Implement attended Railiance Clock host key delivery
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
codex 2026-09-15 23:00:20 +02:00
parent 3b11773469
commit e70ef2f32a
7 changed files with 284 additions and 49 deletions

View file

@ -0,0 +1,36 @@
# Railiance Clock attended host delivery — CCR-2026-0028
The operator approved CCR-2026-0028 for both platform and Clock ownership, then
accepted the correction to systemd host delivery. Kubernetes is present on
Railiance01, but this authority runs as a host service and needs no Kubernetes
identity or standing OpenBao read grant.
Ansible's `railiance_clock_prepare_only=true` prepares the nologin system account,
root-owned installation directory, and service-owned mode-0700 state directory.
It does not require a key or activate the authority.
Run the committed `scripts/railiance_clock_custody.py --receipt <new-private-file>`
inside `warden access openbao-platform-admin-login --exec -- python3 ...`.
The helper requires the exact approved CCR, a non-root platform-admin session
from auth/netkingdom, and enabled audit. It generates an ES256 key in memory,
creates the exact KV path with CAS zero, and verifies version 1 before delivery.
No workload policy or role is created. SSH uses strict known-host verification;
the receiver writes a complete mode-0600 file atomically to
`/var/lib/railiance-clock/signing.pem`, owned by `railiance-clock`, and refuses to
overwrite any different existing key. Only public-key metadata enters the receipt.
If custody succeeded and host delivery failed, inspect the receipt stage/version.
Use `--resume-version 1` through a fresh attended envelope to deliver that same
initial version. This never creates or rotates a key. A changed custody version,
existing different host key, or permission drift requires reconciliation.
After successful delivery, Ansible uses `railiance_clock_key_preinstalled=true`,
checks private key metadata, installs the pinned wheel and health probe, and
starts the localhost-only authority. `railiance_clock_private_key_source` is not
needed in this mode. Readiness and independent signature verification are required
before marking the CCR verified. No client trust is inferred from readiness.
Rotation is a separate explicit operation: stop the authority, CAS against the
known current custody version, replace the host key atomically, and distribute
new public key/epoch trust before resuming clients. This initial-admission helper
deliberately does not implement rotation or overwrite keys.