id: CCR-2026-0023 kind: credential-change-request schema_version: 1 request_type: workload-kv-read title: KeyCape realm-scoped factor credential delivery status: active created: '2026-09-13' updated: '2026-09-13' requester: agent: codex reason: User authorized establishing provider credential custody and delivery for platform P05; RPF-WP-0040 and KEY-WP-0035. review: required: true required_approvers: - platform-operator comments: - at: '2026-09-13T00:00:00+00:00' reviewer: user (platform operator) decision: approved comment: User offered administrative authentication and replied "ok, lets do that" to establishing credential storage and delivery. Exact dedicated path, least-privilege workload binding and secret-free attended execution implement that authorized scope. Provider recovery and policy acceptance remain separate gates. target: domain: infotech tenant: platform workload: key-cape environment: production purpose: Deliver only a provider-issued coulomb factor-read JWT to KeyCape, separating it from issuer credentials and signing keys. openbao: mount: platform kv_path: platform/workloads/net-kingdom/keycape-factor-read fields: - TOKEN - EXPIRES_AT policy_name: workload-kv-read-keycape-factor-read policy_file: openbao/policies/workload-kv-read-keycape-factor-read.hcl metadata_read: true token_self_lifecycle: true auth: method: kubernetes mount: kubernetes role: keycape-factor-workload-kv-read bound_claims: service_account_names: - keycape-factor-eso service_account_namespaces: - sso bound_claims_confirmed: true policies: - workload-kv-read-keycape-factor-read ttl: 15m access_frontdoor: type: external-secrets catalog_id: keycape-factor-read readiness: ready resolvable: true delivery: surface: external-secrets target: Namespace-restricted ClusterSecretStore openbao-keycape-factor-read -> sso/keycape-factor-read Secret admin-token. Mount only the JWT in KeyCape; provider password remains in separate custody. risk: classification: high notes: - JWT can list factors only in coulomb; enforce provider policy before activation. - OpenBao TTL does not renew or revoke the privacyIDEA JWT. - No personal admin credentials delivered to the issuer. verification: positive: - Exact metadata readback and correct-SA Kubernetes login. - Provider-issued JWT accepted and projected file reread after renewal. negative: - Sibling KV paths and writes denied; wrong SA or namespace cannot authenticate. - Provider mutation permission denied and expired credential fails closed. activation_conditions: - Attended metadata apply and exact readback. - Dedicated provider identity with verified rights/expiry and separate renewable custody. - Native delivery and positive/negative factor lookup evidence. evidence: - docs/evidence/2026-09-13-keycape-factor-custody.md lifecycle: deactivate: Detach reader role, stop renewal and revoke/expire provider token; preserve custody history. rotate: Issue replacement before expiry, CAS update exact KV, verify ESO projection and consumer acceptance; retain no plaintext artifacts. compromised: Disable the dedicated provider principal and reconcile JWT revocation or expiry before recovery. state_hub: workplan_id: RPF-WP-0040 task_id: RPF-WP-0040-T01