Allocate sitting-requester CCR pair and record operator gates.

CCR-2026-0026/0027 are proposed source only: new KV path, no apply,
and no widening of 0024/0025. Record destroy-after-confirm for the
npm duplicate, coordinated 0018 disablement, blocked historical
NetKingdom paths, and no Forgejo retention cutover.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
codex 2026-09-15 02:08:39 +02:00
parent f05ef49c69
commit d2dbc19c25
11 changed files with 332 additions and 4 deletions

View file

@ -14,6 +14,7 @@ plans is not a count of missing implementations or independent incidents.
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
| [RPF-WP-0038](RPF-WP-0038-forgejo-scaleway-primary-coverage.md) | Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains | Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention. |
| [RPF-WP-0042](RPF-WP-0042-informed-decision-sitting-requester.md) | Sitting-requester CCR-2026-0026/0027 allocated; no apply | Do not widen 0024/0025. Attended seed waits on owner reviews and KeyCape row. |
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining
acceptance gates. Treat credential exposure closure as the highest-priority attended

View file

@ -9,7 +9,7 @@ flavor: implementation
owner: codex
topic_slug: railiance
created: "2026-08-23"
updated: "2026-09-05"
updated: "2026-09-15"
related:
- KEY-WP-0011
origin: routed
@ -137,6 +137,11 @@ publication, update `docs/net-kingdom-credential-custody-contract.md`, ask
ops-warden to refresh lane resolvability, and pass only protected inputs to
NetKingdom's minimal resolver reconciliation flow.
**Operator decision, 2026-09-15:** leave both historical resolver lanes blocked.
Do not invent mount/path/field names. The KeyCape factor service lane from
RPF-WP-0040 remains the separate active custody; it does not close these
incident lanes.
## Portfolio review — 2026-09-05
INTENT binding: secure custody and incident closure. The goal above is historical;

View file

@ -8,7 +8,7 @@ status: blocked
flavor: implementation
owner: codex
created: "2026-09-05"
updated: "2026-09-11"
updated: "2026-09-15"
related:
- RPF-WP-0032
- RPF-WP-0033
@ -247,7 +247,7 @@ Rotation is a distinct, version-guarded operation.
```task
id: RPF-WP-0035-T07
status: todo
status: wait
priority: high
state_hub_task_id: "0dd7c9a5-65a0-53fc-b6c3-5ad96ee56f7b"
```
@ -271,6 +271,11 @@ then a working production lane has been running off an ungoverned duplicate,
and the governed lane's acceptance evidence describes a path the consumer does
not use. That is worth establishing before anything is removed.
**Operator decision, 2026-09-15:** destroy the legacy path after confirming the
governed lane is the live consumer. Do not wrap `secret/coulomb/whynot-design/npm/publish`
in a CCR. Value remains unread. Platform will ask secrets-engine which path
publish actually reads before any attended destroy.
**Unblock:** secrets-engine confirms which location their publish actually reads
and whether the two hold the same value; the owner of the legacy path is
identified; and a metadata-or-field-name read of the legacy path is admitted so
@ -330,6 +335,11 @@ disables that live registration nor accepts indefinite retention. Keep this
disposition in T06; it is separate from the wanted CCR-2026-0019 factory reader.
No unilateral issuer/config/Secret change is authorized by this closeout.
**Operator decision, 2026-09-15:** coordinated disablement with KeyCape and
Approval Engine. Platform will not disable the live registration or verifier
delivery unilaterally. T06 stays `wait` until both owners confirm the joint
disablement sequence.
Residual handoff from RPF-WP-0035-T05; consumes the completed verifier custody
without extending CCR-2026-0017/0018. Owner: railiance-platform with the named
secrets-engine and approval-engine operator consumers.

View file

@ -8,7 +8,7 @@ status: active
flavor: implementation
owner: codex
created: "2026-09-06"
updated: "2026-09-06"
updated: "2026-09-15"
state_hub_workstream_id: "7beec1a7-aa82-5a36-9a66-6b60008a2455"
---
@ -114,3 +114,7 @@ leave a successful restore status. Historical primary decryption receipts remain
accepted explicitly, while new decryption retains its own schema. No repeat
upload, expiry or scheduled caller change was made; T04 remains in progress for
the existing durable caller, inventory, quota and retention gates.
**Operator decision, 2026-09-15:** do not expire retained backups or cut over
scheduled secondary delivery. The planner and attended executor stay idle until
durable caller/inventory/quota gates are closed.

View file

@ -0,0 +1,46 @@
---
id: RPF-WP-0042
type: workplan
title: "Allocate Informed Decision sitting-requester custody"
domain: financials
repo: railiance-platform
status: ready
flavor: implementation
owner: grok
topic_slug: railiance
created: "2026-09-15"
updated: "2026-09-15"
related: [INFD-WP-0002]
---
INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform
allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or
`platform/workloads/secrets-engine/approval-requester`. No apply, secret seed,
or sitting POST from allocation.
## Allocate the verifier and attended-reader CCR pair
```task
id: RPF-WP-0042-T01
status: done
priority: high
```
CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader)
use KV `platform/workloads/informed-decision/sitting-requester`, field
`CLIENT_SECRET` only. Exact-path policies, Kubernetes ESO role, and
`net-kingdom-admins` reader binding are source-declared. Front door remains
non-resolvable. ESO projection is unapplied source.
## Attended first provision and exchange proof
```task
id: RPF-WP-0042-T02
status: wait
priority: high
```
Requires named owner reviews, KeyCape row `informed-decision-sitting-requester`,
attended CAS=0 custody, exact policy/auth readback, sibling
`secrets-engine/approval-requester` denial, and create-only token-exchange proof.
No sitting POST until that proof exists.