docs: retain approval client consumer procedure return
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-10 12:48:38 +02:00
parent 67c5a7a508
commit d3a502b45c
2 changed files with 24 additions and 1 deletions

View file

@ -5,7 +5,7 @@ request_type: workload-kv-read
title: secrets-engine client-side read of its approval client secret
status: in_flight
created: '2026-09-09'
updated: '2026-09-09'
updated: '2026-09-10'
in_flight:
missing_fields:
- openbao.auth
@ -51,6 +51,21 @@ review:
makes this an attended operator-workstation lane on the OIDC mount, not an
External Secrets lane. The named operator group claim is the one input
neither this repo nor secrets-engine can supply; NetKingdom/KeyCape own it.
- at: '2026-09-10'
reviewer: codex (consumer source review)
decision: consumer_procedure_documented
comment: >-
Secrets Engine source 98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93,
docs/approval-service-auth.md, supplies the requested workstation
procedure: operator-owned 0700 runtime session directory outside Git,
new 0600 file, path-only configuration across one claim/consume operation,
EXIT/INT/TERM cleanup, and explicit residual-file handling after a hard
interruption. The consumer checks file permissions/location/non-emptiness;
creation, parent custody and removal remain attended responsibilities.
No automatic cleanup or live read proof is claimed. This documents the
consumer return; it is not platform-operator/secrets-engine-owner approval,
group confirmation or authority to apply the role. Existing activation
conditions and in_flight status remain.
target:
domain: financials
tenant: platform

View file

@ -308,6 +308,14 @@ from NetKingdom/KeyCape, then reviewed attended file delivery and its scoped
positive/negative proof. Completed CCR-2026-0017/0018 remain closed. T06 stays
`wait`; its historical two-reader notes below are superseded for reader 2.
Consumer procedure returned in source, 2026-09-10:
`secrets-engine@98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93:docs/approval-service-auth.md`
specifies the requested private 0700 runtime directory, 0600 file outside Git,
path-only use, claim/consume lifetime and attended cleanup including hard-stop
residual inspection. CCR-2026-0019 retains this source-review comment without
changing admission status. Exact group, required-owner review, attended apply and
native positive/negative/cleanup evidence remain. No role or credential changed.
Separate retained owner decision: KeyCape's 2026-09-10 return
`21427688-725f-4dea-aab4-7c78fd4328d2` identifies the already-live, unpresented
CCR-2026-0018 registration. Approval Engine, KeyCape and Platform must explicitly