkout `f2e578c` , owner receipt
`45b236c8-052f-43d3-a472-44f8e9694da2` ). It performs one resolver-only POST,
protected interactive inputs, boolean postchecks, replacement-success and
predecessor-denial evidence, and forward-only abort. T03 is ready for the
attended run; T04/T05 remain open until that run produces a sanitized receipt.
2026-08-23 15:13:35 +02:00
The operator completed the resolver-only update and received
`privacyIDEA resolver update: PASS` . Postchecks were not yet run; the operator
was instructed to stop rather than improvise. NetKingdom has been asked to
package the complete sequence as one receipt-producing command for the next
run.
2026-08-23 21:48:29 +02:00
The Railiance-side custody contract is drafted at
`docs/net-kingdom-credential-custody-contract.md` . It deliberately leaves the
OpenBao path and field names unfilled pending owner confirmation; the routing
lane remains unresolved and no credential fetch or retry is authorized.
2026-08-23 14:10:06 +02:00
## T04 — Execute the attended rotation
```task
2026-08-26 19:44:46 +02:00
id: RPF-WP-0027-T04
2026-08-23 14:10:06 +02:00
status: wait
priority: high
2026-08-26 19:44:46 +02:00
state_hub_task_id: "28b31e57-7a76-5100-8a61-9aa87339c5d7"
2026-08-23 14:10:06 +02:00
```
Requires a fresh exact human GO, an at-most-30-minute window, named driver and
abort operator, approved revisions, provider access, private workspace cleanup,
and all T03 acknowledgements. No value may enter captured output.
## T05 — Prove predecessor denial and close
```task
2026-08-26 19:44:46 +02:00
id: RPF-WP-0027-T05
2026-08-23 14:10:06 +02:00
status: wait
priority: high
2026-08-26 19:44:46 +02:00
state_hub_task_id: "9cb5fa67-012a-58cf-bafb-e7c7d4f9782d"
2026-08-23 14:10:06 +02:00
```
Verify replacement operation and predecessor rejection for the signing key,
LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe
fingerprints, resource versions, public JWKS metadata, boolean results, rollout
status, timestamps, and cleanup receipts.
2026-08-23 22:01:21 +02:00
## T06 — Publish the Railiance/OpenBao custody handoff
```task
2026-08-26 19:44:46 +02:00
id: RPF-WP-0027-T06
2026-08-23 22:01:21 +02:00
status: progress
priority: high
2026-08-26 19:44:46 +02:00
state_hub_task_id: "3b9748c4-2906-5ba7-9d34-0a7067a59283"
2026-08-23 22:01:21 +02:00
```
The platform/OpenBao owner must publish a non-secret receipt for both routing
lanes: canonical mount/path, field name, KV version semantics, least-privilege
policy and auth method, expiry/rotation/revocation semantics, and the approved
attended handoff identifier. Do not infer or invent any of these values. After
publication, update `docs/net-kingdom-credential-custody-contract.md` , ask
ops-warden to refresh lane resolvability, and pass only protected inputs to
NetKingdom's minimal resolver reconciliation flow.