Compare commits

...

3 commits

Author SHA1 Message Date
codex
34e78e8937 Review blocked platform obligations and archive completed ESO recovery
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 21:16:53 +02:00
codex
b2c2848e49 feat: verify Anthropic custody through metadata only
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
2026-09-05 21:15:14 +02:00
codex
a16c33942a feat: prepare empty Anthropic custody entry for UI handoff
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
2026-09-05 21:10:43 +02:00
12 changed files with 453 additions and 32 deletions

View file

@ -65,7 +65,7 @@ records every reviewed plan and the consolidation mapping.
| First | Reported credential exposures need final disposition and dependable operator custody | RPF-WP-0027: KeyCape/NetKingdom residual evidence and S3 custody; RPF-WP-0029: provider invalidation and replacement backup recovery |
| First | Private attended OpenBao access remains unproven end to end | RPF-WP-0025-T03; keep its window separate from incident/recovery actions |
| Next | Recovery procedures exist, but two cross-owner exercises still lack completion evidence | RPF-WP-0015-T02/T03: S3 contribution, with audit-core and S1/S2 executing their own parts |
| Next | Three requested credential lanes have designs but no live acceptance | RPF-WP-0035: one queue with separate consumer/issuer/approval gates |
| Next | Signing lane accepted; two requested credential lanes still await live acceptance | RPF-WP-0035: one queue with separate consumer/issuer/approval gates |
| Next | Numeric availability/recovery promises, evidence freshness, recurring drills, emission and admission drift lack a complete S3 acceptance loop | RPF-WP-0036-T02T05 |
| Next | Compatibility ownership, stale Hub aliases, and undeployed capability demand need explicit disposition | RPF-WP-0036-T06/T07 |
@ -120,6 +120,14 @@ legacy aliases are not additional authoritative obligations.
disclosure drift. `make assurance-capture` pins the cluster and collects only
status metadata; `make assurance-check` fails on incomplete/stale/failed evidence.
The first live run found all three database cells Ready with same-day backups
and archiving, but three failing ESO resources. Recurring restore acceptance,
and archiving, and identified three failing ESO resources, since repaired under RPF-WP-0037.
A fresh blocker-review capture confirms healthy database and ESO signals.
Recurring restore acceptance,
validated restore adapters and Q2 delivery remain open. See
[service assurance](docs/service-assurance.md) and RPF-WP-0036.
The dedicated Nextcloud Backup account is active with a 10 GiB provider quota
and a create-only workload share. Encrypted fixture recovery and consumer
refresh are verified; full application restore and predecessor invalidation
remain RPF-WP-0029-T02. See the
[latest blocked-workplan review](history/2026-09-05-blocked-workplan-closure-review.md).

View file

@ -14,7 +14,6 @@
| workplan | RPF-WP-0029 | blocked | — | workplans/RPF-WP-0029-backup-credential-default-removal.md |
| workplan | RPF-WP-0035 | blocked | — | workplans/RPF-WP-0035-credential-lane-implementation.md |
| workplan | RPF-WP-0036 | blocked | — | workplans/RPF-WP-0036-platform-service-assurance.md |
| workplan | RPF-WP-0037 | finished | — | workplans/RPF-WP-0037-eso-static-token-recovery.md |
| task | RPF-WP-0015-T01 | done | — | workplans/RPF-WP-0015-audit-core-custody-and-recovery-coordination.md |
| task | RPF-WP-0015-T02 | wait | — | workplans/RPF-WP-0015-audit-core-custody-and-recovery-coordination.md |
| task | RPF-WP-0015-T03 | wait | — | workplans/RPF-WP-0015-audit-core-custody-and-recovery-coordination.md |
@ -42,6 +41,3 @@
| task | RPF-WP-0036-T05 | done | — | workplans/RPF-WP-0036-platform-service-assurance.md |
| task | RPF-WP-0036-T06 | wait | — | workplans/RPF-WP-0036-platform-service-assurance.md |
| task | RPF-WP-0036-T07 | done | — | workplans/RPF-WP-0036-platform-service-assurance.md |
| task | RPF-WP-0037-T01 | done | — | workplans/RPF-WP-0037-eso-static-token-recovery.md |
| task | RPF-WP-0037-T02 | done | — | workplans/RPF-WP-0037-eso-static-token-recovery.md |
| task | RPF-WP-0037-T03 | done | — | workplans/RPF-WP-0037-eso-static-token-recovery.md |

View file

@ -32,7 +32,7 @@
},
{
"path": "docs/forgejo-backup.md",
"sha256": "69f6f38de902b80c6de161087b1d5738d1dea7ea35b3d49816d2ea67a1a5329b"
"sha256": "af99987e900c8d2322da11c361bac4f1b946a577eed4a93d995cefa31a8e35b5"
},
{
"path": "docs/forgejo-package-prune.md",

View file

@ -10,11 +10,15 @@ in_flight:
missing_fields:
- openbao.policy_file
- openbao.auth
blocking_reason: Anthropic organization and workspace budget await user input; the sandbox owner machine identity and protected delivery path have not been verified. No live grant or key exists from this request.
blocking_reason: User reports key saved through UI; metadata-only owner check confirms
live version 2. Sandbox owner machine identity and protected delivery remain unimplemented;
workspace scope/budget and provider authentication are unverified.
owner: railiance-platform
requester:
agent: codex
reason: User selected a dedicated Anthropic workload API key for GLAS-WP-0012 and SAND-WP-0015. Establish custody and owner delivery before the real local Claude proof.
reason: User selected a dedicated Anthropic workload API key for GLAS-WP-0012 and
SAND-WP-0015. Establish custody and owner delivery before the real local Claude
proof.
review:
required: true
required_approvers:
@ -24,13 +28,21 @@ review:
- at: '2026-09-05'
reviewer: user via chat
decision: authentication_model_selected
comment: User requested establishment of an Anthropic workload API key. This records the chosen authentication model; final machine bindings are not yet known.
comment: User requested establishment of an Anthropic workload API key. This records
the chosen authentication model; final machine bindings are not yet known.
- at: '2026-09-05'
reviewer: user via chat
decision: empty_seed_authorized
comment: User authorized preparing the existing proposed location with an empty
version; user will create a version containing the secret through the OpenBao
UI. No runtime grant authorized by this seed.
target:
domain: infotech
tenant: glas-harness
workload: sand-boxer-claude-agent-dev
environment: production
purpose: Dedicated Claude Code inference for the Glas local agent-dev profile, delivered by the sandbox owner.
purpose: Dedicated Claude Code inference for the Glas local agent-dev profile, delivered
by the sandbox owner.
openbao:
mount: platform
kv_path: platform/workloads/glas-harness/claude-agent-dev
@ -46,34 +58,82 @@ access_frontdoor:
resolvable: false
delivery:
surface: owner-exec
target: Sand-boxer delivers ANTHROPIC_API_KEY only to the selected Claude workload; neither the Glas caller nor the runtime receives an OpenBao token.
target: Sand-boxer delivers ANTHROPIC_API_KEY only to the selected Claude workload;
neither the Glas caller nor the runtime receives an OpenBao token.
risk:
classification: high
notes:
- Proposed KV coordinates and catalog selector are reserved design names, not surveyed live objects.
- Provider credential can incur API charges; use a dedicated workspace and user-selected budget.
- Use a workspace-scoped service account key; organization administration is outside the workload grant.
- OpenBao token expiration does not expire the provider key. Provider revocation is required for compromise.
- Owner environment injection can expose the key to descendants within that workload; it is not per-process secrecy against workload code.
- KV path exists with live version 2. Catalog selector is still proposed and no
runtime read grant has been activated.
- Provider credential can incur API charges; use a dedicated workspace and user-selected
budget.
- Use a workspace-scoped service account key; organization administration is outside
the workload grant.
- OpenBao token expiration does not expire the provider key. Provider revocation
is required for compromise.
- Owner environment injection can expose the key to descendants within that workload;
it is not per-process secrecy against workload code.
verification:
positive:
- Confirm provider organization, workspace, service account, key identifier and expiration using metadata only.
- Exact authenticated sandbox owner can read only the intended data entry and deliver the field without logging it.
- Bounded real Claude proof succeeds through enforced provider egress and removes private state on teardown.
- Confirm provider organization, workspace, service account, key identifier and
expiration using metadata only.
- Exact authenticated sandbox owner can read only the intended data entry and deliver
the field without logging it.
- Bounded real Claude proof succeeds through enforced provider egress and removes
private state on teardown.
negative:
- Wrong owner identity, sibling KV path, metadata read, parent listing and workload writes are denied.
- Wrong owner identity, sibling KV path, metadata read, parent listing and workload
writes are denied.
- Generic coding-agent identity cannot retrieve the credential directly.
- No credential or OpenBao token appears in execution replies, artifacts, source tree or State Hub.
- No credential or OpenBao token appears in execution replies, artifacts, source
tree or State Hub.
- A revoked predecessor provider key fails authentication after controlled rotation.
activation_conditions:
- User confirms Anthropic organization and workspace budget; provider service account and key are created through attended Console custody.
- Confirm actual sandbox host service identity and auth binding; review exact read policy and separate protected custody writer before apply.
- Seed KV with compare-and-set zero through attended custody; never enter values in chat or command arguments.
- Positive and negative access, owner delivery and provider authentication evidence pass before route activation.
- User confirms Anthropic organization and workspace budget; provider service account
and key are created through attended Console custody.
- Confirm actual sandbox host service identity and auth binding; review exact read
policy and separate protected custody writer before apply.
- Seed KV with compare-and-set zero through attended custody; never enter values
in chat or command arguments.
- Positive and negative access, owner delivery and provider authentication evidence
pass before route activation.
evidence:
- at: '2026-09-05'
actor: codex
kind: empty_seed
result: passed
details:
- Empty ANTHROPIC_API_KEY version 1 created with CAS zero; user will create version
2 in UI.
- Request id 50cafc25-8d24-c1d6-5be8-1ade049e088b.
- Provider metadata recorded; metadata-only recovery completed after empty response
parsing fix; contained sessions revoked.
- No secret data read or real key handled; runtime lane remains inactive.
- at: '2026-09-05'
actor: codex
kind: custody_metadata_verification
result: passed
details:
- User reports secret saved in UI. Metadata confirms live version 2 created 2026-09-05T19:12:40.442796563Z,
neither deleted nor destroyed.
- Metadata request id d0b60424-a749-c72f-593b-ced6172dd183; contained session
revoked.
- No value read; field content and provider authentication not verified. Runtime
lane remains inactive.
lifecycle:
deactivate: Disable the owner route and provider key; revoke outstanding OpenBao reader tokens. Preserve KV history under platform retention rules.
rotate: Create a replacement provider key, write with expected-version CAS, stop old runs, verify new delivery and inference, then revoke the predecessor at Anthropic and prove its denial.
compromised: Disable the provider key immediately, stop affected runs and owner route, revoke Bao leases, replace forward through protected custody and record non-secret incident evidence.
deactivate: Disable the owner route and provider key; revoke outstanding OpenBao
reader tokens. Preserve KV history under platform retention rules.
rotate: Create a replacement provider key, write with expected-version CAS, stop
old runs, verify new delivery and inference, then revoke the predecessor at Anthropic
and prove its denial.
compromised: Disable the provider key immediately, stop affected runs and owner
route, revoke Bao leases, replace forward through protected custody and record
non-secret incident evidence.
state_hub:
workplan_id: GLAS-WP-0012
task_id: GLAS-WP-0012-T02
provider_metadata:
organization_id: e1a8f305-9e64-4639-a7fd-af48e34f37c7
key_name: claude_key_bernd.worsch
expires_at: '2027-01-31T21:00:00Z'
source: user supplied; provider identity and workspace scope not independently verified

View file

@ -0,0 +1,168 @@
{
"observation": {
"schema": "railiance-platform.observation.v1",
"cluster_uid": "a553c742-0115-43d4-99a4-a5ca56fe0786",
"captured_at": "2026-09-05T19:13:48.284043+00:00",
"signals": {
"apps-pg.ready": {
"result": "pass",
"observed_at": "2026-09-05T19:13:40.747193+00:00"
},
"apps-pg.backup": {
"result": "pass",
"observed_at": "2026-09-05T02:15:07Z"
},
"apps-pg.wal": {
"result": "pass",
"observed_at": "2026-09-05T19:13:40.747225+00:00"
},
"apps-pg.headroom": {
"result": "pass",
"observed_at": "2026-09-05T19:13:33Z"
},
"platform-pg.ready": {
"result": "pass",
"observed_at": "2026-09-05T19:13:42.890660+00:00"
},
"platform-pg.backup": {
"result": "pass",
"observed_at": "2026-09-05T02:15:11Z"
},
"platform-pg.wal": {
"result": "pass",
"observed_at": "2026-09-05T19:13:42.890688+00:00"
},
"platform-pg.headroom": {
"result": "pass",
"observed_at": "2026-09-05T19:13:30Z"
},
"platform-pg-2.ready": {
"result": "pass",
"observed_at": "2026-09-05T19:13:45.027444+00:00"
},
"platform-pg-2.backup": {
"result": "pass",
"observed_at": "2026-09-05T02:15:08Z"
},
"platform-pg-2.wal": {
"result": "pass",
"observed_at": "2026-09-05T19:13:45.027474+00:00"
},
"platform-pg-2.headroom": {
"result": "pass",
"observed_at": "2026-09-05T19:13:26Z"
},
"openbao.seal": {
"result": "pass",
"observed_at": "2026-09-05T19:13:47.585545+00:00"
},
"eso.ready": {
"result": "pass",
"observed_at": "2026-09-05T19:13:48.284009+00:00"
},
"eso.refresh": {
"result": "pass",
"observed_at": "2026-09-05T18:37:39Z"
}
}
},
"evaluation_at_capture": {
"schema": "railiance-platform.assurance-signal.v1",
"cluster_uid": "a553c742-0115-43d4-99a4-a5ca56fe0786",
"evaluated_at": "2026-09-05T19:13:48.284043+00:00",
"signals": {
"apps-pg.ready": {
"state": "healthy",
"owner": "railiance-platform"
},
"apps-pg.backup": {
"state": "healthy",
"owner": "railiance-platform"
},
"apps-pg.wal": {
"state": "healthy",
"owner": "railiance-platform"
},
"apps-pg.restore": {
"state": "missing",
"owner": "railiance-platform"
},
"apps-pg.headroom": {
"state": "healthy",
"owner": "railiance-platform"
},
"platform-pg.ready": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg.backup": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg.wal": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg.restore": {
"state": "missing",
"owner": "rapp-postgres"
},
"platform-pg.headroom": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg-2.ready": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg-2.backup": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg-2.wal": {
"state": "healthy",
"owner": "rapp-postgres"
},
"platform-pg-2.restore": {
"state": "missing",
"owner": "rapp-postgres"
},
"platform-pg-2.headroom": {
"state": "healthy",
"owner": "rapp-postgres"
},
"openbao.seal": {
"state": "healthy",
"owner": "railiance-platform"
},
"openbao.snapshot": {
"state": "missing",
"owner": "railiance-platform"
},
"openbao.restore": {
"state": "missing",
"owner": "railiance-platform"
},
"offsite.upload": {
"state": "missing",
"owner": "railiance-platform"
},
"offsite.restore": {
"state": "missing",
"owner": "railiance-platform"
},
"eso.ready": {
"state": "healthy",
"owner": "railiance-platform"
},
"eso.refresh": {
"state": "healthy",
"owner": "railiance-platform"
}
},
"transport": "unmonitored",
"guarantees": "unsupported",
"threshold_status": "local-diagnostic-only",
"healthy": false
}
}

View file

@ -47,3 +47,9 @@ owners must first classify current versus obsolete resources, then review
any exact lane repair or retirement. No Secret values were read and no failed
resource was simply excluded to make the aggregate pass. These results do not
by themselves identify a broken provider credential or authorize rotation.
Resolved follow-up: RPF-WP-0037 repaired all three ESO authentication failures
and is archived. The subsequent blocker-review capture verifies ESO readiness
and freshness. No classification or repair request remains for those incidents;
T06 still concerns compatibility ownership and derived-record cleanup.

View file

@ -0,0 +1,82 @@
# Blocked workplan closure review — 2026-09-05
Reviewed all current plans and every archived plan's task status against INTENT,
SCOPE, local evidence, the repository-filtered Hub projection and adjacent owner
records. Six source plans remain blocked, with 12 unfinished tasks. No terminal
plan has unfinished task blocks. There is no evidence to finish another blocked
plan today without additional owner/live acceptance. Reducing the count by
cancelling necessary recovery or custody obligations would misstate completion.
## Completed loose ends removed from the current view
- Archived finished RPF-WP-0037 with all three tasks done; preserved its ID,
UUIDs and evidence. No repeat ESO rotation is needed.
- Corrected signing-lane and Backup-account descriptions in the current index
and SCOPE: RPF-WP-0035-T04 and RPF-WP-0029-T03 are already live-complete.
- Corrected RPF-WP-0015's current blocker: audit-core has implemented and
registered the load driver and proved a local accepted/duplicate round trip.
A new implementation request would duplicate existing work.
- Refreshed the compatibility inventory's hashes after recent documentation
changes. Its retention decision remains valid through 2026-10-05; no owner
acceptance or source transfer is claimed.
## Remaining closure requirements
| Plan / task | Work already complete | Exact remaining result / responsible owner |
| --- | --- | --- |
| 0015 T02 | Reviewed procedure, contained harness, registered audit-core driver | Approved synthetic sender, fresh ≤15-minute window and abort operator; platform lease/ESO recovery plus audit-core retry/readiness proof, accepted by rapp-postgres |
| 0015 T03 | Ordered owner-reviewed outage procedure and contained login repair | Fresh encrypted off-host snapshot, independent quorum/console access, named operators and outage window; S1/S2 execute reboot, S3 proves custody/readiness, audit-core proves application recovery |
| 0025 T03 | Guarded callback/retraction/rollback tooling | Attended loopback callback/login proof, then guarded public-listener retraction and S1 DNS disposition; preserve package/issuer/tunnel boundaries |
| 0027 T03/T05/T06 | KeyCape bundle rotation and provider procedure | NetKingdom's sanitized resolver receipt and incident-owner ruling on unavailable predecessor; confirmed operator custody coordinates and reader/writer handoff. Do not rotate the bundle again or reconstruct exposed values |
| 0029 T02 | Backup-owned create-only share, encrypted fixture recovery, ESO/runtime refresh | Owner invalidation receipt for the old Bernd-owned share plus fetched real-backup application restore. Backup account credentials cannot revoke a different owner's share; existing retained data/key custody must survive |
| 0035 T02 | JWT design and secrets-engine authentication implementation | KeyCape HTTPS issuer/JWKS, accepted exact claims/audience and consumer opt-in; reviewed scoped role, positive/negative/expiry/revocation proof |
| 0035 T03 | Operator matrix design | Accepted tenant/path/fields/capability matrix and IAM assurance binding; then platform validator/executor implementation, consumer CAS/containment and live scoped acceptance |
| 0036 T03 | Local freshness evaluator and recovery procedures | Owner-validated recurring restore/snapshot/offsite receipts and accepted cadence. Synthetic transport recovery does not establish full application recovery |
| 0036 T04 | Metadata producer and repaired ESO delivery | Railiance-telemetry receiving contract, named recipient, controlled failure delivery and missing-emission detection |
| 0036 T06 | Exact inventory and dated retention decision | Accepting compatibility owners/replacement caller proof or renewed retention decision; repo-manager/State Hub repair of retired-alias visibility and regenerated orientation |
These retain six distinct boundaries: recovery exercises, private operator
access, identity incident custody, backup incident recovery, new credential
lanes and recurring service assurance. No further merger removes an underlying
dependency. Application/identity/host execution remains with its existing owner;
S3 retains its acceptance contribution. No coordination messages were sent.
## Fresh read-only operating evidence
`docs/evidence/RPF-blocked-review-2026-09-05.json` pins the railiance01 cluster
and preserves capture-time evaluation. All 15 collected signals are healthy:
readiness, backup, WAL and headroom for three database cells; OpenBao unsealed;
ESO readiness and freshness. The seven absent signals are three database
restores, OpenBao snapshot/restore and offsite upload/restore evidence adapters.
The missing offsite signal is not a failed Backup cutover: its separate receipt
proves a synthetic fixture only and has not been promoted to a real-backup
assurance receipt. Overall assurance remains incomplete and Q2 unmonitored.
## Derived records that inflate the apparent backlog
The repository-filtered Hub read still returns these retired aliases as open:
| Retired alias UUID | Canonical source UUID |
| --- | --- |
| 038bc3c0-4492-5b91-95eb-ae515ca205df | b2c25a01-4a80-55c1-90cf-8538000f7e0e (0027) |
| 6f8a6cbc-c076-5f0a-ade2-281a7ec71360 | 6dda6039-295e-5cac-aef6-3183c3218649 (0025) |
| 88c4ef7f-0af8-580e-90dc-a2bae2675a4d | f4640325-e89c-591d-b58e-ec6b087900ac (0015) |
The installed brief generator queries open rows without filtering these retired
aliases. Regenerating it alone would repeat the defect. Routine exact-commit
reconciliation does not remove the historical rows from this read view. Keep
this scoped owner defect in T06; do not edit managed IDs, blanket-acknowledge
retirements or fabricate file-backed rows. The current workplan README is the
accurate orientation until the owner repairs the read/generator contract.
## Next execution order
First obtain the old-share owner invalidation receipt and execute a real offsite
restore to close 0029; the new account is already operational. Keep the private
OpenBao cutover in its own attended window, especially while other credential
work is active. Resolve the NetKingdom incident evidence disposition separately.
For service assurance, accepted restore adapters/cadence and a Q2 receiver are
the meaningful missing deliverables; another local health checker is unnecessary.
Unrelated in-progress Glas/Anthropic credential files were present at review
start and were excluded from this change.

View file

@ -0,0 +1,69 @@
#!/usr/bin/env python3
"""User-authorized empty KV seed for CCR-2026-0016; silent OIDC child."""
import json
from pathlib import Path
import subprocess
import sys
DATA_PATH = 'platform/data/workloads/glas-harness/claude-agent-dev'
META_PATH = 'platform/metadata/workloads/glas-harness/claude-agent-dev'
RECEIPT = Path('/tmp/glas-anthropic-empty-receipt.json')
def bao(*args, payload=None):
r = subprocess.run(['bao', *args], input=None if payload is None else json.dumps(payload),
text=True, capture_output=True, timeout=30)
if r.returncode:
raise RuntimeError('bao_operation_failed')
return json.loads(r.stdout) if r.stdout.strip() else {}
def main():
if sys.argv[1:] == ['--verify-custody']:
result = bao('read', '-format=json', META_PATH)
observed = result['data']
version = observed.get('current_version', 0)
current = observed.get('versions', {}).get(str(version), {})
if version < 2 or not current or current.get('destroyed') or current.get('deletion_time'):
raise RuntimeError('no_live_successor_version')
# Deliberately exclude arbitrary custom metadata and all data values.
receipt = {'ccr': 'CCR-2026-0016', 'path': META_PATH,
'current_version': version, 'created_time': current.get('created_time'),
'live_successor_observed': True, 'secret_value_read': False,
'provider_authentication_verified': False,
'request_id': result.get('request_id')}
Path('/tmp/glas-anthropic-custody-receipt.json').write_text(json.dumps(receipt))
return
if sys.argv[1:] == ['--complete-metadata']:
receipt = json.loads(RECEIPT.read_text())
if receipt.get('path') != DATA_PATH or receipt.get('version') != 1:
raise RuntimeError('invalid_receipt')
observed = bao('read', '-format=json', META_PATH)['data']
if observed.get('current_version', 0) < 1:
raise RuntimeError('missing_seed')
elif not sys.argv[1:]:
# CAS zero makes concurrent creation and existing versions refuse; no data GET.
result = bao('write', '-format=json', DATA_PATH, '-',
payload={'options': {'cas': 0}, 'data': {'ANTHROPIC_API_KEY': ''}})
version = result['data']['version']
receipt = {'ccr': 'CCR-2026-0016', 'path': DATA_PATH, 'version': version,
'empty_seed_created': True, 'metadata_written': False,
'request_id': result.get('request_id')}
with RECEIPT.open('x') as f:
json.dump(receipt, f)
else:
raise RuntimeError('invalid_arguments')
# Only non-secret custom metadata. No secret expiry is enforced by KV metadata.
bao('write', '-format=json', META_PATH, '-', payload={'custom_metadata': {
'ccr': 'CCR-2026-0016', 'custody_owner': 'railiance-platform',
'provider': 'anthropic', 'organization_id': 'e1a8f305-9e64-4639-a7fd-af48e34f37c7',
'provider_key_name': 'claude_key_bernd.worsch',
'provider_expires_at': '2027-01-31T21:00:00Z',
'seed_version': '1', 'seed_contains_secret': 'false',
'handoff': 'operator creates next version in UI; runtime lane remains inactive'}})
receipt['metadata_written'] = True
RECEIPT.write_text(json.dumps(receipt))
if __name__ == '__main__':
try:
main()
except Exception:
sys.exit(1) # contained executor must never return provider/client output

View file

@ -8,10 +8,10 @@ plans is not a count of missing implementations or independent incidents.
| Workplan | Purpose and next gate | S3 boundary |
| --- | --- | --- |
| [RPF-WP-0027](RPF-WP-0027-keycape-live-secret-exposure-recovery.md) | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. |
| [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup credential exposure; attended provider invalidation and replacement recovery receipts | S3 retains custody acceptance; S1 and forge own their backup execution. |
| [RPF-WP-0029](RPF-WP-0029-backup-credential-default-removal.md) | Backup account cutover complete; old share invalidation and full offsite application restore remain | S3 retains custody acceptance; S1 and forge own their backup execution. |
| [RPF-WP-0025](RPF-WP-0025-openbao-operator-only-access.md) | Private OpenBao access; fresh attended callback/login then guarded retraction | Coordinate package, issuer, tunnel and DNS owners; keep the window separate. |
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; fresh synthetic-load/outage approvals and custody readiness | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | One implementation queue for secrets-engine JWT, Fluid operator KV and preflight signing | Three independent task gates; no new approval inherited from the completed designs. |
| [RPF-WP-0015](RPF-WP-0015-audit-core-custody-and-recovery-coordination.md) | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
| [RPF-WP-0035](RPF-WP-0035-credential-lane-implementation.md) | Two remaining lanes: secrets-engine JWT and Fluid operator KV | Signing T04 is complete; JWT and Fluid retain separate issuer/consumer gates. |
| [RPF-WP-0036](RPF-WP-0036-platform-service-assurance.md) | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining
@ -23,3 +23,11 @@ and [generated current record index](../WORK-RECORDS.md).
Do not recreate completed workplans because an old Hub alias or generated brief
still shows them active. Use source IDs, and follow AGENTS.md for verified sync.
## Latest closure review
[2026-09-05 blocker review](../history/2026-09-05-blocked-workplan-closure-review.md):
12 unfinished tasks across six genuine blocked plans. All terminal plans have
only done/cancel tasks. Completed ESO recovery RPF-WP-0037 is archived.
Three retired Hub aliases still appear open; they are a derived-view defect,
not three more workplans. Use this file before the dated generated brief.

View file

@ -336,3 +336,14 @@ containment defect; the next attempt still needs current acceptance evidence.
Do not create another platform-owned whole-host drill or duplicate these live
tasks in RPF-WP-0036; that plan owns recurring service assurance.
## Blocker recheck — 2026-09-05
AUDIT-WP-0008-T07 already records the synthetic-load driver at `8c8bcf4`,
candidate receipt `7879bf65-06b7-4d0c-bbd1-873b6d20b7fc` and SHA-256
`941ba251f638869626b06e9cbf430c70188c0bdf4715e3eff9c7610366f68662`.
It also records a local accepted/duplicate HTTP round trip. Driver construction
is no longer missing. T02 waits on its separately approved sender identity,
fresh bounded window, abort operator and live recovery receipt. Local driver
success does not prove lease revocation/ESO recovery. T03 remains a separate
outage exercise; no historical window or terminal NO-GO may be reused.

View file

@ -229,3 +229,16 @@ negative checks and repeated refresh passed, obsolete invalid delivery tokens
were removed, and all 27 ExternalSecrets now report Ready. The earlier dated
assurance snapshot is retained as historical evidence. T04 still waits on the
accepted Q2 receiver and controlled failure/absence transport proof.
## Blocker closure review — 2026-09-05
Fresh metadata capture verified all 15 collected signals healthy; seven recovery
signals remain absent from the evaluator. RPF-WP-0037 is archived. The completed
Backup account fixture proof remains separate from a full backup/restore receipt.
T03/T04 remain waiting on recovery evidence/cadence and Q2 delivery respectively.
T06's source inventory hashes were refreshed; its dated retention decision is
unchanged. A repo-filtered Hub read confirms three retired aliases still appear
open. The installed generator would reproduce them; exact UUID mapping and
remaining owner requirements are persisted in
`history/2026-09-05-blocked-workplan-closure-review.md`. No duplicate recovery,
monitoring or owner-transfer workplan was created.