Track OpenBao custody handoff gate
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
This commit is contained in:
parent
f607d747da
commit
51361fbf8e
1 changed files with 16 additions and 0 deletions
|
|
@ -112,3 +112,19 @@ Verify replacement operation and predecessor rejection for the signing key,
|
|||
LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe
|
||||
fingerprints, resource versions, public JWKS metadata, boolean results, rollout
|
||||
status, timestamps, and cleanup receipts.
|
||||
|
||||
## T06 — Publish the Railiance/OpenBao custody handoff
|
||||
|
||||
```task
|
||||
id: RAILIANCE-WP-0029-T06
|
||||
status: progress
|
||||
priority: high
|
||||
```
|
||||
|
||||
The platform/OpenBao owner must publish a non-secret receipt for both routing
|
||||
lanes: canonical mount/path, field name, KV version semantics, least-privilege
|
||||
policy and auth method, expiry/rotation/revocation semantics, and the approved
|
||||
attended handoff identifier. Do not infer or invent any of these values. After
|
||||
publication, update `docs/net-kingdom-credential-custody-contract.md`, ask
|
||||
ops-warden to refresh lane resolvability, and pass only protected inputs to
|
||||
NetKingdom's minimal resolver reconciliation flow.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue