Complete live State Hub signing activation and rotation acceptance
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
parent
ae27a42b18
commit
5d6d8724b4
7 changed files with 167 additions and 9 deletions
|
|
@ -32,7 +32,7 @@
|
||||||
| task | RPF-WP-0035-T01 | done | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
|
| task | RPF-WP-0035-T01 | done | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
|
||||||
| task | RPF-WP-0035-T02 | wait | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
|
| task | RPF-WP-0035-T02 | wait | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
|
||||||
| task | RPF-WP-0035-T03 | wait | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
|
| task | RPF-WP-0035-T03 | wait | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
|
||||||
| task | RPF-WP-0035-T04 | progress | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
|
| task | RPF-WP-0035-T04 | done | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
|
||||||
| task | RPF-WP-0036-T01 | done | — | workplans/RPF-WP-0036-platform-service-assurance.md |
|
| task | RPF-WP-0036-T01 | done | — | workplans/RPF-WP-0036-platform-service-assurance.md |
|
||||||
| task | RPF-WP-0036-T02 | done | — | workplans/RPF-WP-0036-platform-service-assurance.md |
|
| task | RPF-WP-0036-T02 | done | — | workplans/RPF-WP-0036-platform-service-assurance.md |
|
||||||
| task | RPF-WP-0036-T03 | wait | — | workplans/RPF-WP-0036-platform-service-assurance.md |
|
| task | RPF-WP-0036-T03 | wait | — | workplans/RPF-WP-0036-platform-service-assurance.md |
|
||||||
|
|
|
||||||
|
|
@ -3,7 +3,7 @@ kind: credential-change-request
|
||||||
schema_version: 1
|
schema_version: 1
|
||||||
request_type: workload-kv-read
|
request_type: workload-kv-read
|
||||||
title: State Hub repository-rename preflight signing read lane
|
title: State Hub repository-rename preflight signing read lane
|
||||||
status: approved
|
status: active
|
||||||
created: '2026-09-05'
|
created: '2026-09-05'
|
||||||
updated: '2026-09-05'
|
updated: '2026-09-05'
|
||||||
requester:
|
requester:
|
||||||
|
|
@ -73,8 +73,8 @@ access_frontdoor:
|
||||||
type: external-secrets
|
type: external-secrets
|
||||||
catalog_id: state-hub-rename-preflight
|
catalog_id: state-hub-rename-preflight
|
||||||
selector: State Hub API preflight signing delivery only
|
selector: State Hub API preflight signing delivery only
|
||||||
readiness: pending-review
|
readiness: ready
|
||||||
resolvable: false
|
resolvable: true
|
||||||
delivery:
|
delivery:
|
||||||
surface: external-secrets
|
surface: external-secrets
|
||||||
target: Namespace SecretStore openbao-state-hub-rename-preflight -> ExternalSecret/Secret
|
target: Namespace SecretStore openbao-state-hub-rename-preflight -> ExternalSecret/Secret
|
||||||
|
|
@ -82,7 +82,7 @@ delivery:
|
||||||
Retain deletion policy.
|
Retain deletion policy.
|
||||||
bootstrap_command: See docs/credential-lane-designs/state-hub-preflight-signing.md;
|
bootstrap_command: See docs/credential-lane-designs/state-hub-preflight-signing.md;
|
||||||
scripts/state_hub_preflight_lane.py stages the attended protected writer separately
|
scripts/state_hub_preflight_lane.py stages the attended protected writer separately
|
||||||
from this read grant. Owner acceptance and the activation runbook remain pending.
|
from this read grant. Accepted activation and rotation evidence is recorded in state-hub-preflight-activation.md.
|
||||||
risk:
|
risk:
|
||||||
classification: high
|
classification: high
|
||||||
notes:
|
notes:
|
||||||
|
|
@ -108,7 +108,15 @@ verification:
|
||||||
- Demand remains FLEX-WP-0020-T05; target primary/railiance01 and fixture confirmed.
|
- Demand remains FLEX-WP-0020-T05; target primary/railiance01 and fixture confirmed.
|
||||||
- CAS-zero protected generation, exact read grant, and API-only delivery verified.
|
- CAS-zero protected generation, exact read grant, and API-only delivery verified.
|
||||||
- Controlled-outage fence and recovery exercised before completion.
|
- Controlled-outage fence and recovery exercised before completion.
|
||||||
evidence: []
|
evidence:
|
||||||
|
- at: '2026-09-05T15:59:08+00:00'
|
||||||
|
actor: codex
|
||||||
|
kind: frontdoor_activation
|
||||||
|
result: passed
|
||||||
|
details:
|
||||||
|
- 'docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json: exact access
|
||||||
|
negatives, ESO delivery, API-only signing, CAS version 2, predecessor signature
|
||||||
|
denial and forward recovery passed; Helm revision 59.'
|
||||||
lifecycle:
|
lifecycle:
|
||||||
deactivate: Fence API replicas, disable signing binding and ESO role, restart without
|
deactivate: Fence API replicas, disable signing binding and ESO role, restart without
|
||||||
signing; retain KV history by explicit retention decision.
|
signing; retain KV history by explicit retention decision.
|
||||||
|
|
|
||||||
|
|
@ -35,7 +35,7 @@ cross-namespace store references. Coding-agent data AND metadata are denied.
|
||||||
```sh
|
```sh
|
||||||
warden access openbao-platform-admin-login --exec -- \
|
warden access openbao-platform-admin-login --exec -- \
|
||||||
/usr/bin/python3 /home/worsch/railiance-platform/scripts/state_hub_preflight_lane.py \
|
/usr/bin/python3 /home/worsch/railiance-platform/scripts/state_hub_preflight_lane.py \
|
||||||
provision --expected-version 0 --kubeconfig /home/worsch/.kube/config \
|
provision --expected-version 0 --kubeconfig /home/worsch/.kube/config-railiance01 \
|
||||||
--receipt /tmp/statehub-preflight-provision.json --confirm 'APPLY CCR-2026-0015'
|
--receipt /tmp/statehub-preflight-provision.json --confirm 'APPLY CCR-2026-0015'
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
@ -107,3 +107,25 @@ preserving every unrelated live rule. It does not deploy the pending Policy
|
||||||
Nexus source-only change as part of this lane. The global source policy retains
|
Nexus source-only change as part of this lane. The global source policy retains
|
||||||
its desired rules; live parity for that other lane remains a platform assurance
|
its desired rules; live parity for that other lane remains a platform assurance
|
||||||
observation, not an acceptance claim here.
|
observation, not an acceptance claim here.
|
||||||
|
|
||||||
|
|
||||||
|
## Accepted activation — 2026-09-05
|
||||||
|
|
||||||
|
T04 completed; CCR-2026-0015 is active. Version 1 was generated with CAS zero,
|
||||||
|
then version 2 was generated with CAS 1 during the all-API-replicas outage.
|
||||||
|
Both custody receipts passed exact read and scope/identity denials. ESO is Ready;
|
||||||
|
Helm revision 59 enabled the API-only binding with the existing image. The
|
||||||
|
post-rotation API probe passed key equality, primary health, new signed preflight
|
||||||
|
and predecessor signature rejection. No repository rename was executed.
|
||||||
|
|
||||||
|
ESO v0.16.1 required token self-validation and cleanup despite the deliberate
|
||||||
|
absence of the default policy. The exact read policy now additionally permits
|
||||||
|
`auth/token/lookup-self` read and `auth/token/revoke-self` update. It adds no KV
|
||||||
|
metadata, parent list or secret write. Source evidence:
|
||||||
|
https://github.com/external-secrets/external-secrets/blob/v0.16.1/pkg/provider/vault/auth.go
|
||||||
|
The bounded `repair-policy` action refuses drift and does not regenerate a key.
|
||||||
|
|
||||||
|
Use the dedicated kubeconfig above, whose port-forward endpoint is 16444;
|
||||||
|
the default config's 16443 listener was unavailable. Always verify the pinned
|
||||||
|
cluster UID. Protected predecessor fixture was removed after acceptance.
|
||||||
|
Receipts: `docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json`.
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,8 @@
|
||||||
# State Hub repository-rename preflight signing lane
|
# State Hub repository-rename preflight signing lane
|
||||||
|
|
||||||
Status: implementation staged, not provisioned. Owner: railiance-platform, RPF-WP-0035-T04.
|
Status: active; accepted 2026-09-05. Owner: railiance-platform, RPF-WP-0035-T04.
|
||||||
|
CCR-2026-0015 is active at key version 2. See
|
||||||
|
`state-hub-preflight-activation.md` for the accepted implementation and evidence.
|
||||||
Demand: State Hub message `cd52ba10-de41-46ce-aa8b-9b44050da8f7`,
|
Demand: State Hub message `cd52ba10-de41-46ce-aa8b-9b44050da8f7`,
|
||||||
STATE-WP-0085-T09. Provisioning this lane does not authorize any repository rename.
|
STATE-WP-0085-T09. Provisioning this lane does not authorize any repository rename.
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,79 @@
|
||||||
|
{
|
||||||
|
"schema": "platform.statehub-preflight-activation.v1",
|
||||||
|
"date": "2026-09-05",
|
||||||
|
"task": "RPF-WP-0035-T04",
|
||||||
|
"cluster_uid": "a553c742-0115-43d4-99a4-a5ca56fe0786",
|
||||||
|
"helm_revision": 59,
|
||||||
|
"chart_commit": "49e3182332cd46bd66ea51d77c97a97f65c48001",
|
||||||
|
"image": "main-cdff3b7",
|
||||||
|
"final_kv_version": 2,
|
||||||
|
"repository_rename_performed": false,
|
||||||
|
"receipts": {
|
||||||
|
"provision": {
|
||||||
|
"schema": "platform.statehub-preflight-custody.v1",
|
||||||
|
"status": "custody_verified_pending_eso_and_api_acceptance",
|
||||||
|
"action": "provision",
|
||||||
|
"kv_version": 1,
|
||||||
|
"key_generation": "CSPRNG-32-bytes-CAS",
|
||||||
|
"exact_read_and_scope_denials": true,
|
||||||
|
"wrong_sa": true,
|
||||||
|
"wrong_namespace": true,
|
||||||
|
"wrong_audience": true,
|
||||||
|
"coding_agent_deny_wins": true
|
||||||
|
},
|
||||||
|
"eso_policy_repair": {
|
||||||
|
"schema": "platform.statehub-preflight-custody.v1",
|
||||||
|
"status": "custody_verified_pending_eso_and_api_acceptance",
|
||||||
|
"action": "repair-policy",
|
||||||
|
"exact_read_and_scope_denials": true,
|
||||||
|
"wrong_sa": true,
|
||||||
|
"wrong_namespace": true,
|
||||||
|
"wrong_audience": true,
|
||||||
|
"coding_agent_deny_wins": true
|
||||||
|
},
|
||||||
|
"before_rotation": {
|
||||||
|
"schema": "platform.statehub-preflight-api-acceptance.v1",
|
||||||
|
"status": "passed",
|
||||||
|
"api_only": true,
|
||||||
|
"replicas": 1,
|
||||||
|
"secret_resource_version": "57218196",
|
||||||
|
"results": [
|
||||||
|
{
|
||||||
|
"key_matches": true,
|
||||||
|
"signed_preflight_valid": true,
|
||||||
|
"old_token_rejected": null,
|
||||||
|
"blockers": [],
|
||||||
|
"health": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"rotation": {
|
||||||
|
"schema": "platform.statehub-preflight-custody.v1",
|
||||||
|
"status": "custody_verified_pending_eso_and_api_acceptance",
|
||||||
|
"action": "rotate",
|
||||||
|
"kv_version": 2,
|
||||||
|
"key_generation": "CSPRNG-32-bytes-CAS",
|
||||||
|
"exact_read_and_scope_denials": true,
|
||||||
|
"wrong_sa": true,
|
||||||
|
"wrong_namespace": true,
|
||||||
|
"wrong_audience": true,
|
||||||
|
"coding_agent_deny_wins": true
|
||||||
|
},
|
||||||
|
"after_rotation": {
|
||||||
|
"schema": "platform.statehub-preflight-api-acceptance.v1",
|
||||||
|
"status": "passed",
|
||||||
|
"api_only": true,
|
||||||
|
"replicas": 1,
|
||||||
|
"secret_resource_version": "57239554",
|
||||||
|
"results": [
|
||||||
|
{
|
||||||
|
"key_matches": true,
|
||||||
|
"signed_preflight_valid": true,
|
||||||
|
"old_token_rejected": true,
|
||||||
|
"blockers": [],
|
||||||
|
"health": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
37
history/2026-09-05-preflight-signing-activation-complete.md
Normal file
37
history/2026-09-05-preflight-signing-activation-complete.md
Normal file
|
|
@ -0,0 +1,37 @@
|
||||||
|
# RPF-WP-0035-T04 completed — 2026-09-05
|
||||||
|
|
||||||
|
The user explicitly assigned this session to lead activation. The approved
|
||||||
|
CCR-2026-0015 lane was provisioned through the attended Warden/OpenBao envelope.
|
||||||
|
The dedicated kubeconfig reached the pinned primary cluster. Warden exited
|
||||||
|
successfully after each contained operation and its session cleanup.
|
||||||
|
|
||||||
|
Initial CAS-zero generation produced version 1. Exact path read, wrong service
|
||||||
|
account/namespace/audience, sibling and metadata denial, and coding-agent deny
|
||||||
|
precedence passed. ESO initially failed token lookup-self with 403. Inspection
|
||||||
|
of deployed ESO v0.16.1 source confirmed token lookup-self and revoke-self calls.
|
||||||
|
The policy was narrowly amended to permit these self-token operations; no KV
|
||||||
|
access was broadened. A drift-checked repair passed all custody checks and ESO
|
||||||
|
became Ready.
|
||||||
|
|
||||||
|
State Hub production source commit `49e3182` enabled its reviewed API-only
|
||||||
|
reference. Deployment used a fresh Forge clone of that exact revision, retained
|
||||||
|
the running image `main-cdff3b7` and existing release values, and server dry-run
|
||||||
|
showed only Deployment/state-hub changed. Helm revision 59 deployed successfully.
|
||||||
|
The single API replica matched the delivered key, returned healthy primary
|
||||||
|
identity, and produced a valid signed preflight with zero blockers for the
|
||||||
|
approved flex-auth to access-engine fixture. MCP had no key reference; the
|
||||||
|
shared environment Secret had no competing signing key.
|
||||||
|
|
||||||
|
The API deployment was scaled to zero, every matching pod terminated, and no
|
||||||
|
HPA was present. The guarded attended writer rotated with CAS 1 to version 2.
|
||||||
|
ESO refreshed; the API was restored to one replica. Forward recovery passed:
|
||||||
|
delivered key equality, health, valid new preflight, and predecessor rejection
|
||||||
|
specifically for invalid signature, not expiry. The protected predecessor
|
||||||
|
fixture was removed after verification. No repository rename was executed.
|
||||||
|
|
||||||
|
Evidence: `docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json`.
|
||||||
|
CCR is active and T04 is done; other credential lanes retain their own gates.
|
||||||
|
|
||||||
|
Validation: 183 platform unit tests, 15 State Hub signing/rename API tests,
|
||||||
|
credential request validation and Helm lint passed. Live acceptance receipts
|
||||||
|
provide the operational evidence beyond these source tests.
|
||||||
|
|
@ -98,7 +98,7 @@ The unattended adapter remains a separate demand and gets no operator session.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: RPF-WP-0035-T04
|
id: RPF-WP-0035-T04
|
||||||
status: progress
|
status: done
|
||||||
priority: medium
|
priority: medium
|
||||||
state_hub_task_id: "35a85846-61d5-54ce-8b18-ede45733d53c"
|
state_hub_task_id: "35a85846-61d5-54ce-8b18-ede45733d53c"
|
||||||
```
|
```
|
||||||
|
|
@ -130,3 +130,13 @@ workstation kubeconfig's local port-forward listener was unavailable. Activation
|
||||||
still needs the contained attended OIDC/MFA login and the acceptance evidence
|
still needs the contained attended OIDC/MFA login and the acceptance evidence
|
||||||
above; source preparation is not live completion. See
|
above; source preparation is not live completion. See
|
||||||
`history/2026-09-05-preflight-signing-activation-readiness.md`.
|
`history/2026-09-05-preflight-signing-activation-readiness.md`.
|
||||||
|
|
||||||
|
|
||||||
|
Completed 2026-09-05: user-led attended activation generated version 1 and
|
||||||
|
rotated to version 2 with every API replica stopped. Exact access and negative
|
||||||
|
identity checks passed; ESO delivery and API-only exposure passed; the recovered
|
||||||
|
single API replica accepts new signed preflight and rejects its predecessor by
|
||||||
|
signature, with healthy primary identity and no preflight blockers. State Hub
|
||||||
|
chart commit `49e3182`, Helm revision 59. No repository rename executed.
|
||||||
|
Evidence: `docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json`;
|
||||||
|
closure: `history/2026-09-05-preflight-signing-activation-complete.md`.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue