Approve sitting-requester CCRs and add the attended provisioner.
CCR-2026-0026/0027 are approved for the create-only informed-decision client. Live KeyCape registration and CAS=0 custody stay in the contained helper; no sitting POST. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
parent
6dfb751e60
commit
4b34c239bc
7 changed files with 162 additions and 9 deletions
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Allocate Informed Decision sitting-requester custody"
|
||||
domain: financials
|
||||
repo: railiance-platform
|
||||
status: ready
|
||||
status: active
|
||||
flavor: implementation
|
||||
owner: grok
|
||||
topic_slug: railiance
|
||||
|
|
@ -38,12 +38,12 @@ non-resolvable. ESO projection is unapplied source.
|
|||
|
||||
```task
|
||||
id: RPF-WP-0042-T02
|
||||
status: wait
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "c6fbf99c-de2b-55be-9f0c-58be9fe7c518"
|
||||
```
|
||||
|
||||
Requires named owner reviews, KeyCape row `informed-decision-sitting-requester`,
|
||||
attended CAS=0 custody, exact policy/auth readback, sibling
|
||||
`secrets-engine/approval-requester` denial, and create-only token-exchange proof.
|
||||
No sitting POST until that proof exists.
|
||||
Operator approved CCR-2026-0026/0027 on 2026-09-15. Source registration is in
|
||||
`key-cape/config/service-clients.example.yaml`. Live apply is the silent helper
|
||||
`scripts/provision-sitting-requester.sh` through `openbao-attended-exec.py`.
|
||||
No sitting POST until exchange proof exists. Do not widen CCR-2026-0024/0025.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue