Close RPF-WP-0029-T02 on operator-attested predecessor unshare.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Record metadata-only invalidation of the personal Nextcloud file-drop.
No predecessor value was captured; age-key taint stays open.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
codex 2026-09-15 02:48:15 +02:00
parent f3668f4f0a
commit 6dfb751e60
4 changed files with 52 additions and 13 deletions

View file

@ -77,7 +77,8 @@ risk:
- Operator credentials remain in KVv2 operators/nextcloud/backup, fields
BACKUP_USERNAME and BACKUP_PASSWORD; never deliver them to production.
- Existing Bernd-owned retained backups and recovery access remain separate;
historical predecessor invalidation and age-key exposure are still open.
predecessor file-drop unshared 2026-09-15 by operator attestation; age-key
exposure remains open.
- "AGE_PRIVATE_KEY decrypts all age-encrypted backup artifacts \u2014 recovery escrow\
\ only."
- Credentials must not be stored on production hosts with delete permission.
@ -134,6 +135,15 @@ verification:
runtime GET and DELETE returned 405 on the actual upload endpoint.
- CAS advanced workload KV version 2 to 3, preserving age escrow and other fields.
- Evidence docs/evidence/RPF-WP-0029-backup-account-2026-09-05.json.
- at: '2026-09-15'
actor: operator
kind: predecessor_share_invalidated
result: passed
details:
- Operator attested unshare of the personal predecessor Nextcloud file-drop.
- No predecessor value, fingerprint, length or shape was recorded.
- HTTP 401/403 probe not run; predecessor must not be reconstructed.
- Evidence docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json.
lifecycle:
deactivate: Disable ops-warden catalog entry and detach OIDC role policy; rotate