Close RPF-WP-0029-T02 on operator-attested predecessor unshare.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Record metadata-only invalidation of the personal Nextcloud file-drop.
No predecessor value was captured; age-key taint stays open.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
codex 2026-09-15 02:48:15 +02:00
parent f3668f4f0a
commit 6dfb751e60
4 changed files with 52 additions and 13 deletions

View file

@ -77,7 +77,8 @@ risk:
- Operator credentials remain in KVv2 operators/nextcloud/backup, fields
BACKUP_USERNAME and BACKUP_PASSWORD; never deliver them to production.
- Existing Bernd-owned retained backups and recovery access remain separate;
historical predecessor invalidation and age-key exposure are still open.
predecessor file-drop unshared 2026-09-15 by operator attestation; age-key
exposure remains open.
- "AGE_PRIVATE_KEY decrypts all age-encrypted backup artifacts \u2014 recovery escrow\
\ only."
- Credentials must not be stored on production hosts with delete permission.
@ -134,6 +135,15 @@ verification:
runtime GET and DELETE returned 405 on the actual upload endpoint.
- CAS advanced workload KV version 2 to 3, preserving age escrow and other fields.
- Evidence docs/evidence/RPF-WP-0029-backup-account-2026-09-05.json.
- at: '2026-09-15'
actor: operator
kind: predecessor_share_invalidated
result: passed
details:
- Operator attested unshare of the personal predecessor Nextcloud file-drop.
- No predecessor value, fingerprint, length or shape was recorded.
- HTTP 401/403 probe not run; predecessor must not be reconstructed.
- Evidence docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json.
lifecycle:
deactivate: Disable ops-warden catalog entry and detach OIDC role policy; rotate

View file

@ -0,0 +1,18 @@
{
"schema": "railiance-platform.predecessor-share-invalidation.v1",
"observed_at": "2026-09-15T00:45:00Z",
"workplan_id": "RPF-WP-0029",
"task_id": "RPF-WP-0029-T02",
"ccr_id": "CCR-2026-0004",
"status": "operator_attested_unshare",
"provider": "nextcloud",
"account_class": "personal_predecessor_file_drop",
"replacement_account": "Backup",
"objects_deleted": false,
"http_probe_run": false,
"http_probe_reason": "predecessor credential must not be reconstructed",
"predecessor_value_recorded": false,
"predecessor_fingerprint_recorded": false,
"age_key_taint_cleared": false,
"credential_values_emitted": false
}

View file

@ -1,14 +1,14 @@
# Current platform work
Reviewed 2026-09-06. Seven open workplans: WP-0038 active, six blocked on explicit owner/live
gates; RPF-WP-0036 now has its repository implementation. Completed designs and implementations are
under `archived/`; their IDs and UUIDs are preserved. The number of blocked
plans is not a count of missing implementations or independent incidents.
Reviewed 2026-09-15. Open workplans below; RPF-WP-0029 finished on predecessor
unshare. Completed designs and implementations are under `archived/`; their IDs
and UUIDs are preserved. The number of blocked plans is not a count of missing
implementations or independent incidents.
| Workplan | Purpose and next gate | S3 boundary |
| --- | --- | --- |
| [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. |
| [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup cutover and full offsite application recovery complete; old share invalidation receipt remains | S3 retains custody acceptance; S1 and forge own their backup execution. |
| [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Public Ingress retracted 2026-09-15; private tunnel remains | DNS withdrawal with railiance-infra; rollback phrase still available. |
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |

View file

@ -4,11 +4,11 @@ type: workplan
title: "Remove backup credential default and verify governed replacement"
domain: financials
repo: railiance-platform
status: blocked
status: finished
flavor: implementation
owner: codex
created: "2026-09-05"
updated: "2026-09-06"
updated: "2026-09-15"
state_hub_workstream_id: "bb326ebb-a313-549e-b35f-1bf17e1c58fd"
---
@ -37,7 +37,7 @@ redirects/non-success status. Added transport containment and failure tests.
```task
id: RPF-WP-0029-T02
status: wait
status: done
priority: high
state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8"
```
@ -51,8 +51,8 @@ recovery passed on September 6 (evidence below). Activity-core is
also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical
exposure evidence; upload-token rotation cannot clear recovery-key taint.
T03 proves encrypted fixture transport and decryption; September 6 evidence
also proves full application recovery. Historical predecessor invalidation
remains open.
also proves full application recovery. Operator attested predecessor unshare
on 2026-09-15.
## Portfolio review — 2026-09-05
@ -153,8 +153,19 @@ Replacement recovery PASSED: isolated Forgejo healthy, 142 repositories, six
users, two public Git clones plus fsck, and all 2,040 package blob digests
verified. Disposable resources removed. Evidence:
`docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`.
T02 remains `wait` solely for the Bernd-owned predecessor invalidation/custody
receipt; do not repeat the completed replacement restore as an open gate.
T02 closed 2026-09-15 on operator-attested unshare of the Bernd-owned
predecessor file-drop. No predecessor value, fingerprint, length or shape was
recorded. The 401/403 probe was not run; the predecessor must not be
reconstructed. Replacement recovery remains the 2026-09-06 receipt. Age-key
exposure taint is unchanged. Evidence:
`docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`.
Rejected drill-copy cleanup completed with conditional DELETE 204; attended
session exited 0. Temporary plaintext removed; good encrypted backups retained.
## Closeout — 2026-09-15
T01T03 are done. Live closure of the upload-share predecessor is operator-
attested unshare; replacement recovery was already proven 2026-09-06. The
historical AGE_PRIVATE_KEY exposure remains a separate taint and is not
cleared by this share revocation.