Plan KeyCape exposure recovery
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
This commit is contained in:
parent
c9d02147d3
commit
453fed3b2d
3 changed files with 271 additions and 0 deletions
|
|
@ -0,0 +1,88 @@
|
|||
---
|
||||
id: RAILIANCE-WP-0029
|
||||
type: workplan
|
||||
title: "Coordinate KeyCape live Secret exposure recovery"
|
||||
domain: financials
|
||||
repo: railiance-platform
|
||||
status: active
|
||||
owner: codex
|
||||
topic_slug: railiance
|
||||
created: "2026-08-23"
|
||||
updated: "2026-08-23"
|
||||
related:
|
||||
- KEY-WP-0011
|
||||
origin: routed
|
||||
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d and acf98be3-ff6b-4270-bd21-0193bebd806b"
|
||||
---
|
||||
|
||||
# RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery
|
||||
|
||||
## Goal
|
||||
|
||||
Coordinate a forward-only, value-safe rotation of every credential class in
|
||||
the exposed `sso/keycape-config` bundle. Never reproduce or decode the exposed
|
||||
payload and never treat repository access as live mutation authority.
|
||||
|
||||
## T01 — Contain and establish the recovery boundary
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0029-T01
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection,
|
||||
and routed custody through `warden route show openbao-api-key`. Metadata-only
|
||||
preflight pinned Secret UID/resource version, Deployment generation/image, and
|
||||
the public JWKS digest/kid. The legacy value-printing rotation helper is banned.
|
||||
|
||||
## T02 — Publish the governed bundle cutover
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0029-T02
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
`docs/keycape-live-secret-exposure-recovery.md` defines owners, required
|
||||
revision/window/operator receipts, private-file handling, one guarded bundle
|
||||
apply, provider/consumer ordering, forward-only abort, positive/negative proof,
|
||||
predecessor revocation, and sanitized evidence.
|
||||
|
||||
## T03 — Collect exact owner acknowledgements
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0029-T03
|
||||
status: progress
|
||||
priority: high
|
||||
```
|
||||
|
||||
KeyCape must pin the non-secret client-config revision and either a unique-kid
|
||||
overlap implementation or the exact immediate-invalidation/cache-refresh
|
||||
procedure. NetKingdom must pin the LLDAP, Authelia, and privacyIDEA provider
|
||||
steps. Railiance-platform must then issue one digest-bound approval template.
|
||||
|
||||
## T04 — Execute the attended rotation
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0029-T04
|
||||
status: wait
|
||||
priority: high
|
||||
```
|
||||
|
||||
Requires a fresh exact human GO, an at-most-30-minute window, named driver and
|
||||
abort operator, approved revisions, provider access, private workspace cleanup,
|
||||
and all T03 acknowledgements. No value may enter captured output.
|
||||
|
||||
## T05 — Prove predecessor denial and close
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0029-T05
|
||||
status: wait
|
||||
priority: high
|
||||
```
|
||||
|
||||
Verify replacement operation and predecessor rejection for the signing key,
|
||||
LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe
|
||||
fingerprints, resource versions, public JWKS metadata, boolean results, rollout
|
||||
status, timestamps, and cleanup receipts.
|
||||
Loading…
Add table
Add a link
Reference in a new issue