--- id: RPF-WP-0029 type: workplan title: "Remove backup credential default and verify governed replacement" domain: financials repo: railiance-platform status: blocked owner: codex created: "2026-09-05" updated: "2026-09-05" state_hub_workstream_id: "bb326ebb-a313-549e-b35f-1bf17e1c58fd" --- # Remove backup credential default and verify governed replacement Source: State Hub message `ee702ac9-9118-4b9b-963a-01943052b65a`. Reviewed against current repository state on 2026-09-05. Repository implementation is complete; live closure remains pending. ## Remove source fallback and verify fail-closed behavior ```task id: RPF-WP-0029-T01 status: done priority: high state_hub_task_id: "4b5aefdb-a746-54f9-ba29-ebb840e7848d" ``` Removed the literal upload credential default from tools/cmd/forgejo-backup. Missing governed input now fails before cluster operations with a value-free diagnostic; encryption dry-runs skip upload authentication. Offline tests prove missing-input denial, explicit input, and mocked OpenBao resolution. ## Invalidate predecessor and prove replacement recovery ```task id: RPF-WP-0029-T02 status: wait priority: high state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8" ``` Provider-side invalidation and replacement custody need the attended provider owner and CCR-2026-0004 lifecycle procedure. Record only non-secret invalidation, encrypted upload and restore receipts. No provider authority or replacement receipt was available; source removal alone does not close the reported exposure. Never record the predecessor value, fingerprint, length, or shape.