Record sitting-requester custody apply; keep exchange proof open.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Attended helper returned applied, KV version 1, ESO synced, KeyCape
ready. No sitting POST. CCRs 0026/0027 are applied metadata only.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
codex 2026-09-15 20:31:00 +02:00
parent 75e5c1af65
commit 50f031091c
5 changed files with 54 additions and 3 deletions

View file

@ -3,7 +3,7 @@ kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Informed Decision sitting-requester KeyCape verifier custody
status: approved
status: applied
created: '2026-09-15'
updated: '2026-09-15'
requester:
@ -84,6 +84,17 @@ verification:
until attended CAS=0 custody and exact policy/auth readback.
- Separate reader verification and no human entry synthesized.
- No sitting POST until exchange proof exists.
evidence:
- at: '2026-09-15T18:28:28+00:00'
actor: operator via attended sitting-requester custody session
kind: delegated_metadata_apply
result: passed
details:
- Delegated metadata applier ran as operator via attended sitting-requester custody
session using local bao CLI ambient authority.
- 'Policy metadata write: sys/policies/acl/workload-kv-read-keycape-informed-decision-sitting-requester'
- 'Auth role metadata write: auth/kubernetes/role/external-secrets-keycape-informed-decision-sitting-requester'
- No secret values were read, written, printed, or accepted in argv.
lifecycle:
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025

View file

@ -3,7 +3,7 @@ kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Informed Decision sitting-requester attended operator reader
status: approved
status: applied
created: '2026-09-15'
updated: '2026-09-15'
requester:
@ -93,6 +93,17 @@ verification:
verifier delivery.
- Separate reader verification and no human entry synthesized.
- No sitting POST until exchange proof exists.
evidence:
- at: '2026-09-15T18:28:28+00:00'
actor: operator via attended sitting-requester custody session
kind: delegated_metadata_apply
result: passed
details:
- Delegated metadata applier ran as operator via attended sitting-requester custody
session using local bao CLI ambient authority.
- 'Policy metadata write: sys/policies/acl/workload-kv-read-informed-decision-sitting-requester-client'
- 'Auth role metadata write: auth/netkingdom/role/informed-decision-sitting-requester-workload-kv-read'
- No secret values were read, written, printed, or accepted in argv.
lifecycle:
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025

View file

@ -0,0 +1,23 @@
{
"observed_at": "2026-09-15T18:28:25.214744+00:00",
"status": "applied",
"phase": "keycape_ready",
"ccrs": [
"CCR-2026-0026",
"CCR-2026-0027"
],
"credential_values_emitted": false,
"approval_mutations": false,
"sitting_post": false,
"kv_version": 1,
"request_id": "257e491a-3627-2240-66ae-1c23c0fc0d13",
"keycape": {
"deployment_uid": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f",
"generation": 53,
"pod_uid": "fef16c07-48e8-4073-8fb0-681dce4da5cc",
"single_ready_replica": true
},
"image_unchanged": "forgejo.coulomb.social/coulomb/key-cape@sha256:db2c5a13a47839049349e881c8d19bc39f720ee69d8518f9f2eba2b1f98af9d5",
"unrelated_config_preserved": true,
"verifier_secret_exported": false
}

View file

@ -14,7 +14,7 @@ implementations or independent incidents.
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
| [RPF-WP-0038](RPF-WP-0038-forgejo-scaleway-primary-coverage.md) | Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains | Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention. |
| [RPF-WP-0042](RPF-WP-0042-informed-decision-sitting-requester.md) | Sitting-requester CCRs approved; live KeyCape/OpenBao apply remains | Attended `provision-sitting-requester.sh`; no sitting POST. |
| [RPF-WP-0042](RPF-WP-0042-informed-decision-sitting-requester.md) | Sitting-requester custody applied; exchange proof remains | No sitting POST until create-only token proof. |
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining
acceptance gates. Treat credential exposure closure as the highest-priority attended

View file

@ -52,3 +52,9 @@ No sitting POST until exchange proof exists. Do not widen CCR-2026-0024/0025.
`revocation could not be confirmed`. Public Ingress is already absent, and the
shell still had `BAO_ADDR=https://bao.coulomb.social`. The wrapper now pins the
operator tunnel. Retry that same helper; do not treat this attempt as custody.
Retry 2026-09-15T18:28:25Z succeeded: receipt `applied`, phase `keycape_ready`,
KV version 1, ESO Ready/SecretSynced, KeyCape single Ready replica, CCRs
applied. No sitting POST. Remaining: create-only token-exchange proof
(positive create scope, refuse approve/consume, sibling path deny). Evidence:
`docs/evidence/2026-09-15-sitting-requester-provision.json`.