diff --git a/credential-change-requests/CCR-2026-0014-policy-nexus-forgejo-source-read.yaml b/credential-change-requests/CCR-2026-0014-policy-nexus-forgejo-source-read.yaml index db22f73..768e3a4 100644 --- a/credential-change-requests/CCR-2026-0014-policy-nexus-forgejo-source-read.yaml +++ b/credential-change-requests/CCR-2026-0014-policy-nexus-forgejo-source-read.yaml @@ -127,6 +127,16 @@ verification: - Approved metadata dry-run passed; two governed platform-admin OIDC attempts failed closed before command handoff; Warden revoked any possible session; no OpenBao mutation or secret provisioning occurred. + - at: '2026-08-31T21:26:07+00:00' + actor: codex attended operator + kind: attended_oidc_handoff + result: blocked + details: + - Canonical bootstrap command from railiance-platform commit 1b85a3e failed closed + before child handoff; Warden revoked any possible session. OpenBao is initialized/unsealed + and its public health endpoint returns 200; the KeyCape openbao-admin authorize + path returns 302. No Forgejo identity, PAT, OpenBao secret value, Actions secret, + or workflow run was created. lifecycle: deactivate: Remove the repository Actions secret, revoke the Forgejo PAT, disable the OpenBao access path, and leave scheduled publication failing closed.