From 8ae77ca006d3a91f527a6c0ab5c93a5c2fb405f2 Mon Sep 17 00:00:00 2001 From: codex Date: Sun, 23 Aug 2026 13:23:35 +0200 Subject: [PATCH] Record KeyCape loopback callback evidence Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093 --- ...LIANCE-WP-0027-openbao-operator-only-access.md | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/workplans/RAILIANCE-WP-0027-openbao-operator-only-access.md b/workplans/RAILIANCE-WP-0027-openbao-operator-only-access.md index e4d0ce1..7e44267 100644 --- a/workplans/RAILIANCE-WP-0027-openbao-operator-only-access.md +++ b/workplans/RAILIANCE-WP-0027-openbao-operator-only-access.md @@ -59,12 +59,15 @@ priority: high state_hub_task_id: "99f8b41f-e9db-579d-a6fb-b71337048afc" ``` -Blocked on two facts: KeyCape and the OpenBao role must accept the exact -loopback callback, and an attended MFA login must pass. The host-namespace -preflight already proves `openbao-ui-railiance01` lifecycle-healthy and reaches -the expected overlay. Then execute the guarded retraction, coordinate public -DNS withdrawal with railiance-infra, and return non-secret acceptance evidence -to Railiance Master. +KeyCape revision `d150be1` now admits exactly +`http://127.0.0.1:18200/ui/vault/auth/netkingdom/oidc/callback` in the +source-owned `openbao-admin` client and pins it in configuration tests. The +OpenBao `auth/netkingdom/role/platform-admin` role must still independently +admit that exact callback, and an attended MFA login must pass. The +host-namespace preflight already proves `openbao-ui-railiance01` +lifecycle-healthy and reaches the expected overlay. Then execute the guarded +retraction, coordinate public DNS withdrawal with railiance-infra, and return +non-secret acceptance evidence to Railiance Master. This workplan authorizes no OpenBao seal/unseal, policy broadening, PVC or Secret mutation, reboot, restore, or RMASTER-WP-0020-T08 cleanup.