diff --git a/docs/evidence/2026-09-13-keycape-factor-custody.md b/docs/evidence/2026-09-13-keycape-factor-custody.md index 7a7b52c..158fc96 100644 --- a/docs/evidence/2026-09-13-keycape-factor-custody.md +++ b/docs/evidence/2026-09-13-keycape-factor-custody.md @@ -53,3 +53,17 @@ were true: wrong-SA rejection, issuer-password denial, sibling-secret denial, mounted-token/custody equality, KeyCape per-user lookup, provider administration denial, renewed projection acceptance, and explicit reader-session revocation. KeyCape remained Ready 1/1 at deployment generation 46. CCR validation passed. + + +## P05 acceptance closure — 2026-09-13 + +RPF-WP-0040-T04 is complete. Actual installed-provider isolated fixture +`provider-p05-contract-01` verifies expiry, fresh-session recovery, expired +predecessor denial and policy permission withdrawal/recovery. Native proof +`keycape-factor-proof-91ea82cd` repeated all eight checks successfully, including +mounted rotation after renewal Job `keycape-factor-rotate-91ea82cd` and explicit +proof-session revocation. CronJob retains failed Jobs (limit 3), and ESO reports +Ready/SecretSynced. Provider and credential failure/recovery are covered by +KeyCape's Go adapter suite. See user-engine's P05 evidence for exact boundaries. +The preceding "remaining T04" statements are historical and superseded here. +Existing NK-WP-0033 and KEY-WP-0035 retain resolver/policy residual ownership. diff --git a/workplans/RPF-WP-0040-keycape-factor-credential-custody.md b/workplans/RPF-WP-0040-keycape-factor-credential-custody.md index e05104f..2d43a6a 100644 --- a/workplans/RPF-WP-0040-keycape-factor-credential-custody.md +++ b/workplans/RPF-WP-0040-keycape-factor-credential-custody.md @@ -4,7 +4,7 @@ type: workplan title: "Establish KeyCape factor credential custody and renewal" domain: financials repo: railiance-platform -status: active +status: finished owner: codex topic_slug: financials created: "2026-09-13" @@ -56,7 +56,7 @@ rolled out Ready 1/1 without changing MFA policy or signing/client secrets. ```task id: RPF-WP-0040-T04 -status: todo +status: done priority: high state_hub_task_id: "c7803984-e96d-5503-9214-6dc2a1a84fbe" ``` @@ -67,3 +67,21 @@ Verify rejected predecessor handling independently of OpenBao token revocation. Include provider interruption/retry evidence and maintain visible failed-Job / ExternalSecret failure signals. This is remaining acceptance, not another owner handoff. Historical resolver incident NK-WP-0033 remains separately open. + + +2026-09-13 T04 completed: KeyCape installed-provider isolated Job +`provider-p05-contract-01` passed genuine provider JWT expiry, fresh-session +recovery, continued expired-predecessor denial and actual permission withdrawal / +recovery. Existing Go tests cover provider interruption, missing credential and +mounted replacement recovery with no stale fallback. Native proof +`keycape-factor-proof-91ea82cd` passed all eight scope/rotation/revocation checks; +renewal `keycape-factor-rotate-91ea82cd` succeeded. CronJob retains three failed +Jobs; ExternalSecret reports Ready/SecretSynced. Full receipts and test boundaries +are recorded in user-engine/docs/evidence/2026-09-13-p05-service-operations.md. + +Residual ownership: historical resolver incident remains the existing live +NK-WP-0033; client policy/optional onboarding is live KEY-WP-0035 and +USER-WP-0030-T03/P06. No residual is parked only in this completion note. Renewal +is not predecessor revocation: the fixture independently proves expired JWTs +stay denied after a new session is issued. Production credentials/factors were +not deliberately revoked to simulate outage.