Establish scoped KeyCape factor custody and verified automatic renewal
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
parent
b75729b799
commit
2e2c31d237
22 changed files with 1169 additions and 1 deletions
|
|
@ -0,0 +1,94 @@
|
|||
id: CCR-2026-0023
|
||||
kind: credential-change-request
|
||||
schema_version: 1
|
||||
request_type: workload-kv-read
|
||||
title: KeyCape realm-scoped factor credential delivery
|
||||
status: active
|
||||
created: '2026-09-13'
|
||||
updated: '2026-09-13'
|
||||
requester:
|
||||
agent: codex
|
||||
reason: User authorized establishing provider credential custody and delivery for
|
||||
platform P05; RPF-WP-0040 and KEY-WP-0035.
|
||||
review:
|
||||
required: true
|
||||
required_approvers:
|
||||
- platform-operator
|
||||
comments:
|
||||
- at: '2026-09-13T00:00:00+00:00'
|
||||
reviewer: user (platform operator)
|
||||
decision: approved
|
||||
comment: User offered administrative authentication and replied "ok, lets do that"
|
||||
to establishing credential storage and delivery. Exact dedicated path, least-privilege
|
||||
workload binding and secret-free attended execution implement that authorized
|
||||
scope. Provider recovery and policy acceptance remain separate gates.
|
||||
target:
|
||||
domain: infotech
|
||||
tenant: platform
|
||||
workload: key-cape
|
||||
environment: production
|
||||
purpose: Deliver only a provider-issued coulomb factor-read JWT to KeyCape, separating
|
||||
it from issuer credentials and signing keys.
|
||||
openbao:
|
||||
mount: platform
|
||||
kv_path: platform/workloads/net-kingdom/keycape-factor-read
|
||||
fields:
|
||||
- TOKEN
|
||||
- EXPIRES_AT
|
||||
policy_name: workload-kv-read-keycape-factor-read
|
||||
policy_file: openbao/policies/workload-kv-read-keycape-factor-read.hcl
|
||||
metadata_read: true
|
||||
token_self_lifecycle: true
|
||||
auth:
|
||||
method: kubernetes
|
||||
mount: kubernetes
|
||||
role: keycape-factor-workload-kv-read
|
||||
bound_claims:
|
||||
service_account_names:
|
||||
- keycape-factor-eso
|
||||
service_account_namespaces:
|
||||
- sso
|
||||
bound_claims_confirmed: true
|
||||
policies:
|
||||
- workload-kv-read-keycape-factor-read
|
||||
ttl: 15m
|
||||
access_frontdoor:
|
||||
type: external-secrets
|
||||
catalog_id: keycape-factor-read
|
||||
readiness: ready
|
||||
resolvable: true
|
||||
delivery:
|
||||
surface: external-secrets
|
||||
target: Namespace-restricted ClusterSecretStore openbao-keycape-factor-read -> sso/keycape-factor-read
|
||||
Secret admin-token. Mount only the JWT in KeyCape; provider password remains in
|
||||
separate custody.
|
||||
risk:
|
||||
classification: high
|
||||
notes:
|
||||
- JWT can list factors only in coulomb; enforce provider policy before activation.
|
||||
- OpenBao TTL does not renew or revoke the privacyIDEA JWT.
|
||||
- No personal admin credentials delivered to the issuer.
|
||||
verification:
|
||||
positive:
|
||||
- Exact metadata readback and correct-SA Kubernetes login.
|
||||
- Provider-issued JWT accepted and projected file reread after renewal.
|
||||
negative:
|
||||
- Sibling KV paths and writes denied; wrong SA or namespace cannot authenticate.
|
||||
- Provider mutation permission denied and expired credential fails closed.
|
||||
activation_conditions:
|
||||
- Attended metadata apply and exact readback.
|
||||
- Dedicated provider identity with verified rights/expiry and separate renewable
|
||||
custody.
|
||||
- Native delivery and positive/negative factor lookup evidence.
|
||||
evidence:
|
||||
- docs/evidence/2026-09-13-keycape-factor-custody.md
|
||||
lifecycle:
|
||||
deactivate: Detach reader role, stop renewal and revoke/expire provider token; preserve
|
||||
custody history.
|
||||
rotate: Issue replacement before expiry, CAS update exact KV, verify ESO projection
|
||||
and consumer acceptance; retain no plaintext artifacts.
|
||||
compromised: Disable the dedicated provider principal and reconcile JWT revocation
|
||||
or expiry before recovery.
|
||||
state_hub:
|
||||
workplan_id: RPF-WP-0040
|
||||
task_id: RPF-WP-0040-T01
|
||||
Loading…
Add table
Add a link
Reference in a new issue