purpose:Hold one ES256 authority private signing key in OpenBao and deliver it only to the private railiance01 Railiance Clock service; no public listener or consumer-wide distribution.
selector:Private Railiance Clock authority key on railiance01
readiness:pending-review
resolvable:false
delivery:
surface:attended-host-file
target:railiance01:/etc/railiance-clock/authority-key.pem, owner railiance-clock, mode 0600; key material must be generated and delivered through the governed OpenBao platform-admin lane and never appear in Git, argv, logs, or chat.
bootstrap_command:See the attended platform custody runbook to be added with this CCR; configure the service only after key admission, public-key metadata readback, and exact artifact hash verification.
risk:
classification:high
notes:
- Compromise permits forging Railiance Clock samples until the key is revoked and every consumer trust file is replaced.
- The authority remains loopback-only on railiance01; no workstation-wide or public endpoint is admitted.
- Key generation, OpenBao write, host delivery, and rotation require an attended platform operator and railiance-clock owner review.
verification:
positive:
- Exact service identity reads only PRIVATE_KEY_PEM and KEY_ID; authority readiness and signed sample verification pass.
- Host file ownership and mode are exact; private key value is absent from all command output and logs.
negative:
- Other service accounts, namespaces, sibling paths, metadata/listing, and public listeners are denied.
- Wrong key id, wrong authority/environment/epoch, expired trust, rollback, and stale health fail closed.
activation_conditions:
- CCR approved by platform-operator and railiance-clock-owner.
- Dedicated OpenBao policy, Kubernetes role, and host delivery path are applied and read back without secret disclosure.
- Fresh public-key metadata, artifact SHA-256, /readyz, and colocated sample verification are recorded.
evidence:[]
lifecycle:
deactivate:Stop the authority, remove the host key, revoke the workload policy/role, and replace consumer trust files.
rotate:Stop authority and consumers, generate a new key under attended custody, deliver mode 0600, then replace trust files and verify old signatures fail.
compromised:Stop the authority immediately, revoke the policy and key version, replace all trust files, and restart only after fresh verification.