docs: retain approval client consumer procedure return
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
67c5a7a508
commit
d3a502b45c
2 changed files with 24 additions and 1 deletions
|
|
@ -5,7 +5,7 @@ request_type: workload-kv-read
|
||||||
title: secrets-engine client-side read of its approval client secret
|
title: secrets-engine client-side read of its approval client secret
|
||||||
status: in_flight
|
status: in_flight
|
||||||
created: '2026-09-09'
|
created: '2026-09-09'
|
||||||
updated: '2026-09-09'
|
updated: '2026-09-10'
|
||||||
in_flight:
|
in_flight:
|
||||||
missing_fields:
|
missing_fields:
|
||||||
- openbao.auth
|
- openbao.auth
|
||||||
|
|
@ -51,6 +51,21 @@ review:
|
||||||
makes this an attended operator-workstation lane on the OIDC mount, not an
|
makes this an attended operator-workstation lane on the OIDC mount, not an
|
||||||
External Secrets lane. The named operator group claim is the one input
|
External Secrets lane. The named operator group claim is the one input
|
||||||
neither this repo nor secrets-engine can supply; NetKingdom/KeyCape own it.
|
neither this repo nor secrets-engine can supply; NetKingdom/KeyCape own it.
|
||||||
|
- at: '2026-09-10'
|
||||||
|
reviewer: codex (consumer source review)
|
||||||
|
decision: consumer_procedure_documented
|
||||||
|
comment: >-
|
||||||
|
Secrets Engine source 98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93,
|
||||||
|
docs/approval-service-auth.md, supplies the requested workstation
|
||||||
|
procedure: operator-owned 0700 runtime session directory outside Git,
|
||||||
|
new 0600 file, path-only configuration across one claim/consume operation,
|
||||||
|
EXIT/INT/TERM cleanup, and explicit residual-file handling after a hard
|
||||||
|
interruption. The consumer checks file permissions/location/non-emptiness;
|
||||||
|
creation, parent custody and removal remain attended responsibilities.
|
||||||
|
No automatic cleanup or live read proof is claimed. This documents the
|
||||||
|
consumer return; it is not platform-operator/secrets-engine-owner approval,
|
||||||
|
group confirmation or authority to apply the role. Existing activation
|
||||||
|
conditions and in_flight status remain.
|
||||||
target:
|
target:
|
||||||
domain: financials
|
domain: financials
|
||||||
tenant: platform
|
tenant: platform
|
||||||
|
|
|
||||||
|
|
@ -308,6 +308,14 @@ from NetKingdom/KeyCape, then reviewed attended file delivery and its scoped
|
||||||
positive/negative proof. Completed CCR-2026-0017/0018 remain closed. T06 stays
|
positive/negative proof. Completed CCR-2026-0017/0018 remain closed. T06 stays
|
||||||
`wait`; its historical two-reader notes below are superseded for reader 2.
|
`wait`; its historical two-reader notes below are superseded for reader 2.
|
||||||
|
|
||||||
|
Consumer procedure returned in source, 2026-09-10:
|
||||||
|
`secrets-engine@98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93:docs/approval-service-auth.md`
|
||||||
|
specifies the requested private 0700 runtime directory, 0600 file outside Git,
|
||||||
|
path-only use, claim/consume lifetime and attended cleanup including hard-stop
|
||||||
|
residual inspection. CCR-2026-0019 retains this source-review comment without
|
||||||
|
changing admission status. Exact group, required-owner review, attended apply and
|
||||||
|
native positive/negative/cleanup evidence remain. No role or credential changed.
|
||||||
|
|
||||||
Separate retained owner decision: KeyCape's 2026-09-10 return
|
Separate retained owner decision: KeyCape's 2026-09-10 return
|
||||||
`21427688-725f-4dea-aab4-7c78fd4328d2` identifies the already-live, unpresented
|
`21427688-725f-4dea-aab4-7c78fd4328d2` identifies the already-live, unpresented
|
||||||
CCR-2026-0018 registration. Approval Engine, KeyCape and Platform must explicitly
|
CCR-2026-0018 registration. Approval Engine, KeyCape and Platform must explicitly
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue