Allocate sitting-requester CCR pair and record operator gates.
CCR-2026-0026/0027 are proposed source only: new KV path, no apply, and no widening of 0024/0025. Record destroy-after-confirm for the npm duplicate, coordinated 0018 disablement, blocked historical NetKingdom paths, and no Forgejo retention cutover. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
This commit is contained in:
parent
f05ef49c69
commit
d2dbc19c25
11 changed files with 332 additions and 4 deletions
|
|
@ -0,0 +1,47 @@
|
||||||
|
# CCR-2026-0026 (INFD-WP-0002, RPF-WP-0042). Source only. Do not apply from this
|
||||||
|
# file. KeyCape env KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
|
||||||
|
# uses Kubernetes Secret key client-secret; OpenBao field is CLIENT_SECRET.
|
||||||
|
apiVersion: external-secrets.io/v1
|
||||||
|
kind: ClusterSecretStore
|
||||||
|
metadata:
|
||||||
|
name: openbao-keycape-informed-decision-sitting-requester
|
||||||
|
labels:
|
||||||
|
app.kubernetes.io/part-of: railiance-gitops
|
||||||
|
railiance-platform/component: external-secrets
|
||||||
|
app.kubernetes.io/name: keycape
|
||||||
|
spec:
|
||||||
|
provider:
|
||||||
|
vault:
|
||||||
|
server: http://openbao.openbao.svc:8200
|
||||||
|
path: platform
|
||||||
|
version: v2
|
||||||
|
auth:
|
||||||
|
kubernetes:
|
||||||
|
mountPath: kubernetes
|
||||||
|
role: external-secrets-keycape-informed-decision-sitting-requester
|
||||||
|
serviceAccountRef:
|
||||||
|
name: external-secrets
|
||||||
|
namespace: external-secrets
|
||||||
|
conditions:
|
||||||
|
- namespaces:
|
||||||
|
- sso
|
||||||
|
---
|
||||||
|
apiVersion: external-secrets.io/v1
|
||||||
|
kind: ExternalSecret
|
||||||
|
metadata:
|
||||||
|
name: keycape-informed-decision-sitting-requester-client
|
||||||
|
namespace: sso
|
||||||
|
spec:
|
||||||
|
refreshInterval: 5m
|
||||||
|
secretStoreRef:
|
||||||
|
kind: ClusterSecretStore
|
||||||
|
name: openbao-keycape-informed-decision-sitting-requester
|
||||||
|
target:
|
||||||
|
name: keycape-informed-decision-sitting-requester-client
|
||||||
|
creationPolicy: Owner
|
||||||
|
deletionPolicy: Retain
|
||||||
|
data:
|
||||||
|
- secretKey: client-secret
|
||||||
|
remoteRef:
|
||||||
|
key: workloads/informed-decision/sitting-requester
|
||||||
|
property: CLIENT_SECRET
|
||||||
|
|
@ -0,0 +1,94 @@
|
||||||
|
id: CCR-2026-0026
|
||||||
|
kind: credential-change-request
|
||||||
|
schema_version: 1
|
||||||
|
request_type: workload-kv-read
|
||||||
|
title: Informed Decision sitting-requester KeyCape verifier custody
|
||||||
|
status: proposed
|
||||||
|
created: '2026-09-15'
|
||||||
|
updated: '2026-09-15'
|
||||||
|
requester:
|
||||||
|
agent: grok
|
||||||
|
reason: INFD-WP-0002-T03 requested a create-only sitting presenter whose binding.actor
|
||||||
|
is informed-decision. Allocate a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025
|
||||||
|
or platform/workloads/secrets-engine/approval-requester.
|
||||||
|
review:
|
||||||
|
required: true
|
||||||
|
required_approvers:
|
||||||
|
- platform-operator
|
||||||
|
- key-cape-owner
|
||||||
|
comments:
|
||||||
|
- at: '2026-09-15'
|
||||||
|
reviewer: operator instruction in Grok session
|
||||||
|
decision: allocated
|
||||||
|
comment: Operator selected allocation of the sitting-requester CCR pair. Source
|
||||||
|
only. No OpenBao apply, no secret seed, no KeyCape registration, and no sitting
|
||||||
|
POST from this allocation.
|
||||||
|
target:
|
||||||
|
domain: financials
|
||||||
|
tenant: platform
|
||||||
|
workload: informed-decision
|
||||||
|
environment: production
|
||||||
|
purpose: create-only sitting requester KeyCape verifier custody; approval:create
|
||||||
|
only; subject informed-decision; audience approval-engine.
|
||||||
|
openbao:
|
||||||
|
mount: platform
|
||||||
|
kv_path: platform/workloads/informed-decision/sitting-requester
|
||||||
|
fields:
|
||||||
|
- CLIENT_SECRET
|
||||||
|
policy_name: workload-kv-read-keycape-informed-decision-sitting-requester
|
||||||
|
policy_file: openbao/policies/workload-kv-read-keycape-informed-decision-sitting-requester.hcl
|
||||||
|
auth:
|
||||||
|
method: kubernetes
|
||||||
|
mount: kubernetes
|
||||||
|
role: external-secrets-keycape-informed-decision-sitting-requester
|
||||||
|
bound_claims:
|
||||||
|
service_account_names:
|
||||||
|
- external-secrets
|
||||||
|
service_account_namespaces:
|
||||||
|
- external-secrets
|
||||||
|
bound_claims_confirmed: true
|
||||||
|
policies:
|
||||||
|
- workload-kv-read-keycape-informed-decision-sitting-requester
|
||||||
|
ttl: 15m
|
||||||
|
access_frontdoor:
|
||||||
|
type: ops-warden
|
||||||
|
catalog_id: informed-decision-sitting-requester-login
|
||||||
|
selector: Informed Decision create-only sitting requester
|
||||||
|
command: warden access informed-decision-sitting-requester-login --exec -- <reviewed-requester-command>
|
||||||
|
resolvable: false
|
||||||
|
readiness: pending-review
|
||||||
|
delivery:
|
||||||
|
surface: external-secrets
|
||||||
|
target: sso/keycape-informed-decision-sitting-requester-client via ESO; env KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
|
||||||
|
risk:
|
||||||
|
classification: high
|
||||||
|
notes:
|
||||||
|
- Credential authenticates only the separate approval:create sitting requester.
|
||||||
|
Human disposition remains on the public PKCE client informed-decision-approver.
|
||||||
|
- Do not widen CCR-2026-0024/0025 or secrets-engine/approval-requester.
|
||||||
|
- No approval, consume, or read scope. No sitting POST until exchange proof exists.
|
||||||
|
verification:
|
||||||
|
positive:
|
||||||
|
- Exact path read of CLIENT_SECRET for the KeyCape verifier ServiceAccount only.
|
||||||
|
- Sibling secrets-engine/approval-requester and parent listing denied.
|
||||||
|
negative:
|
||||||
|
- Approval and consume scopes refused at token exchange; wrong secret refused.
|
||||||
|
- Sibling KV paths and parent listing denied.
|
||||||
|
activation_conditions:
|
||||||
|
- KeyCape row informed-decision-sitting-requester exists and remains unregistered
|
||||||
|
until attended CAS=0 custody and exact policy/auth readback.
|
||||||
|
- Separate reader verification and no human entry synthesized.
|
||||||
|
- No sitting POST until exchange proof exists.
|
||||||
|
lifecycle:
|
||||||
|
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
|
||||||
|
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025
|
||||||
|
and existing consumer/verifier lanes.
|
||||||
|
rotate: Rotate through KeyCape and platform using a new version with predecessor
|
||||||
|
refusal proof.
|
||||||
|
compromised: Disable sitting-requester issuance first; revoke sessions and rotate
|
||||||
|
under attended owner authority.
|
||||||
|
state_hub:
|
||||||
|
workplan_id: RPF-WP-0042
|
||||||
|
task_id: RPF-WP-0042-T01
|
||||||
|
related_request: CCR-2026-0027
|
||||||
|
related_workplan: INFD-WP-0002
|
||||||
|
|
@ -0,0 +1,103 @@
|
||||||
|
id: CCR-2026-0027
|
||||||
|
kind: credential-change-request
|
||||||
|
schema_version: 1
|
||||||
|
request_type: workload-kv-read
|
||||||
|
title: Informed Decision sitting-requester attended operator reader
|
||||||
|
status: proposed
|
||||||
|
created: '2026-09-15'
|
||||||
|
updated: '2026-09-15'
|
||||||
|
requester:
|
||||||
|
agent: grok
|
||||||
|
reason: INFD-WP-0002-T03 requested a create-only sitting presenter whose binding.actor
|
||||||
|
is informed-decision. Allocate a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025
|
||||||
|
or platform/workloads/secrets-engine/approval-requester.
|
||||||
|
review:
|
||||||
|
required: true
|
||||||
|
required_approvers:
|
||||||
|
- platform-operator
|
||||||
|
- key-cape-owner
|
||||||
|
comments:
|
||||||
|
- at: '2026-09-15'
|
||||||
|
reviewer: operator instruction in Grok session
|
||||||
|
decision: allocated
|
||||||
|
comment: Operator selected allocation of the sitting-requester CCR pair. Source
|
||||||
|
only. No OpenBao apply, no secret seed, and no sitting POST from this allocation.
|
||||||
|
target:
|
||||||
|
domain: financials
|
||||||
|
tenant: platform
|
||||||
|
workload: informed-decision
|
||||||
|
environment: production
|
||||||
|
purpose: create-only sitting requester attended operator reader; approval:create
|
||||||
|
only; subject informed-decision; audience approval-engine.
|
||||||
|
openbao:
|
||||||
|
mount: platform
|
||||||
|
kv_path: platform/workloads/informed-decision/sitting-requester
|
||||||
|
fields:
|
||||||
|
- CLIENT_SECRET
|
||||||
|
policy_name: workload-kv-read-informed-decision-sitting-requester-client
|
||||||
|
policy_file: openbao/policies/workload-kv-read-informed-decision-sitting-requester-client.hcl
|
||||||
|
auth:
|
||||||
|
method: oidc
|
||||||
|
mount: netkingdom
|
||||||
|
role: informed-decision-sitting-requester-workload-kv-read
|
||||||
|
allowed_redirect_uris:
|
||||||
|
- https://bao.coulomb.social/ui/vault/auth/netkingdom/oidc/callback
|
||||||
|
- http://localhost:8250/oidc/callback
|
||||||
|
- http://127.0.0.1:8250/oidc/callback
|
||||||
|
oidc_scopes:
|
||||||
|
- openid
|
||||||
|
- profile
|
||||||
|
- email
|
||||||
|
- groups
|
||||||
|
user_claim: sub
|
||||||
|
groups_claim: groups
|
||||||
|
bound_claims:
|
||||||
|
groups:
|
||||||
|
- net-kingdom-admins
|
||||||
|
bound_claims_confirmed: true
|
||||||
|
policies:
|
||||||
|
- workload-kv-read-informed-decision-sitting-requester-client
|
||||||
|
ttl: 15m
|
||||||
|
access_frontdoor:
|
||||||
|
type: ops-warden
|
||||||
|
catalog_id: informed-decision-sitting-requester-login
|
||||||
|
selector: Informed Decision create-only sitting requester
|
||||||
|
command: warden access informed-decision-sitting-requester-login --exec -- <reviewed-requester-command>
|
||||||
|
resolvable: false
|
||||||
|
readiness: pending-review
|
||||||
|
delivery:
|
||||||
|
surface: operator-workstation
|
||||||
|
target: Contained attended reader session; secret stays in memory for native requester
|
||||||
|
exchange; no retained file or raw output.
|
||||||
|
risk:
|
||||||
|
classification: high
|
||||||
|
notes:
|
||||||
|
- Credential authenticates only the separate approval:create sitting requester.
|
||||||
|
Human disposition remains on the public PKCE client informed-decision-approver.
|
||||||
|
- Do not widen CCR-2026-0024/0025 or secrets-engine/approval-requester.
|
||||||
|
- Bound group is net-kingdom-admins, matching CCR-2026-0019/0025 operator binding.
|
||||||
|
verification:
|
||||||
|
positive:
|
||||||
|
- Exact path read of CLIENT_SECRET for the attended operator identity only.
|
||||||
|
- Sibling secrets-engine/approval-requester and parent listing denied.
|
||||||
|
negative:
|
||||||
|
- Approval and consume scopes refused at token exchange; wrong secret refused.
|
||||||
|
- Sibling KV paths and parent listing denied.
|
||||||
|
activation_conditions:
|
||||||
|
- Attended platform authority, CAS=0 custody, exact policy/auth readback and synchronized
|
||||||
|
verifier delivery.
|
||||||
|
- Separate reader verification and no human entry synthesized.
|
||||||
|
- No sitting POST until exchange proof exists.
|
||||||
|
lifecycle:
|
||||||
|
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
|
||||||
|
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025
|
||||||
|
and existing consumer/verifier lanes.
|
||||||
|
rotate: Rotate through KeyCape and platform using a new version with predecessor
|
||||||
|
refusal proof.
|
||||||
|
compromised: Disable sitting-requester issuance first; revoke sessions and rotate
|
||||||
|
under attended owner authority.
|
||||||
|
state_hub:
|
||||||
|
workplan_id: RPF-WP-0042
|
||||||
|
task_id: RPF-WP-0042-T01
|
||||||
|
related_request: CCR-2026-0026
|
||||||
|
related_workplan: INFD-WP-0002
|
||||||
|
|
@ -45,6 +45,10 @@ The routing lane is registered but remains `resolvable: false`. No
|
||||||
restoration is authorized until the OpenBao owner publishes the missing
|
restoration is authorized until the OpenBao owner publishes the missing
|
||||||
metadata and the attended handoff is approved.
|
metadata and the attended handoff is approved.
|
||||||
|
|
||||||
|
Operator decision 2026-09-15: leave both historical resolver lanes blocked.
|
||||||
|
Do not invent mount, path, or field names. The KeyCape factor service lane
|
||||||
|
below is separate and does not close this gate.
|
||||||
|
|
||||||
## KeyCape factor service lane — authorized setup, 2026-09-13
|
## KeyCape factor service lane — authorized setup, 2026-09-13
|
||||||
|
|
||||||
RPF-WP-0040 / CCR-2026-0023 establish a new dedicated service lane. The user,
|
RPF-WP-0040 / CCR-2026-0023 establish a new dedicated service lane. The user,
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,7 @@
|
||||||
|
path "platform/data/workloads/informed-decision/sitting-requester" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
|
|
||||||
|
path "platform/metadata/workloads/informed-decision/sitting-requester" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
|
|
@ -0,0 +1,7 @@
|
||||||
|
path "platform/data/workloads/informed-decision/sitting-requester" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
|
|
||||||
|
path "platform/metadata/workloads/informed-decision/sitting-requester" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
|
|
@ -14,6 +14,7 @@ plans is not a count of missing implementations or independent incidents.
|
||||||
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |
|
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |
|
||||||
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
|
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
|
||||||
| [RPF-WP-0038](RPF-WP-0038-forgejo-scaleway-primary-coverage.md) | Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains | Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention. |
|
| [RPF-WP-0038](RPF-WP-0038-forgejo-scaleway-primary-coverage.md) | Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains | Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention. |
|
||||||
|
| [RPF-WP-0042](RPF-WP-0042-informed-decision-sitting-requester.md) | Sitting-requester CCR-2026-0026/0027 allocated; no apply | Do not widen 0024/0025. Attended seed waits on owner reviews and KeyCape row. |
|
||||||
|
|
||||||
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining
|
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining
|
||||||
acceptance gates. Treat credential exposure closure as the highest-priority attended
|
acceptance gates. Treat credential exposure closure as the highest-priority attended
|
||||||
|
|
|
||||||
|
|
@ -9,7 +9,7 @@ flavor: implementation
|
||||||
owner: codex
|
owner: codex
|
||||||
topic_slug: railiance
|
topic_slug: railiance
|
||||||
created: "2026-08-23"
|
created: "2026-08-23"
|
||||||
updated: "2026-09-05"
|
updated: "2026-09-15"
|
||||||
related:
|
related:
|
||||||
- KEY-WP-0011
|
- KEY-WP-0011
|
||||||
origin: routed
|
origin: routed
|
||||||
|
|
@ -137,6 +137,11 @@ publication, update `docs/net-kingdom-credential-custody-contract.md`, ask
|
||||||
ops-warden to refresh lane resolvability, and pass only protected inputs to
|
ops-warden to refresh lane resolvability, and pass only protected inputs to
|
||||||
NetKingdom's minimal resolver reconciliation flow.
|
NetKingdom's minimal resolver reconciliation flow.
|
||||||
|
|
||||||
|
**Operator decision, 2026-09-15:** leave both historical resolver lanes blocked.
|
||||||
|
Do not invent mount/path/field names. The KeyCape factor service lane from
|
||||||
|
RPF-WP-0040 remains the separate active custody; it does not close these
|
||||||
|
incident lanes.
|
||||||
|
|
||||||
## Portfolio review — 2026-09-05
|
## Portfolio review — 2026-09-05
|
||||||
|
|
||||||
INTENT binding: secure custody and incident closure. The goal above is historical;
|
INTENT binding: secure custody and incident closure. The goal above is historical;
|
||||||
|
|
|
||||||
|
|
@ -8,7 +8,7 @@ status: blocked
|
||||||
flavor: implementation
|
flavor: implementation
|
||||||
owner: codex
|
owner: codex
|
||||||
created: "2026-09-05"
|
created: "2026-09-05"
|
||||||
updated: "2026-09-11"
|
updated: "2026-09-15"
|
||||||
related:
|
related:
|
||||||
- RPF-WP-0032
|
- RPF-WP-0032
|
||||||
- RPF-WP-0033
|
- RPF-WP-0033
|
||||||
|
|
@ -247,7 +247,7 @@ Rotation is a distinct, version-guarded operation.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: RPF-WP-0035-T07
|
id: RPF-WP-0035-T07
|
||||||
status: todo
|
status: wait
|
||||||
priority: high
|
priority: high
|
||||||
state_hub_task_id: "0dd7c9a5-65a0-53fc-b6c3-5ad96ee56f7b"
|
state_hub_task_id: "0dd7c9a5-65a0-53fc-b6c3-5ad96ee56f7b"
|
||||||
```
|
```
|
||||||
|
|
@ -271,6 +271,11 @@ then a working production lane has been running off an ungoverned duplicate,
|
||||||
and the governed lane's acceptance evidence describes a path the consumer does
|
and the governed lane's acceptance evidence describes a path the consumer does
|
||||||
not use. That is worth establishing before anything is removed.
|
not use. That is worth establishing before anything is removed.
|
||||||
|
|
||||||
|
**Operator decision, 2026-09-15:** destroy the legacy path after confirming the
|
||||||
|
governed lane is the live consumer. Do not wrap `secret/coulomb/whynot-design/npm/publish`
|
||||||
|
in a CCR. Value remains unread. Platform will ask secrets-engine which path
|
||||||
|
publish actually reads before any attended destroy.
|
||||||
|
|
||||||
**Unblock:** secrets-engine confirms which location their publish actually reads
|
**Unblock:** secrets-engine confirms which location their publish actually reads
|
||||||
and whether the two hold the same value; the owner of the legacy path is
|
and whether the two hold the same value; the owner of the legacy path is
|
||||||
identified; and a metadata-or-field-name read of the legacy path is admitted so
|
identified; and a metadata-or-field-name read of the legacy path is admitted so
|
||||||
|
|
@ -330,6 +335,11 @@ disables that live registration nor accepts indefinite retention. Keep this
|
||||||
disposition in T06; it is separate from the wanted CCR-2026-0019 factory reader.
|
disposition in T06; it is separate from the wanted CCR-2026-0019 factory reader.
|
||||||
No unilateral issuer/config/Secret change is authorized by this closeout.
|
No unilateral issuer/config/Secret change is authorized by this closeout.
|
||||||
|
|
||||||
|
**Operator decision, 2026-09-15:** coordinated disablement with KeyCape and
|
||||||
|
Approval Engine. Platform will not disable the live registration or verifier
|
||||||
|
delivery unilaterally. T06 stays `wait` until both owners confirm the joint
|
||||||
|
disablement sequence.
|
||||||
|
|
||||||
Residual handoff from RPF-WP-0035-T05; consumes the completed verifier custody
|
Residual handoff from RPF-WP-0035-T05; consumes the completed verifier custody
|
||||||
without extending CCR-2026-0017/0018. Owner: railiance-platform with the named
|
without extending CCR-2026-0017/0018. Owner: railiance-platform with the named
|
||||||
secrets-engine and approval-engine operator consumers.
|
secrets-engine and approval-engine operator consumers.
|
||||||
|
|
|
||||||
|
|
@ -8,7 +8,7 @@ status: active
|
||||||
flavor: implementation
|
flavor: implementation
|
||||||
owner: codex
|
owner: codex
|
||||||
created: "2026-09-06"
|
created: "2026-09-06"
|
||||||
updated: "2026-09-06"
|
updated: "2026-09-15"
|
||||||
state_hub_workstream_id: "7beec1a7-aa82-5a36-9a66-6b60008a2455"
|
state_hub_workstream_id: "7beec1a7-aa82-5a36-9a66-6b60008a2455"
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
@ -114,3 +114,7 @@ leave a successful restore status. Historical primary decryption receipts remain
|
||||||
accepted explicitly, while new decryption retains its own schema. No repeat
|
accepted explicitly, while new decryption retains its own schema. No repeat
|
||||||
upload, expiry or scheduled caller change was made; T04 remains in progress for
|
upload, expiry or scheduled caller change was made; T04 remains in progress for
|
||||||
the existing durable caller, inventory, quota and retention gates.
|
the existing durable caller, inventory, quota and retention gates.
|
||||||
|
|
||||||
|
**Operator decision, 2026-09-15:** do not expire retained backups or cut over
|
||||||
|
scheduled secondary delivery. The planner and attended executor stay idle until
|
||||||
|
durable caller/inventory/quota gates are closed.
|
||||||
|
|
|
||||||
46
workplans/RPF-WP-0042-informed-decision-sitting-requester.md
Normal file
46
workplans/RPF-WP-0042-informed-decision-sitting-requester.md
Normal file
|
|
@ -0,0 +1,46 @@
|
||||||
|
---
|
||||||
|
id: RPF-WP-0042
|
||||||
|
type: workplan
|
||||||
|
title: "Allocate Informed Decision sitting-requester custody"
|
||||||
|
domain: financials
|
||||||
|
repo: railiance-platform
|
||||||
|
status: ready
|
||||||
|
flavor: implementation
|
||||||
|
owner: grok
|
||||||
|
topic_slug: railiance
|
||||||
|
created: "2026-09-15"
|
||||||
|
updated: "2026-09-15"
|
||||||
|
related: [INFD-WP-0002]
|
||||||
|
---
|
||||||
|
|
||||||
|
INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform
|
||||||
|
allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or
|
||||||
|
`platform/workloads/secrets-engine/approval-requester`. No apply, secret seed,
|
||||||
|
or sitting POST from allocation.
|
||||||
|
|
||||||
|
## Allocate the verifier and attended-reader CCR pair
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: RPF-WP-0042-T01
|
||||||
|
status: done
|
||||||
|
priority: high
|
||||||
|
```
|
||||||
|
|
||||||
|
CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader)
|
||||||
|
use KV `platform/workloads/informed-decision/sitting-requester`, field
|
||||||
|
`CLIENT_SECRET` only. Exact-path policies, Kubernetes ESO role, and
|
||||||
|
`net-kingdom-admins` reader binding are source-declared. Front door remains
|
||||||
|
non-resolvable. ESO projection is unapplied source.
|
||||||
|
|
||||||
|
## Attended first provision and exchange proof
|
||||||
|
|
||||||
|
```task
|
||||||
|
id: RPF-WP-0042-T02
|
||||||
|
status: wait
|
||||||
|
priority: high
|
||||||
|
```
|
||||||
|
|
||||||
|
Requires named owner reviews, KeyCape row `informed-decision-sitting-requester`,
|
||||||
|
attended CAS=0 custody, exact policy/auth readback, sibling
|
||||||
|
`secrets-engine/approval-requester` denial, and create-only token-exchange proof.
|
||||||
|
No sitting POST until that proof exists.
|
||||||
Loading…
Add table
Add a link
Reference in a new issue