Bind secrets-engine approval reader to confirmed operator group
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
codex 2026-09-14 01:30:23 +02:00
parent 817c122d07
commit bbff2bfb93
4 changed files with 200 additions and 121 deletions

View file

@ -303,10 +303,15 @@ remains refused. No live identity, policy, role, custody or verifier was changed
Human approval follows existing INFD-WP-0001-T07/T08; future service requesters
need a separate narrow registration, not this withdrawn bundle.
**Remaining unblock:** CCR-2026-0019 needs the exact authorized operator group
from NetKingdom/KeyCape, then reviewed attended file delivery and its scoped
positive/negative proof. Completed CCR-2026-0017/0018 remain closed. T06 stays
`wait`; its historical two-reader notes below are superseded for reader 2.
**Operator binding confirmed, 2026-09-14:** The user explicitly selected
`net-kingdom-admins` and authorized applying CCR-2026-0019. Its OIDC role is
`secrets-engine-approval-client-workload-kv-read`, aligned with the platform
applier naming rule; policy and exact KV scope are unchanged. The metadata dry
run passes with no warnings. Attended apply and exact role/policy readback passed; the enclosing Warden
command exited successfully after its self-revocation/cleanup. Receipt:
`docs/evidence/2026-09-14-ccr0019-operator-binding.json`. Scoped delivery proof
remains pending; the front door stays non-resolvable. Completed CCR-2026-0017/0018
remain closed and T06 stays `wait`.
Consumer procedure returned in source, 2026-09-10:
`secrets-engine@98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93:docs/approval-service-auth.md`