Close RPF-WP-0029-T02 on operator-attested predecessor unshare.
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Record metadata-only invalidation of the personal Nextcloud file-drop.
No predecessor value was captured; age-key taint stays open.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
codex 2026-09-15 02:48:15 +02:00
parent f3668f4f0a
commit 6dfb751e60
4 changed files with 52 additions and 13 deletions

View file

@ -77,7 +77,8 @@ risk:
- Operator credentials remain in KVv2 operators/nextcloud/backup, fields - Operator credentials remain in KVv2 operators/nextcloud/backup, fields
BACKUP_USERNAME and BACKUP_PASSWORD; never deliver them to production. BACKUP_USERNAME and BACKUP_PASSWORD; never deliver them to production.
- Existing Bernd-owned retained backups and recovery access remain separate; - Existing Bernd-owned retained backups and recovery access remain separate;
historical predecessor invalidation and age-key exposure are still open. predecessor file-drop unshared 2026-09-15 by operator attestation; age-key
exposure remains open.
- "AGE_PRIVATE_KEY decrypts all age-encrypted backup artifacts \u2014 recovery escrow\ - "AGE_PRIVATE_KEY decrypts all age-encrypted backup artifacts \u2014 recovery escrow\
\ only." \ only."
- Credentials must not be stored on production hosts with delete permission. - Credentials must not be stored on production hosts with delete permission.
@ -134,6 +135,15 @@ verification:
runtime GET and DELETE returned 405 on the actual upload endpoint. runtime GET and DELETE returned 405 on the actual upload endpoint.
- CAS advanced workload KV version 2 to 3, preserving age escrow and other fields. - CAS advanced workload KV version 2 to 3, preserving age escrow and other fields.
- Evidence docs/evidence/RPF-WP-0029-backup-account-2026-09-05.json. - Evidence docs/evidence/RPF-WP-0029-backup-account-2026-09-05.json.
- at: '2026-09-15'
actor: operator
kind: predecessor_share_invalidated
result: passed
details:
- Operator attested unshare of the personal predecessor Nextcloud file-drop.
- No predecessor value, fingerprint, length or shape was recorded.
- HTTP 401/403 probe not run; predecessor must not be reconstructed.
- Evidence docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json.
lifecycle: lifecycle:
deactivate: Disable ops-warden catalog entry and detach OIDC role policy; rotate deactivate: Disable ops-warden catalog entry and detach OIDC role policy; rotate

View file

@ -0,0 +1,18 @@
{
"schema": "railiance-platform.predecessor-share-invalidation.v1",
"observed_at": "2026-09-15T00:45:00Z",
"workplan_id": "RPF-WP-0029",
"task_id": "RPF-WP-0029-T02",
"ccr_id": "CCR-2026-0004",
"status": "operator_attested_unshare",
"provider": "nextcloud",
"account_class": "personal_predecessor_file_drop",
"replacement_account": "Backup",
"objects_deleted": false,
"http_probe_run": false,
"http_probe_reason": "predecessor credential must not be reconstructed",
"predecessor_value_recorded": false,
"predecessor_fingerprint_recorded": false,
"age_key_taint_cleared": false,
"credential_values_emitted": false
}

View file

@ -1,14 +1,14 @@
# Current platform work # Current platform work
Reviewed 2026-09-06. Seven open workplans: WP-0038 active, six blocked on explicit owner/live Reviewed 2026-09-15. Open workplans below; RPF-WP-0029 finished on predecessor
gates; RPF-WP-0036 now has its repository implementation. Completed designs and implementations are unshare. Completed designs and implementations are under `archived/`; their IDs
under `archived/`; their IDs and UUIDs are preserved. The number of blocked and UUIDs are preserved. The number of blocked plans is not a count of missing
plans is not a count of missing implementations or independent incidents. implementations or independent incidents.
| Workplan | Purpose and next gate | S3 boundary | | Workplan | Purpose and next gate | S3 boundary |
| --- | --- | --- | | --- | --- | --- |
| [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. | | [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. |
| [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup cutover and full offsite application recovery complete; old share invalidation receipt remains | S3 retains custody acceptance; S1 and forge own their backup execution. |
| [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Public Ingress retracted 2026-09-15; private tunnel remains | DNS withdrawal with railiance-infra; rollback phrase still available. | | [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Public Ingress retracted 2026-09-15; private tunnel remains | DNS withdrawal with railiance-infra; rollback phrase still available. |
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. | | [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. | | [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |

View file

@ -4,11 +4,11 @@ type: workplan
title: "Remove backup credential default and verify governed replacement" title: "Remove backup credential default and verify governed replacement"
domain: financials domain: financials
repo: railiance-platform repo: railiance-platform
status: blocked status: finished
flavor: implementation flavor: implementation
owner: codex owner: codex
created: "2026-09-05" created: "2026-09-05"
updated: "2026-09-06" updated: "2026-09-15"
state_hub_workstream_id: "bb326ebb-a313-549e-b35f-1bf17e1c58fd" state_hub_workstream_id: "bb326ebb-a313-549e-b35f-1bf17e1c58fd"
--- ---
@ -37,7 +37,7 @@ redirects/non-success status. Added transport containment and failure tests.
```task ```task
id: RPF-WP-0029-T02 id: RPF-WP-0029-T02
status: wait status: done
priority: high priority: high
state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8" state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8"
``` ```
@ -51,8 +51,8 @@ recovery passed on September 6 (evidence below). Activity-core is
also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical
exposure evidence; upload-token rotation cannot clear recovery-key taint. exposure evidence; upload-token rotation cannot clear recovery-key taint.
T03 proves encrypted fixture transport and decryption; September 6 evidence T03 proves encrypted fixture transport and decryption; September 6 evidence
also proves full application recovery. Historical predecessor invalidation also proves full application recovery. Operator attested predecessor unshare
remains open. on 2026-09-15.
## Portfolio review — 2026-09-05 ## Portfolio review — 2026-09-05
@ -153,8 +153,19 @@ Replacement recovery PASSED: isolated Forgejo healthy, 142 repositories, six
users, two public Git clones plus fsck, and all 2,040 package blob digests users, two public Git clones plus fsck, and all 2,040 package blob digests
verified. Disposable resources removed. Evidence: verified. Disposable resources removed. Evidence:
`docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`. `docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`.
T02 remains `wait` solely for the Bernd-owned predecessor invalidation/custody T02 closed 2026-09-15 on operator-attested unshare of the Bernd-owned
receipt; do not repeat the completed replacement restore as an open gate. predecessor file-drop. No predecessor value, fingerprint, length or shape was
recorded. The 401/403 probe was not run; the predecessor must not be
reconstructed. Replacement recovery remains the 2026-09-06 receipt. Age-key
exposure taint is unchanged. Evidence:
`docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`.
Rejected drill-copy cleanup completed with conditional DELETE 204; attended Rejected drill-copy cleanup completed with conditional DELETE 204; attended
session exited 0. Temporary plaintext removed; good encrypted backups retained. session exited 0. Temporary plaintext removed; good encrypted backups retained.
## Closeout — 2026-09-15
T01T03 are done. Live closure of the upload-share predecessor is operator-
attested unshare; replacement recovery was already proven 2026-09-06. The
historical AGE_PRIVATE_KEY exposure remains a separate taint and is not
cleared by this share revocation.