Allocate sitting-requester CCR pair and record operator gates.

CCR-2026-0026/0027 are proposed source only: new KV path, no apply,
and no widening of 0024/0025. Record destroy-after-confirm for the
npm duplicate, coordinated 0018 disablement, blocked historical
NetKingdom paths, and no Forgejo retention cutover.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
codex 2026-09-15 02:08:39 +02:00
parent f05ef49c69
commit d2dbc19c25
11 changed files with 332 additions and 4 deletions

View file

@ -0,0 +1,47 @@
# CCR-2026-0026 (INFD-WP-0002, RPF-WP-0042). Source only. Do not apply from this
# file. KeyCape env KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
# uses Kubernetes Secret key client-secret; OpenBao field is CLIENT_SECRET.
apiVersion: external-secrets.io/v1
kind: ClusterSecretStore
metadata:
name: openbao-keycape-informed-decision-sitting-requester
labels:
app.kubernetes.io/part-of: railiance-gitops
railiance-platform/component: external-secrets
app.kubernetes.io/name: keycape
spec:
provider:
vault:
server: http://openbao.openbao.svc:8200
path: platform
version: v2
auth:
kubernetes:
mountPath: kubernetes
role: external-secrets-keycape-informed-decision-sitting-requester
serviceAccountRef:
name: external-secrets
namespace: external-secrets
conditions:
- namespaces:
- sso
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: keycape-informed-decision-sitting-requester-client
namespace: sso
spec:
refreshInterval: 5m
secretStoreRef:
kind: ClusterSecretStore
name: openbao-keycape-informed-decision-sitting-requester
target:
name: keycape-informed-decision-sitting-requester-client
creationPolicy: Owner
deletionPolicy: Retain
data:
- secretKey: client-secret
remoteRef:
key: workloads/informed-decision/sitting-requester
property: CLIENT_SECRET

View file

@ -0,0 +1,94 @@
id: CCR-2026-0026
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Informed Decision sitting-requester KeyCape verifier custody
status: proposed
created: '2026-09-15'
updated: '2026-09-15'
requester:
agent: grok
reason: INFD-WP-0002-T03 requested a create-only sitting presenter whose binding.actor
is informed-decision. Allocate a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025
or platform/workloads/secrets-engine/approval-requester.
review:
required: true
required_approvers:
- platform-operator
- key-cape-owner
comments:
- at: '2026-09-15'
reviewer: operator instruction in Grok session
decision: allocated
comment: Operator selected allocation of the sitting-requester CCR pair. Source
only. No OpenBao apply, no secret seed, no KeyCape registration, and no sitting
POST from this allocation.
target:
domain: financials
tenant: platform
workload: informed-decision
environment: production
purpose: create-only sitting requester KeyCape verifier custody; approval:create
only; subject informed-decision; audience approval-engine.
openbao:
mount: platform
kv_path: platform/workloads/informed-decision/sitting-requester
fields:
- CLIENT_SECRET
policy_name: workload-kv-read-keycape-informed-decision-sitting-requester
policy_file: openbao/policies/workload-kv-read-keycape-informed-decision-sitting-requester.hcl
auth:
method: kubernetes
mount: kubernetes
role: external-secrets-keycape-informed-decision-sitting-requester
bound_claims:
service_account_names:
- external-secrets
service_account_namespaces:
- external-secrets
bound_claims_confirmed: true
policies:
- workload-kv-read-keycape-informed-decision-sitting-requester
ttl: 15m
access_frontdoor:
type: ops-warden
catalog_id: informed-decision-sitting-requester-login
selector: Informed Decision create-only sitting requester
command: warden access informed-decision-sitting-requester-login --exec -- <reviewed-requester-command>
resolvable: false
readiness: pending-review
delivery:
surface: external-secrets
target: sso/keycape-informed-decision-sitting-requester-client via ESO; env KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
risk:
classification: high
notes:
- Credential authenticates only the separate approval:create sitting requester.
Human disposition remains on the public PKCE client informed-decision-approver.
- Do not widen CCR-2026-0024/0025 or secrets-engine/approval-requester.
- No approval, consume, or read scope. No sitting POST until exchange proof exists.
verification:
positive:
- Exact path read of CLIENT_SECRET for the KeyCape verifier ServiceAccount only.
- Sibling secrets-engine/approval-requester and parent listing denied.
negative:
- Approval and consume scopes refused at token exchange; wrong secret refused.
- Sibling KV paths and parent listing denied.
activation_conditions:
- KeyCape row informed-decision-sitting-requester exists and remains unregistered
until attended CAS=0 custody and exact policy/auth readback.
- Separate reader verification and no human entry synthesized.
- No sitting POST until exchange proof exists.
lifecycle:
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025
and existing consumer/verifier lanes.
rotate: Rotate through KeyCape and platform using a new version with predecessor
refusal proof.
compromised: Disable sitting-requester issuance first; revoke sessions and rotate
under attended owner authority.
state_hub:
workplan_id: RPF-WP-0042
task_id: RPF-WP-0042-T01
related_request: CCR-2026-0027
related_workplan: INFD-WP-0002

View file

@ -0,0 +1,103 @@
id: CCR-2026-0027
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Informed Decision sitting-requester attended operator reader
status: proposed
created: '2026-09-15'
updated: '2026-09-15'
requester:
agent: grok
reason: INFD-WP-0002-T03 requested a create-only sitting presenter whose binding.actor
is informed-decision. Allocate a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025
or platform/workloads/secrets-engine/approval-requester.
review:
required: true
required_approvers:
- platform-operator
- key-cape-owner
comments:
- at: '2026-09-15'
reviewer: operator instruction in Grok session
decision: allocated
comment: Operator selected allocation of the sitting-requester CCR pair. Source
only. No OpenBao apply, no secret seed, and no sitting POST from this allocation.
target:
domain: financials
tenant: platform
workload: informed-decision
environment: production
purpose: create-only sitting requester attended operator reader; approval:create
only; subject informed-decision; audience approval-engine.
openbao:
mount: platform
kv_path: platform/workloads/informed-decision/sitting-requester
fields:
- CLIENT_SECRET
policy_name: workload-kv-read-informed-decision-sitting-requester-client
policy_file: openbao/policies/workload-kv-read-informed-decision-sitting-requester-client.hcl
auth:
method: oidc
mount: netkingdom
role: informed-decision-sitting-requester-workload-kv-read
allowed_redirect_uris:
- https://bao.coulomb.social/ui/vault/auth/netkingdom/oidc/callback
- http://localhost:8250/oidc/callback
- http://127.0.0.1:8250/oidc/callback
oidc_scopes:
- openid
- profile
- email
- groups
user_claim: sub
groups_claim: groups
bound_claims:
groups:
- net-kingdom-admins
bound_claims_confirmed: true
policies:
- workload-kv-read-informed-decision-sitting-requester-client
ttl: 15m
access_frontdoor:
type: ops-warden
catalog_id: informed-decision-sitting-requester-login
selector: Informed Decision create-only sitting requester
command: warden access informed-decision-sitting-requester-login --exec -- <reviewed-requester-command>
resolvable: false
readiness: pending-review
delivery:
surface: operator-workstation
target: Contained attended reader session; secret stays in memory for native requester
exchange; no retained file or raw output.
risk:
classification: high
notes:
- Credential authenticates only the separate approval:create sitting requester.
Human disposition remains on the public PKCE client informed-decision-approver.
- Do not widen CCR-2026-0024/0025 or secrets-engine/approval-requester.
- Bound group is net-kingdom-admins, matching CCR-2026-0019/0025 operator binding.
verification:
positive:
- Exact path read of CLIENT_SECRET for the attended operator identity only.
- Sibling secrets-engine/approval-requester and parent listing denied.
negative:
- Approval and consume scopes refused at token exchange; wrong secret refused.
- Sibling KV paths and parent listing denied.
activation_conditions:
- Attended platform authority, CAS=0 custody, exact policy/auth readback and synchronized
verifier delivery.
- Separate reader verification and no human entry synthesized.
- No sitting POST until exchange proof exists.
lifecycle:
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025
and existing consumer/verifier lanes.
rotate: Rotate through KeyCape and platform using a new version with predecessor
refusal proof.
compromised: Disable sitting-requester issuance first; revoke sessions and rotate
under attended owner authority.
state_hub:
workplan_id: RPF-WP-0042
task_id: RPF-WP-0042-T01
related_request: CCR-2026-0026
related_workplan: INFD-WP-0002

View file

@ -45,6 +45,10 @@ The routing lane is registered but remains `resolvable: false`. No
restoration is authorized until the OpenBao owner publishes the missing
metadata and the attended handoff is approved.
Operator decision 2026-09-15: leave both historical resolver lanes blocked.
Do not invent mount, path, or field names. The KeyCape factor service lane
below is separate and does not close this gate.
## KeyCape factor service lane — authorized setup, 2026-09-13
RPF-WP-0040 / CCR-2026-0023 establish a new dedicated service lane. The user,

View file

@ -0,0 +1,7 @@
path "platform/data/workloads/informed-decision/sitting-requester" {
capabilities = ["read"]
}
path "platform/metadata/workloads/informed-decision/sitting-requester" {
capabilities = ["read"]
}

View file

@ -0,0 +1,7 @@
path "platform/data/workloads/informed-decision/sitting-requester" {
capabilities = ["read"]
}
path "platform/metadata/workloads/informed-decision/sitting-requester" {
capabilities = ["read"]
}

View file

@ -14,6 +14,7 @@ plans is not a count of missing implementations or independent incidents.
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
| [RPF-WP-0038](RPF-WP-0038-forgejo-scaleway-primary-coverage.md) | Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains | Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention. |
| [RPF-WP-0042](RPF-WP-0042-informed-decision-sitting-requester.md) | Sitting-requester CCR-2026-0026/0027 allocated; no apply | Do not widen 0024/0025. Attended seed waits on owner reviews and KeyCape row. |
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining
acceptance gates. Treat credential exposure closure as the highest-priority attended

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex
topic_slug: railiance
created: "2026-08-23"
updated: "2026-09-05"
updated: "2026-09-15"
related:
- KEY-WP-0011
origin: routed
@ -137,6 +137,11 @@ publication, update `docs/net-kingdom-credential-custody-contract.md`, ask
ops-warden to refresh lane resolvability, and pass only protected inputs to
NetKingdom's minimal resolver reconciliation flow.
**Operator decision, 2026-09-15:** leave both historical resolver lanes blocked.
Do not invent mount/path/field names. The KeyCape factor service lane from
RPF-WP-0040 remains the separate active custody; it does not close these
incident lanes.
## Portfolio review — 2026-09-05
INTENT binding: secure custody and incident closure. The goal above is historical;

View file

@ -8,7 +8,7 @@ status: blocked
flavor: implementation
owner: codex
created: "2026-09-05"
updated: "2026-09-11"
updated: "2026-09-15"
related:
- RPF-WP-0032
- RPF-WP-0033
@ -247,7 +247,7 @@ Rotation is a distinct, version-guarded operation.
```task
id: RPF-WP-0035-T07
status: todo
status: wait
priority: high
state_hub_task_id: "0dd7c9a5-65a0-53fc-b6c3-5ad96ee56f7b"
```
@ -271,6 +271,11 @@ then a working production lane has been running off an ungoverned duplicate,
and the governed lane's acceptance evidence describes a path the consumer does
not use. That is worth establishing before anything is removed.
**Operator decision, 2026-09-15:** destroy the legacy path after confirming the
governed lane is the live consumer. Do not wrap `secret/coulomb/whynot-design/npm/publish`
in a CCR. Value remains unread. Platform will ask secrets-engine which path
publish actually reads before any attended destroy.
**Unblock:** secrets-engine confirms which location their publish actually reads
and whether the two hold the same value; the owner of the legacy path is
identified; and a metadata-or-field-name read of the legacy path is admitted so
@ -330,6 +335,11 @@ disables that live registration nor accepts indefinite retention. Keep this
disposition in T06; it is separate from the wanted CCR-2026-0019 factory reader.
No unilateral issuer/config/Secret change is authorized by this closeout.
**Operator decision, 2026-09-15:** coordinated disablement with KeyCape and
Approval Engine. Platform will not disable the live registration or verifier
delivery unilaterally. T06 stays `wait` until both owners confirm the joint
disablement sequence.
Residual handoff from RPF-WP-0035-T05; consumes the completed verifier custody
without extending CCR-2026-0017/0018. Owner: railiance-platform with the named
secrets-engine and approval-engine operator consumers.

View file

@ -8,7 +8,7 @@ status: active
flavor: implementation
owner: codex
created: "2026-09-06"
updated: "2026-09-06"
updated: "2026-09-15"
state_hub_workstream_id: "7beec1a7-aa82-5a36-9a66-6b60008a2455"
---
@ -114,3 +114,7 @@ leave a successful restore status. Historical primary decryption receipts remain
accepted explicitly, while new decryption retains its own schema. No repeat
upload, expiry or scheduled caller change was made; T04 remains in progress for
the existing durable caller, inventory, quota and retention gates.
**Operator decision, 2026-09-15:** do not expire retained backups or cut over
scheduled secondary delivery. The planner and attended executor stay idle until
durable caller/inventory/quota gates are closed.

View file

@ -0,0 +1,46 @@
---
id: RPF-WP-0042
type: workplan
title: "Allocate Informed Decision sitting-requester custody"
domain: financials
repo: railiance-platform
status: ready
flavor: implementation
owner: grok
topic_slug: railiance
created: "2026-09-15"
updated: "2026-09-15"
related: [INFD-WP-0002]
---
INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform
allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or
`platform/workloads/secrets-engine/approval-requester`. No apply, secret seed,
or sitting POST from allocation.
## Allocate the verifier and attended-reader CCR pair
```task
id: RPF-WP-0042-T01
status: done
priority: high
```
CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader)
use KV `platform/workloads/informed-decision/sitting-requester`, field
`CLIENT_SECRET` only. Exact-path policies, Kubernetes ESO role, and
`net-kingdom-admins` reader binding are source-declared. Front door remains
non-resolvable. ESO projection is unapplied source.
## Attended first provision and exchange proof
```task
id: RPF-WP-0042-T02
status: wait
priority: high
```
Requires named owner reviews, KeyCape row `informed-decision-sitting-requester`,
attended CAS=0 custody, exact policy/auth readback, sibling
`secrets-engine/approval-requester` denial, and create-only token-exchange proof.
No sitting POST until that proof exists.