docs: retain approval client consumer procedure return
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-10 12:48:38 +02:00
parent 67c5a7a508
commit d3a502b45c
2 changed files with 24 additions and 1 deletions

View file

@ -5,7 +5,7 @@ request_type: workload-kv-read
title: secrets-engine client-side read of its approval client secret title: secrets-engine client-side read of its approval client secret
status: in_flight status: in_flight
created: '2026-09-09' created: '2026-09-09'
updated: '2026-09-09' updated: '2026-09-10'
in_flight: in_flight:
missing_fields: missing_fields:
- openbao.auth - openbao.auth
@ -51,6 +51,21 @@ review:
makes this an attended operator-workstation lane on the OIDC mount, not an makes this an attended operator-workstation lane on the OIDC mount, not an
External Secrets lane. The named operator group claim is the one input External Secrets lane. The named operator group claim is the one input
neither this repo nor secrets-engine can supply; NetKingdom/KeyCape own it. neither this repo nor secrets-engine can supply; NetKingdom/KeyCape own it.
- at: '2026-09-10'
reviewer: codex (consumer source review)
decision: consumer_procedure_documented
comment: >-
Secrets Engine source 98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93,
docs/approval-service-auth.md, supplies the requested workstation
procedure: operator-owned 0700 runtime session directory outside Git,
new 0600 file, path-only configuration across one claim/consume operation,
EXIT/INT/TERM cleanup, and explicit residual-file handling after a hard
interruption. The consumer checks file permissions/location/non-emptiness;
creation, parent custody and removal remain attended responsibilities.
No automatic cleanup or live read proof is claimed. This documents the
consumer return; it is not platform-operator/secrets-engine-owner approval,
group confirmation or authority to apply the role. Existing activation
conditions and in_flight status remain.
target: target:
domain: financials domain: financials
tenant: platform tenant: platform

View file

@ -308,6 +308,14 @@ from NetKingdom/KeyCape, then reviewed attended file delivery and its scoped
positive/negative proof. Completed CCR-2026-0017/0018 remain closed. T06 stays positive/negative proof. Completed CCR-2026-0017/0018 remain closed. T06 stays
`wait`; its historical two-reader notes below are superseded for reader 2. `wait`; its historical two-reader notes below are superseded for reader 2.
Consumer procedure returned in source, 2026-09-10:
`secrets-engine@98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93:docs/approval-service-auth.md`
specifies the requested private 0700 runtime directory, 0600 file outside Git,
path-only use, claim/consume lifetime and attended cleanup including hard-stop
residual inspection. CCR-2026-0019 retains this source-review comment without
changing admission status. Exact group, required-owner review, attended apply and
native positive/negative/cleanup evidence remain. No role or credential changed.
Separate retained owner decision: KeyCape's 2026-09-10 return Separate retained owner decision: KeyCape's 2026-09-10 return
`21427688-725f-4dea-aab4-7c78fd4328d2` identifies the already-live, unpresented `21427688-725f-4dea-aab4-7c78fd4328d2` identifies the already-live, unpresented
CCR-2026-0018 registration. Approval Engine, KeyCape and Platform must explicitly CCR-2026-0018 registration. Approval Engine, KeyCape and Platform must explicitly