id: CCR-2026-0015 kind: credential-change-request schema_version: 1 request_type: workload-kv-read title: State Hub repository-rename preflight signing read lane status: approved created: '2026-09-05' updated: '2026-09-05' requester: agent: codex reason: User requested RPF-WP-0035-T04. FLEX-WP-0020-T05 still needs signed State Hub preflight; retirement has not replaced this transitional contract. No repository rename is authorized. review: required: true required_approvers: - platform-operator - state-hub-owner comments: - at: '2026-09-05' reviewer: codex decision: binding_observed comment: 'Live primary/railiance01: namespace/release/deployment state-hub, API SA state-hub, one replica; ESO CRD supports serviceAccountRef.audiences. New dedicated delivery identity requires live acceptance.' - at: '2026-09-05T14:37:03+00:00' reviewer: codex decision: binding_confirmed comment: Live dedicated state-hub/state-hub-preflight-eso ServiceAccount observed; minted subject and audience openbao verified by TokenReview. API workload TokenRequest and ExternalSecret create denied. - at: '2026-09-05T14:37:03+00:00' reviewer: user via RPF-WP-0035-T04 instruction decision: approved comment: User explicitly requested execution of RPF-WP-0035-T04 on 2026-09-05. Scope is the reviewed transitional State Hub signing lane, exact data-only ESO grant and protected CAS writer with controlled-outage rotation acceptance. No repository rename authorized. Operator OIDC remains required. target: domain: infotech tenant: state-hub workload: state-hub-api environment: production purpose: Deliver one HMAC signing key to the transitional State Hub API; no rename execution, general credential vending, or second identity authority. openbao: mount: platform kv_path: platform/workloads/state-hub/repository-rename-preflight fields: - REPOSITORY_RENAME_PREFLIGHT_SECRET metadata_read: false token_self_lifecycle: true policy_name: workload-kv-read-state-hub-rename-preflight policy_file: openbao/policies/workload-kv-read-state-hub-rename-preflight.hcl auth: method: kubernetes mount: kubernetes role: state-hub-rename-preflight-eso bound_claims: service_account_names: - state-hub-preflight-eso service_account_namespaces: - state-hub bound_claims_confirmed: true policies: - workload-kv-read-state-hub-rename-preflight ttl: 15m audience: openbao token_max_ttl: 15m token_explicit_max_ttl: 15m token_no_default_policy: true access_frontdoor: type: external-secrets catalog_id: state-hub-rename-preflight selector: State Hub API preflight signing delivery only readiness: pending-review resolvable: false delivery: surface: external-secrets target: Namespace SecretStore openbao-state-hub-rename-preflight -> ExternalSecret/Secret state-hub-rename-preflight; required explicit API-only secretKeyRef. Owner creation, Retain deletion policy. bootstrap_command: See docs/credential-lane-designs/state-hub-preflight-signing.md; scripts/state_hub_preflight_lane.py stages the attended protected writer separately from this read grant. Owner acceptance and the activation runbook remain pending. risk: classification: high notes: - Signing key permits creation of preflight evidence; raw values and tokens must never enter outputs, Git, or State Hub. - All API replicas must be stopped before rotation; no rolling mixed-key population. A bounded coordination API outage is the fence. - ESO is already a trusted cluster-wide controller; no additional broad RBAC is introduced. - No metadata read, parent list, sibling read or workload write access. verification: positive: - Exact SA/namespace/audience login and native data GET succeed; ESO SecretSynced. - All API replicas load the accepted version; non-mutating signed preflight and health pass. negative: - Wrong SA, namespace and audience fail login; sibling/metadata/write access denied. - Coding-agent deny wins over the new read policy; API SA cannot mint delivery tokens. - Old signed fixture fails after fenced rotation; tamper, expiry, wrong-key and no-key checks fail closed. activation_conditions: - Reviewed source and attended operator identity available. - Demand remains FLEX-WP-0020-T05; target primary/railiance01 and fixture confirmed. - CAS-zero protected generation, exact read grant, and API-only delivery verified. - Controlled-outage fence and recovery exercised before completion. evidence: [] lifecycle: deactivate: Fence API replicas, disable signing binding and ESO role, restart without signing; retain KV history by explicit retention decision. rotate: Stop every API replica and verify no matching pods before CAS rotation; wait ESO, recreate API replicas with one version, verify old token invalidation and health. compromised: Stop every API replica immediately; replace key forward with CAS and restart only after ESO verification. Never restore compromised key material. state_hub: workplan_id: RPF-WP-0035 task_id: RPF-WP-0035-T04