From 6dfb751e600985f3d3071bf5f5a5d62b7292e14f Mon Sep 17 00:00:00 2001 From: codex Date: Tue, 15 Sep 2026 02:48:15 +0200 Subject: [PATCH] Close RPF-WP-0029-T02 on operator-attested predecessor unshare. Record metadata-only invalidation of the personal Nextcloud file-drop. No predecessor value was captured; age-key taint stays open. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a --- ...26-0004-railiance-backup-offsite-lane.yaml | 12 ++++++++- ...wp-0029-predecessor-share-invalidated.json | 18 +++++++++++++ workplans/README.md | 10 ++++---- ...-0029-backup-credential-default-removal.md | 25 +++++++++++++------ 4 files changed, 52 insertions(+), 13 deletions(-) create mode 100644 docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json diff --git a/credential-change-requests/CCR-2026-0004-railiance-backup-offsite-lane.yaml b/credential-change-requests/CCR-2026-0004-railiance-backup-offsite-lane.yaml index 5bca033..69ca933 100644 --- a/credential-change-requests/CCR-2026-0004-railiance-backup-offsite-lane.yaml +++ b/credential-change-requests/CCR-2026-0004-railiance-backup-offsite-lane.yaml @@ -77,7 +77,8 @@ risk: - Operator credentials remain in KVv2 operators/nextcloud/backup, fields BACKUP_USERNAME and BACKUP_PASSWORD; never deliver them to production. - Existing Bernd-owned retained backups and recovery access remain separate; - historical predecessor invalidation and age-key exposure are still open. + predecessor file-drop unshared 2026-09-15 by operator attestation; age-key + exposure remains open. - "AGE_PRIVATE_KEY decrypts all age-encrypted backup artifacts \u2014 recovery escrow\ \ only." - Credentials must not be stored on production hosts with delete permission. @@ -134,6 +135,15 @@ verification: runtime GET and DELETE returned 405 on the actual upload endpoint. - CAS advanced workload KV version 2 to 3, preserving age escrow and other fields. - Evidence docs/evidence/RPF-WP-0029-backup-account-2026-09-05.json. + - at: '2026-09-15' + actor: operator + kind: predecessor_share_invalidated + result: passed + details: + - Operator attested unshare of the personal predecessor Nextcloud file-drop. + - No predecessor value, fingerprint, length or shape was recorded. + - HTTP 401/403 probe not run; predecessor must not be reconstructed. + - Evidence docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json. lifecycle: deactivate: Disable ops-warden catalog entry and detach OIDC role policy; rotate diff --git a/docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json b/docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json new file mode 100644 index 0000000..d211553 --- /dev/null +++ b/docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json @@ -0,0 +1,18 @@ +{ + "schema": "railiance-platform.predecessor-share-invalidation.v1", + "observed_at": "2026-09-15T00:45:00Z", + "workplan_id": "RPF-WP-0029", + "task_id": "RPF-WP-0029-T02", + "ccr_id": "CCR-2026-0004", + "status": "operator_attested_unshare", + "provider": "nextcloud", + "account_class": "personal_predecessor_file_drop", + "replacement_account": "Backup", + "objects_deleted": false, + "http_probe_run": false, + "http_probe_reason": "predecessor credential must not be reconstructed", + "predecessor_value_recorded": false, + "predecessor_fingerprint_recorded": false, + "age_key_taint_cleared": false, + "credential_values_emitted": false +} diff --git a/workplans/README.md b/workplans/README.md index 5737a07..e223bce 100644 --- a/workplans/README.md +++ b/workplans/README.md @@ -1,14 +1,14 @@ # Current platform work -Reviewed 2026-09-06. Seven open workplans: WP-0038 active, six blocked on explicit owner/live -gates; RPF-WP-0036 now has its repository implementation. Completed designs and implementations are -under `archived/`; their IDs and UUIDs are preserved. The number of blocked -plans is not a count of missing implementations or independent incidents. +Reviewed 2026-09-15. Open workplans below; RPF-WP-0029 finished on predecessor +unshare. Completed designs and implementations are under `archived/`; their IDs +and UUIDs are preserved. The number of blocked plans is not a count of missing +implementations or independent incidents. | Workplan | Purpose and next gate | S3 boundary | | --- | --- | --- | | [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. | -| [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup cutover and full offsite application recovery complete; old share invalidation receipt remains | S3 retains custody acceptance; S1 and forge own their backup execution. | + | [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Public Ingress retracted 2026-09-15; private tunnel remains | DNS withdrawal with railiance-infra; rollback phrase still available. | | [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. | | [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. | diff --git a/workplans/RPF-WP-0029-backup-credential-default-removal.md b/workplans/RPF-WP-0029-backup-credential-default-removal.md index e5e4d6d..76bca92 100644 --- a/workplans/RPF-WP-0029-backup-credential-default-removal.md +++ b/workplans/RPF-WP-0029-backup-credential-default-removal.md @@ -4,11 +4,11 @@ type: workplan title: "Remove backup credential default and verify governed replacement" domain: financials repo: railiance-platform -status: blocked +status: finished flavor: implementation owner: codex created: "2026-09-05" -updated: "2026-09-06" +updated: "2026-09-15" state_hub_workstream_id: "bb326ebb-a313-549e-b35f-1bf17e1c58fd" --- @@ -37,7 +37,7 @@ redirects/non-success status. Added transport containment and failure tests. ```task id: RPF-WP-0029-T02 -status: wait +status: done priority: high state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8" ``` @@ -51,8 +51,8 @@ recovery passed on September 6 (evidence below). Activity-core is also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical exposure evidence; upload-token rotation cannot clear recovery-key taint. T03 proves encrypted fixture transport and decryption; September 6 evidence -also proves full application recovery. Historical predecessor invalidation -remains open. +also proves full application recovery. Operator attested predecessor unshare +on 2026-09-15. ## Portfolio review — 2026-09-05 @@ -153,8 +153,19 @@ Replacement recovery PASSED: isolated Forgejo healthy, 142 repositories, six users, two public Git clones plus fsck, and all 2,040 package blob digests verified. Disposable resources removed. Evidence: `docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`. -T02 remains `wait` solely for the Bernd-owned predecessor invalidation/custody -receipt; do not repeat the completed replacement restore as an open gate. +T02 closed 2026-09-15 on operator-attested unshare of the Bernd-owned +predecessor file-drop. No predecessor value, fingerprint, length or shape was +recorded. The 401/403 probe was not run; the predecessor must not be +reconstructed. Replacement recovery remains the 2026-09-06 receipt. Age-key +exposure taint is unchanged. Evidence: +`docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`. Rejected drill-copy cleanup completed with conditional DELETE 204; attended session exited 0. Temporary plaintext removed; good encrypted backups retained. + +## Closeout — 2026-09-15 + +T01–T03 are done. Live closure of the upload-share predecessor is operator- +attested unshare; replacement recovery was already proven 2026-09-06. The +historical AGE_PRIVATE_KEY exposure remains a separate taint and is not +cleared by this share revocation.