Close RPF-WP-0029-T02 on operator-attested predecessor unshare.
Record metadata-only invalidation of the personal Nextcloud file-drop. No predecessor value was captured; age-key taint stays open. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
parent
f3668f4f0a
commit
6dfb751e60
4 changed files with 52 additions and 13 deletions
|
|
@ -77,7 +77,8 @@ risk:
|
|||
- Operator credentials remain in KVv2 operators/nextcloud/backup, fields
|
||||
BACKUP_USERNAME and BACKUP_PASSWORD; never deliver them to production.
|
||||
- Existing Bernd-owned retained backups and recovery access remain separate;
|
||||
historical predecessor invalidation and age-key exposure are still open.
|
||||
predecessor file-drop unshared 2026-09-15 by operator attestation; age-key
|
||||
exposure remains open.
|
||||
- "AGE_PRIVATE_KEY decrypts all age-encrypted backup artifacts \u2014 recovery escrow\
|
||||
\ only."
|
||||
- Credentials must not be stored on production hosts with delete permission.
|
||||
|
|
@ -134,6 +135,15 @@ verification:
|
|||
runtime GET and DELETE returned 405 on the actual upload endpoint.
|
||||
- CAS advanced workload KV version 2 to 3, preserving age escrow and other fields.
|
||||
- Evidence docs/evidence/RPF-WP-0029-backup-account-2026-09-05.json.
|
||||
- at: '2026-09-15'
|
||||
actor: operator
|
||||
kind: predecessor_share_invalidated
|
||||
result: passed
|
||||
details:
|
||||
- Operator attested unshare of the personal predecessor Nextcloud file-drop.
|
||||
- No predecessor value, fingerprint, length or shape was recorded.
|
||||
- HTTP 401/403 probe not run; predecessor must not be reconstructed.
|
||||
- Evidence docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json.
|
||||
|
||||
lifecycle:
|
||||
deactivate: Disable ops-warden catalog entry and detach OIDC role policy; rotate
|
||||
|
|
|
|||
|
|
@ -0,0 +1,18 @@
|
|||
{
|
||||
"schema": "railiance-platform.predecessor-share-invalidation.v1",
|
||||
"observed_at": "2026-09-15T00:45:00Z",
|
||||
"workplan_id": "RPF-WP-0029",
|
||||
"task_id": "RPF-WP-0029-T02",
|
||||
"ccr_id": "CCR-2026-0004",
|
||||
"status": "operator_attested_unshare",
|
||||
"provider": "nextcloud",
|
||||
"account_class": "personal_predecessor_file_drop",
|
||||
"replacement_account": "Backup",
|
||||
"objects_deleted": false,
|
||||
"http_probe_run": false,
|
||||
"http_probe_reason": "predecessor credential must not be reconstructed",
|
||||
"predecessor_value_recorded": false,
|
||||
"predecessor_fingerprint_recorded": false,
|
||||
"age_key_taint_cleared": false,
|
||||
"credential_values_emitted": false
|
||||
}
|
||||
|
|
@ -1,14 +1,14 @@
|
|||
# Current platform work
|
||||
|
||||
Reviewed 2026-09-06. Seven open workplans: WP-0038 active, six blocked on explicit owner/live
|
||||
gates; RPF-WP-0036 now has its repository implementation. Completed designs and implementations are
|
||||
under `archived/`; their IDs and UUIDs are preserved. The number of blocked
|
||||
plans is not a count of missing implementations or independent incidents.
|
||||
Reviewed 2026-09-15. Open workplans below; RPF-WP-0029 finished on predecessor
|
||||
unshare. Completed designs and implementations are under `archived/`; their IDs
|
||||
and UUIDs are preserved. The number of blocked plans is not a count of missing
|
||||
implementations or independent incidents.
|
||||
|
||||
| Workplan | Purpose and next gate | S3 boundary |
|
||||
| --- | --- | --- |
|
||||
| [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. |
|
||||
| [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup cutover and full offsite application recovery complete; old share invalidation receipt remains | S3 retains custody acceptance; S1 and forge own their backup execution. |
|
||||
|
||||
| [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Public Ingress retracted 2026-09-15; private tunnel remains | DNS withdrawal with railiance-infra; rollback phrase still available. |
|
||||
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
|
||||
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |
|
||||
|
|
|
|||
|
|
@ -4,11 +4,11 @@ type: workplan
|
|||
title: "Remove backup credential default and verify governed replacement"
|
||||
domain: financials
|
||||
repo: railiance-platform
|
||||
status: blocked
|
||||
status: finished
|
||||
flavor: implementation
|
||||
owner: codex
|
||||
created: "2026-09-05"
|
||||
updated: "2026-09-06"
|
||||
updated: "2026-09-15"
|
||||
state_hub_workstream_id: "bb326ebb-a313-549e-b35f-1bf17e1c58fd"
|
||||
---
|
||||
|
||||
|
|
@ -37,7 +37,7 @@ redirects/non-success status. Added transport containment and failure tests.
|
|||
|
||||
```task
|
||||
id: RPF-WP-0029-T02
|
||||
status: wait
|
||||
status: done
|
||||
priority: high
|
||||
state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8"
|
||||
```
|
||||
|
|
@ -51,8 +51,8 @@ recovery passed on September 6 (evidence below). Activity-core is
|
|||
also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical
|
||||
exposure evidence; upload-token rotation cannot clear recovery-key taint.
|
||||
T03 proves encrypted fixture transport and decryption; September 6 evidence
|
||||
also proves full application recovery. Historical predecessor invalidation
|
||||
remains open.
|
||||
also proves full application recovery. Operator attested predecessor unshare
|
||||
on 2026-09-15.
|
||||
|
||||
## Portfolio review — 2026-09-05
|
||||
|
||||
|
|
@ -153,8 +153,19 @@ Replacement recovery PASSED: isolated Forgejo healthy, 142 repositories, six
|
|||
users, two public Git clones plus fsck, and all 2,040 package blob digests
|
||||
verified. Disposable resources removed. Evidence:
|
||||
`docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`.
|
||||
T02 remains `wait` solely for the Bernd-owned predecessor invalidation/custody
|
||||
receipt; do not repeat the completed replacement restore as an open gate.
|
||||
T02 closed 2026-09-15 on operator-attested unshare of the Bernd-owned
|
||||
predecessor file-drop. No predecessor value, fingerprint, length or shape was
|
||||
recorded. The 401/403 probe was not run; the predecessor must not be
|
||||
reconstructed. Replacement recovery remains the 2026-09-06 receipt. Age-key
|
||||
exposure taint is unchanged. Evidence:
|
||||
`docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`.
|
||||
|
||||
Rejected drill-copy cleanup completed with conditional DELETE 204; attended
|
||||
session exited 0. Temporary plaintext removed; good encrypted backups retained.
|
||||
|
||||
## Closeout — 2026-09-15
|
||||
|
||||
T01–T03 are done. Live closure of the upload-share predecessor is operator-
|
||||
attested unshare; replacement recovery was already proven 2026-09-06. The
|
||||
historical AGE_PRIVATE_KEY exposure remains a separate taint and is not
|
||||
cleared by this share revocation.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue