diff --git a/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md b/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md index 4588932..f03c1e6 100644 --- a/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md +++ b/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md @@ -112,3 +112,19 @@ Verify replacement operation and predecessor rejection for the signing key, LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe fingerprints, resource versions, public JWKS metadata, boolean results, rollout status, timestamps, and cleanup receipts. + +## T06 — Publish the Railiance/OpenBao custody handoff + +```task +id: RAILIANCE-WP-0029-T06 +status: progress +priority: high +``` + +The platform/OpenBao owner must publish a non-secret receipt for both routing +lanes: canonical mount/path, field name, KV version semantics, least-privilege +policy and auth method, expiry/rotation/revocation semantics, and the approved +attended handoff identifier. Do not infer or invent any of these values. After +publication, update `docs/net-kingdom-credential-custody-contract.md`, ask +ops-warden to refresh lane resolvability, and pass only protected inputs to +NetKingdom's minimal resolver reconciliation flow.