diff --git a/credential-change-requests/CCR-2026-0019-secrets-engine-approval-client-read.yaml b/credential-change-requests/CCR-2026-0019-secrets-engine-approval-client-read.yaml index 01982df..f12e555 100644 --- a/credential-change-requests/CCR-2026-0019-secrets-engine-approval-client-read.yaml +++ b/credential-change-requests/CCR-2026-0019-secrets-engine-approval-client-read.yaml @@ -5,7 +5,7 @@ request_type: workload-kv-read title: secrets-engine client-side read of its approval client secret status: in_flight created: '2026-09-09' -updated: '2026-09-09' +updated: '2026-09-10' in_flight: missing_fields: - openbao.auth @@ -51,6 +51,21 @@ review: makes this an attended operator-workstation lane on the OIDC mount, not an External Secrets lane. The named operator group claim is the one input neither this repo nor secrets-engine can supply; NetKingdom/KeyCape own it. + - at: '2026-09-10' + reviewer: codex (consumer source review) + decision: consumer_procedure_documented + comment: >- + Secrets Engine source 98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93, + docs/approval-service-auth.md, supplies the requested workstation + procedure: operator-owned 0700 runtime session directory outside Git, + new 0600 file, path-only configuration across one claim/consume operation, + EXIT/INT/TERM cleanup, and explicit residual-file handling after a hard + interruption. The consumer checks file permissions/location/non-emptiness; + creation, parent custody and removal remain attended responsibilities. + No automatic cleanup or live read proof is claimed. This documents the + consumer return; it is not platform-operator/secrets-engine-owner approval, + group confirmation or authority to apply the role. Existing activation + conditions and in_flight status remain. target: domain: financials tenant: platform diff --git a/workplans/RPF-WP-0035-credential-lane-implementation.md b/workplans/RPF-WP-0035-credential-lane-implementation.md index 519f122..fdc3228 100644 --- a/workplans/RPF-WP-0035-credential-lane-implementation.md +++ b/workplans/RPF-WP-0035-credential-lane-implementation.md @@ -308,6 +308,14 @@ from NetKingdom/KeyCape, then reviewed attended file delivery and its scoped positive/negative proof. Completed CCR-2026-0017/0018 remain closed. T06 stays `wait`; its historical two-reader notes below are superseded for reader 2. +Consumer procedure returned in source, 2026-09-10: +`secrets-engine@98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93:docs/approval-service-auth.md` +specifies the requested private 0700 runtime directory, 0600 file outside Git, +path-only use, claim/consume lifetime and attended cleanup including hard-stop +residual inspection. CCR-2026-0019 retains this source-review comment without +changing admission status. Exact group, required-owner review, attended apply and +native positive/negative/cleanup evidence remain. No role or credential changed. + Separate retained owner decision: KeyCape's 2026-09-10 return `21427688-725f-4dea-aab4-7c78fd4328d2` identifies the already-live, unpresented CCR-2026-0018 registration. Approval Engine, KeyCape and Platform must explicitly