From 8f40d73d0f8cde62fca29218e533d9de2005506f Mon Sep 17 00:00:00 2001 From: tegwick Date: Tue, 8 Sep 2026 23:50:55 +0200 Subject: [PATCH] docs(identity): record verified live upstream issuer and completed cleanup Assistant: codex Assistant-Model: gpt-5.6-luna Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc --- .../keycape-approval-clients.md | 14 +- ...6-09-08-keycape-upstream-issuer-proof.json | 133 ++++++++++++++++++ ...-WP-0035-credential-lane-implementation.md | 17 +++ 3 files changed, 157 insertions(+), 7 deletions(-) create mode 100644 docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json diff --git a/docs/credential-lane-designs/keycape-approval-clients.md b/docs/credential-lane-designs/keycape-approval-clients.md index 0a6ed43..75f94e0 100644 --- a/docs/credential-lane-designs/keycape-approval-clients.md +++ b/docs/credential-lane-designs/keycape-approval-clients.md @@ -113,13 +113,13 @@ Prerequisites before the window opens: 2. KeyCape image that reads both environment names is **built and pinned, not deployed**. `main-153258b` is not that image. 3. Founder available for the attended OpenBao session. -4. **The Authelia issuer precondition from KeyCape message - `c8b1ad10-dae8-48fb-a0ea-7e2a101c54bf` is settled first.** The same rollout - that lands these clients also lands upstream ID-token verification that fails - closed on issuer mismatch. Confirm the `iss` value and pin `authelia.issuer` - in the KeyCape config secret before, not during, this window. A broken human - login and a broken client registration arriving together would be very hard to - tell apart. +4. **The actual signed issuer is verified as `https://auth.coulomb.social`.** + The admitted probe passed signature/audience/time/nonce verification on + 2026-09-08 at 21:44:44 UTC, exited 0 and removed every temporary resource. + [Receipt](../evidence/2026-09-08-keycape-upstream-issuer-proof.json). + The configuration owner must still ensure `authelia.issuer` is pinned to + that exact value before this window. The probe left normal configuration + unchanged. Keep the existing-human-login regression in the rollout checks. In-window order: diff --git a/docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json b/docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json new file mode 100644 index 0000000..85dab93 --- /dev/null +++ b/docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json @@ -0,0 +1,133 @@ +{ + "recorded_at": "2026-09-08T21:50:10.049099+00:00", + "authorization": { + "source": "User response in this session: yes, go on", + "scope": "Prepared ten-minute temporary issuer probe; existing config read in workload, exact-state callback and cleanup", + "custody_activation_authorized": false + }, + "source": { + "repo": "key-cape", + "code_commit": "6f33abddcff6cbc348ced862057973cdcc4f78ec", + "published_owner_commit": "7ecc78f4100c04f9b4ea7751240114bcc485de03", + "packet": "docs/upstream-issuer-proof.md", + "image": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4" + }, + "proof": { + "audience_verified": true, + "downstream_credential_issued": false, + "issuer": "https://auth.coulomb.social", + "nonce_verified": true, + "observed_at": "2026-09-08T21:44:44Z", + "schema": "keycape.upstream-issuer-proof.v1", + "signature_verified": true, + "status": "verified", + "tokens_retained": false, + "validity_window_verified": true + }, + "job": { + "name": "keycape-issuer-proof-532da53dc96a", + "started_at": "2026-09-08T21:43:34.019545+00:00", + "created_resources": [ + { + "kind": "Job", + "name": "keycape-issuer-proof-532da53dc96a", + "uid": "4e01daef-9184-4866-ac4d-9d61cd8d79ae" + }, + { + "kind": "Service", + "name": "keycape-issuer-proof-532da53dc96a", + "uid": "3359ce09-cbe2-487b-b9d9-a4cc5c484047" + }, + { + "kind": "NetworkPolicy", + "name": "keycape-issuer-proof-532da53dc96a", + "uid": "8940e5b4-3665-4395-8a0d-39b4b08ae12d" + }, + { + "kind": "NetworkPolicy", + "name": "keycape-issuer-proof-532da53dc96a-authelia", + "uid": "13d72383-0864-4665-af28-eefc76452131" + }, + { + "kind": "IngressRoute", + "name": "keycape-issuer-proof-532da53dc96a", + "uid": "7d705d80-f491-408f-a133-0bc4abd2c867" + } + ] + }, + "pod_evidence": [ + { + "name": "keycape-issuer-proof-532da53dc96a-tgpxh", + "uid": "c9230c57-0fad-4dcf-b798-d586385db9a2", + "phase": "Succeeded", + "containers": [ + { + "name": "probe", + "image": "sha256:204d8a4b04f47fa93c508b0a74c600e9954cfeab8e4e6566a8feaab327e8f793", + "imageID": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4", + "ready": false, + "state": { + "terminated": { + "exitCode": 0, + "finishedAt": "2026-09-08T21:44:44Z", + "reason": "Completed", + "startedAt": "2026-09-08T21:43:37Z" + } + } + } + ] + } + ], + "browser": { + "route_head_status": 405, + "launcher_exit": 0, + "url_scope": "exact generated HTTPS issuer-proof start path" + }, + "cleanup": { + "completed_at": "2026-09-08T21:45:17.886281+00:00", + "removed": [ + { + "kind": "IngressRoute", + "name": "keycape-issuer-proof-532da53dc96a", + "uid_precondition": true + }, + { + "kind": "Job", + "name": "keycape-issuer-proof-532da53dc96a", + "uid_precondition": true + }, + { + "kind": "Service", + "name": "keycape-issuer-proof-532da53dc96a", + "already_absent": true + }, + { + "kind": "NetworkPolicy", + "name": "keycape-issuer-proof-532da53dc96a", + "already_absent": true + }, + { + "kind": "NetworkPolicy", + "name": "keycape-issuer-proof-532da53dc96a-authelia", + "already_absent": true + } + ], + "all_temporary_resources_absent": true, + "production_metadata_unchanged": true, + "before": { + "production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b", + "deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29", + "secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058" + }, + "after": { + "production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b", + "deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29", + "secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058" + } + }, + "config_issuer_pinned_by_this_run": false, + "custody_activated": false, + "normal_keycape_deployment_changed": false, + "downstream_mfa_or_application_login_proved": false, + "next_return": "Configuration owner ensures authelia.issuer equals the verified HTTPS issuer; named CCR reviews and attended custody/compatible image rollout remain open" +} diff --git a/workplans/RPF-WP-0035-credential-lane-implementation.md b/workplans/RPF-WP-0035-credential-lane-implementation.md index edcebe2..851f32e 100644 --- a/workplans/RPF-WP-0035-credential-lane-implementation.md +++ b/workplans/RPF-WP-0035-credential-lane-implementation.md @@ -220,3 +220,20 @@ T05 remains wait: both CCRs are still proposed, the actual upstream ID-token issuer precondition remains open, and no verifier-side credential is provisioned. Client-side retrieval and audit-sender custody are still separate owner returns. The capability receipt is not a review approval or service readiness proof. + + +### 2026-09-08 actual upstream issuer returned + +The admitted KeyCape one-shot probe verified the actual signed upstream issuer +as **`https://auth.coulomb.social`** at 21:44:44 UTC. Signature, audience, +validity window and nonce checks passed and the pinned Job exited 0. All +five temporary resources and the Pod were removed; normal KeyCape Deployment +and config Secret metadata are unchanged. See +`docs/evidence/2026-09-08-keycape-upstream-issuer-proof.json`. + +T05's unknown-issuer input is resolved. The configuration owner still ensures +`authelia.issuer` equals that exact HTTPS value before the custody window. +Both CCRs remain proposed and await the named reviews; this probe grants no +custody mutation or client-side read. Keep the current authority preflight and +this signed-token proof as separate receipts. Live ESO/client/approval and +separate audit/client-side custody acceptance remain open.