docs(identity): record verified live upstream issuer and completed cleanup
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-08 23:50:55 +02:00
parent a94d06dbcf
commit 8f40d73d0f
3 changed files with 157 additions and 7 deletions

View file

@ -113,13 +113,13 @@ Prerequisites before the window opens:
2. KeyCape image that reads both environment names is **built and pinned, not
deployed**. `main-153258b` is not that image.
3. Founder available for the attended OpenBao session.
4. **The Authelia issuer precondition from KeyCape message
`c8b1ad10-dae8-48fb-a0ea-7e2a101c54bf` is settled first.** The same rollout
that lands these clients also lands upstream ID-token verification that fails
closed on issuer mismatch. Confirm the `iss` value and pin `authelia.issuer`
in the KeyCape config secret before, not during, this window. A broken human
login and a broken client registration arriving together would be very hard to
tell apart.
4. **The actual signed issuer is verified as `https://auth.coulomb.social`.**
The admitted probe passed signature/audience/time/nonce verification on
2026-09-08 at 21:44:44 UTC, exited 0 and removed every temporary resource.
[Receipt](../evidence/2026-09-08-keycape-upstream-issuer-proof.json).
The configuration owner must still ensure `authelia.issuer` is pinned to
that exact value before this window. The probe left normal configuration
unchanged. Keep the existing-human-login regression in the rollout checks.
In-window order:

View file

@ -0,0 +1,133 @@
{
"recorded_at": "2026-09-08T21:50:10.049099+00:00",
"authorization": {
"source": "User response in this session: yes, go on",
"scope": "Prepared ten-minute temporary issuer probe; existing config read in workload, exact-state callback and cleanup",
"custody_activation_authorized": false
},
"source": {
"repo": "key-cape",
"code_commit": "6f33abddcff6cbc348ced862057973cdcc4f78ec",
"published_owner_commit": "7ecc78f4100c04f9b4ea7751240114bcc485de03",
"packet": "docs/upstream-issuer-proof.md",
"image": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4"
},
"proof": {
"audience_verified": true,
"downstream_credential_issued": false,
"issuer": "https://auth.coulomb.social",
"nonce_verified": true,
"observed_at": "2026-09-08T21:44:44Z",
"schema": "keycape.upstream-issuer-proof.v1",
"signature_verified": true,
"status": "verified",
"tokens_retained": false,
"validity_window_verified": true
},
"job": {
"name": "keycape-issuer-proof-532da53dc96a",
"started_at": "2026-09-08T21:43:34.019545+00:00",
"created_resources": [
{
"kind": "Job",
"name": "keycape-issuer-proof-532da53dc96a",
"uid": "4e01daef-9184-4866-ac4d-9d61cd8d79ae"
},
{
"kind": "Service",
"name": "keycape-issuer-proof-532da53dc96a",
"uid": "3359ce09-cbe2-487b-b9d9-a4cc5c484047"
},
{
"kind": "NetworkPolicy",
"name": "keycape-issuer-proof-532da53dc96a",
"uid": "8940e5b4-3665-4395-8a0d-39b4b08ae12d"
},
{
"kind": "NetworkPolicy",
"name": "keycape-issuer-proof-532da53dc96a-authelia",
"uid": "13d72383-0864-4665-af28-eefc76452131"
},
{
"kind": "IngressRoute",
"name": "keycape-issuer-proof-532da53dc96a",
"uid": "7d705d80-f491-408f-a133-0bc4abd2c867"
}
]
},
"pod_evidence": [
{
"name": "keycape-issuer-proof-532da53dc96a-tgpxh",
"uid": "c9230c57-0fad-4dcf-b798-d586385db9a2",
"phase": "Succeeded",
"containers": [
{
"name": "probe",
"image": "sha256:204d8a4b04f47fa93c508b0a74c600e9954cfeab8e4e6566a8feaab327e8f793",
"imageID": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4",
"ready": false,
"state": {
"terminated": {
"exitCode": 0,
"finishedAt": "2026-09-08T21:44:44Z",
"reason": "Completed",
"startedAt": "2026-09-08T21:43:37Z"
}
}
}
]
}
],
"browser": {
"route_head_status": 405,
"launcher_exit": 0,
"url_scope": "exact generated HTTPS issuer-proof start path"
},
"cleanup": {
"completed_at": "2026-09-08T21:45:17.886281+00:00",
"removed": [
{
"kind": "IngressRoute",
"name": "keycape-issuer-proof-532da53dc96a",
"uid_precondition": true
},
{
"kind": "Job",
"name": "keycape-issuer-proof-532da53dc96a",
"uid_precondition": true
},
{
"kind": "Service",
"name": "keycape-issuer-proof-532da53dc96a",
"already_absent": true
},
{
"kind": "NetworkPolicy",
"name": "keycape-issuer-proof-532da53dc96a",
"already_absent": true
},
{
"kind": "NetworkPolicy",
"name": "keycape-issuer-proof-532da53dc96a-authelia",
"already_absent": true
}
],
"all_temporary_resources_absent": true,
"production_metadata_unchanged": true,
"before": {
"production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b",
"deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29",
"secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058"
},
"after": {
"production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b",
"deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29",
"secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058"
}
},
"config_issuer_pinned_by_this_run": false,
"custody_activated": false,
"normal_keycape_deployment_changed": false,
"downstream_mfa_or_application_login_proved": false,
"next_return": "Configuration owner ensures authelia.issuer equals the verified HTTPS issuer; named CCR reviews and attended custody/compatible image rollout remain open"
}

View file

@ -220,3 +220,20 @@ T05 remains wait: both CCRs are still proposed, the actual upstream ID-token
issuer precondition remains open, and no verifier-side credential is provisioned.
Client-side retrieval and audit-sender custody are still separate owner returns.
The capability receipt is not a review approval or service readiness proof.
### 2026-09-08 actual upstream issuer returned
The admitted KeyCape one-shot probe verified the actual signed upstream issuer
as **`https://auth.coulomb.social`** at 21:44:44 UTC. Signature, audience,
validity window and nonce checks passed and the pinned Job exited 0. All
five temporary resources and the Pod were removed; normal KeyCape Deployment
and config Secret metadata are unchanged. See
`docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json`.
T05's unknown-issuer input is resolved. The configuration owner still ensures
`authelia.issuer` equals that exact HTTPS value before the custody window.
Both CCRs remain proposed and await the named reviews; this probe grants no
custody mutation or client-side read. Keep the current authority preflight and
this signed-token proof as separate receipts. Live ESO/client/approval and
separate audit/client-side custody acceptance remain open.