docs(identity): record verified live upstream issuer and completed cleanup
Assistant: codex Assistant-Model: gpt-5.6-luna Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
a94d06dbcf
commit
8f40d73d0f
3 changed files with 157 additions and 7 deletions
|
|
@ -113,13 +113,13 @@ Prerequisites before the window opens:
|
|||
2. KeyCape image that reads both environment names is **built and pinned, not
|
||||
deployed**. `main-153258b` is not that image.
|
||||
3. Founder available for the attended OpenBao session.
|
||||
4. **The Authelia issuer precondition from KeyCape message
|
||||
`c8b1ad10-dae8-48fb-a0ea-7e2a101c54bf` is settled first.** The same rollout
|
||||
that lands these clients also lands upstream ID-token verification that fails
|
||||
closed on issuer mismatch. Confirm the `iss` value and pin `authelia.issuer`
|
||||
in the KeyCape config secret before, not during, this window. A broken human
|
||||
login and a broken client registration arriving together would be very hard to
|
||||
tell apart.
|
||||
4. **The actual signed issuer is verified as `https://auth.coulomb.social`.**
|
||||
The admitted probe passed signature/audience/time/nonce verification on
|
||||
2026-09-08 at 21:44:44 UTC, exited 0 and removed every temporary resource.
|
||||
[Receipt](../evidence/2026-09-08-keycape-upstream-issuer-proof.json).
|
||||
The configuration owner must still ensure `authelia.issuer` is pinned to
|
||||
that exact value before this window. The probe left normal configuration
|
||||
unchanged. Keep the existing-human-login regression in the rollout checks.
|
||||
|
||||
In-window order:
|
||||
|
||||
|
|
|
|||
133
docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json
Normal file
133
docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json
Normal file
|
|
@ -0,0 +1,133 @@
|
|||
{
|
||||
"recorded_at": "2026-09-08T21:50:10.049099+00:00",
|
||||
"authorization": {
|
||||
"source": "User response in this session: yes, go on",
|
||||
"scope": "Prepared ten-minute temporary issuer probe; existing config read in workload, exact-state callback and cleanup",
|
||||
"custody_activation_authorized": false
|
||||
},
|
||||
"source": {
|
||||
"repo": "key-cape",
|
||||
"code_commit": "6f33abddcff6cbc348ced862057973cdcc4f78ec",
|
||||
"published_owner_commit": "7ecc78f4100c04f9b4ea7751240114bcc485de03",
|
||||
"packet": "docs/upstream-issuer-proof.md",
|
||||
"image": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4"
|
||||
},
|
||||
"proof": {
|
||||
"audience_verified": true,
|
||||
"downstream_credential_issued": false,
|
||||
"issuer": "https://auth.coulomb.social",
|
||||
"nonce_verified": true,
|
||||
"observed_at": "2026-09-08T21:44:44Z",
|
||||
"schema": "keycape.upstream-issuer-proof.v1",
|
||||
"signature_verified": true,
|
||||
"status": "verified",
|
||||
"tokens_retained": false,
|
||||
"validity_window_verified": true
|
||||
},
|
||||
"job": {
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"started_at": "2026-09-08T21:43:34.019545+00:00",
|
||||
"created_resources": [
|
||||
{
|
||||
"kind": "Job",
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"uid": "4e01daef-9184-4866-ac4d-9d61cd8d79ae"
|
||||
},
|
||||
{
|
||||
"kind": "Service",
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"uid": "3359ce09-cbe2-487b-b9d9-a4cc5c484047"
|
||||
},
|
||||
{
|
||||
"kind": "NetworkPolicy",
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"uid": "8940e5b4-3665-4395-8a0d-39b4b08ae12d"
|
||||
},
|
||||
{
|
||||
"kind": "NetworkPolicy",
|
||||
"name": "keycape-issuer-proof-532da53dc96a-authelia",
|
||||
"uid": "13d72383-0864-4665-af28-eefc76452131"
|
||||
},
|
||||
{
|
||||
"kind": "IngressRoute",
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"uid": "7d705d80-f491-408f-a133-0bc4abd2c867"
|
||||
}
|
||||
]
|
||||
},
|
||||
"pod_evidence": [
|
||||
{
|
||||
"name": "keycape-issuer-proof-532da53dc96a-tgpxh",
|
||||
"uid": "c9230c57-0fad-4dcf-b798-d586385db9a2",
|
||||
"phase": "Succeeded",
|
||||
"containers": [
|
||||
{
|
||||
"name": "probe",
|
||||
"image": "sha256:204d8a4b04f47fa93c508b0a74c600e9954cfeab8e4e6566a8feaab327e8f793",
|
||||
"imageID": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4",
|
||||
"ready": false,
|
||||
"state": {
|
||||
"terminated": {
|
||||
"exitCode": 0,
|
||||
"finishedAt": "2026-09-08T21:44:44Z",
|
||||
"reason": "Completed",
|
||||
"startedAt": "2026-09-08T21:43:37Z"
|
||||
}
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"browser": {
|
||||
"route_head_status": 405,
|
||||
"launcher_exit": 0,
|
||||
"url_scope": "exact generated HTTPS issuer-proof start path"
|
||||
},
|
||||
"cleanup": {
|
||||
"completed_at": "2026-09-08T21:45:17.886281+00:00",
|
||||
"removed": [
|
||||
{
|
||||
"kind": "IngressRoute",
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"uid_precondition": true
|
||||
},
|
||||
{
|
||||
"kind": "Job",
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"uid_precondition": true
|
||||
},
|
||||
{
|
||||
"kind": "Service",
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"already_absent": true
|
||||
},
|
||||
{
|
||||
"kind": "NetworkPolicy",
|
||||
"name": "keycape-issuer-proof-532da53dc96a",
|
||||
"already_absent": true
|
||||
},
|
||||
{
|
||||
"kind": "NetworkPolicy",
|
||||
"name": "keycape-issuer-proof-532da53dc96a-authelia",
|
||||
"already_absent": true
|
||||
}
|
||||
],
|
||||
"all_temporary_resources_absent": true,
|
||||
"production_metadata_unchanged": true,
|
||||
"before": {
|
||||
"production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b",
|
||||
"deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29",
|
||||
"secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058"
|
||||
},
|
||||
"after": {
|
||||
"production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b",
|
||||
"deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29",
|
||||
"secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058"
|
||||
}
|
||||
},
|
||||
"config_issuer_pinned_by_this_run": false,
|
||||
"custody_activated": false,
|
||||
"normal_keycape_deployment_changed": false,
|
||||
"downstream_mfa_or_application_login_proved": false,
|
||||
"next_return": "Configuration owner ensures authelia.issuer equals the verified HTTPS issuer; named CCR reviews and attended custody/compatible image rollout remain open"
|
||||
}
|
||||
|
|
@ -220,3 +220,20 @@ T05 remains wait: both CCRs are still proposed, the actual upstream ID-token
|
|||
issuer precondition remains open, and no verifier-side credential is provisioned.
|
||||
Client-side retrieval and audit-sender custody are still separate owner returns.
|
||||
The capability receipt is not a review approval or service readiness proof.
|
||||
|
||||
|
||||
### 2026-09-08 actual upstream issuer returned
|
||||
|
||||
The admitted KeyCape one-shot probe verified the actual signed upstream issuer
|
||||
as **`https://auth.coulomb.social`** at 21:44:44 UTC. Signature, audience,
|
||||
validity window and nonce checks passed and the pinned Job exited 0. All
|
||||
five temporary resources and the Pod were removed; normal KeyCape Deployment
|
||||
and config Secret metadata are unchanged. See
|
||||
`docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json`.
|
||||
|
||||
T05's unknown-issuer input is resolved. The configuration owner still ensures
|
||||
`authelia.issuer` equals that exact HTTPS value before the custody window.
|
||||
Both CCRs remain proposed and await the named reviews; this probe grants no
|
||||
custody mutation or client-side read. Keep the current authority preflight and
|
||||
this signed-token proof as separate receipts. Live ESO/client/approval and
|
||||
separate audit/client-side custody acceptance remain open.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue