Allocate sitting-requester CCR pair and record operator gates.

CCR-2026-0026/0027 are proposed source only: new KV path, no apply,
and no widening of 0024/0025. Record destroy-after-confirm for the
npm duplicate, coordinated 0018 disablement, blocked historical
NetKingdom paths, and no Forgejo retention cutover.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
codex 2026-09-15 02:08:39 +02:00
parent f05ef49c69
commit d2dbc19c25
11 changed files with 332 additions and 4 deletions

View file

@ -8,7 +8,7 @@ status: blocked
flavor: implementation
owner: codex
created: "2026-09-05"
updated: "2026-09-11"
updated: "2026-09-15"
related:
- RPF-WP-0032
- RPF-WP-0033
@ -247,7 +247,7 @@ Rotation is a distinct, version-guarded operation.
```task
id: RPF-WP-0035-T07
status: todo
status: wait
priority: high
state_hub_task_id: "0dd7c9a5-65a0-53fc-b6c3-5ad96ee56f7b"
```
@ -271,6 +271,11 @@ then a working production lane has been running off an ungoverned duplicate,
and the governed lane's acceptance evidence describes a path the consumer does
not use. That is worth establishing before anything is removed.
**Operator decision, 2026-09-15:** destroy the legacy path after confirming the
governed lane is the live consumer. Do not wrap `secret/coulomb/whynot-design/npm/publish`
in a CCR. Value remains unread. Platform will ask secrets-engine which path
publish actually reads before any attended destroy.
**Unblock:** secrets-engine confirms which location their publish actually reads
and whether the two hold the same value; the owner of the legacy path is
identified; and a metadata-or-field-name read of the legacy path is admitted so
@ -330,6 +335,11 @@ disables that live registration nor accepts indefinite retention. Keep this
disposition in T06; it is separate from the wanted CCR-2026-0019 factory reader.
No unilateral issuer/config/Secret change is authorized by this closeout.
**Operator decision, 2026-09-15:** coordinated disablement with KeyCape and
Approval Engine. Platform will not disable the live registration or verifier
delivery unilaterally. T06 stays `wait` until both owners confirm the joint
disablement sequence.
Residual handoff from RPF-WP-0035-T05; consumes the completed verifier custody
without extending CCR-2026-0017/0018. Owner: railiance-platform with the named
secrets-engine and approval-engine operator consumers.