--- id: RPF-WP-0025 type: workplan title: "Retract public OpenBao listener behind operator-only access" domain: financials repo: railiance-platform status: blocked owner: codex topic_slug: railiance created: "2026-08-23" updated: "2026-09-06" related: - RMASTER-WP-0020-T09 - RAPP-OPENBAO-WP-0002 state_hub_workstream_id: "6dda6039-295e-5cac-aef6-3183c3218649" --- # RPF-WP-0025 — OpenBao operator-only access ## Goal Implement the S3-owner half of RMASTER-WP-0020-T09 without coupling it to destructive CoulombCore cleanup. ## T01 — Align the retained compatibility source ```task id: RPF-WP-0025-T01 status: done priority: high state_hub_task_id: "80f9638f-707f-5038-bc77-5962b535949e" ``` The retained platform manifest now matches the canonical package posture: Deployment plus ClusterIP Service only. Ordinary deploy no longer applies the public-only middleware. The old Ingress remains solely in an explicitly named rollback artifact. ## T02 — Add guarded retraction and rollback ```task id: RPF-WP-0025-T02 status: done priority: high state_hub_task_id: "685aba0f-2594-5b99-903a-8c9cd16f6539" ``` `scripts/openbao-public-listener-transition.sh` pins the cluster UID, verifies source and runtime packet posture, requires a lifecycle-healthy named tunnel, and gates live deletion on exact confirmation plus attended-login verification. It deletes only the Ingress and provides an exact rollback path. ## T03 — Complete the attended operator cutover ```task id: RPF-WP-0025-T03 status: wait priority: high state_hub_task_id: "8850d742-7cd7-5a1b-ba52-4dbc4bdeba7e" ``` KeyCape revision `d150be1` now admits exactly `http://127.0.0.1:18200/ui/vault/auth/netkingdom/oidc/callback` in the source-owned `openbao-admin` client and pins it in configuration tests. The OpenBao `auth/netkingdom/role/platform-admin` role must still independently admit that exact callback, and an attended MFA login must pass. The host-namespace preflight already proves `openbao-ui-railiance01` lifecycle-healthy and reaches the expected overlay. Then execute the guarded retraction, coordinate public DNS withdrawal with railiance-infra, and return non-secret acceptance evidence to Railiance Master. Net Kingdom revision `61aeafe` additionally applied the exact KeyCape callback live and proved the public authorization endpoint accepts it. Railiance Platform now carries the silent, narrowly scoped `scripts/openbao-apply-operator-loopback-callback.sh` owner command for the governed `openbao-platform-admin-login` lane. The remaining hold is one attended OIDC/MFA execution of that command followed by one loopback UI login. An attended attempt on 2026-08-23 failed closed before command handoff. Warden contained all login output and did not execute the role update; its cleanup could not confirm self-revocation, so the attempt is terminal NO-GO and must not be treated as callback evidence. No public-listener or OpenBao role change was made. T03 remains `wait` for a fresh attended execution after the operator is ready to complete the browser/MFA act. This workplan authorizes no OpenBao seal/unseal, policy broadening, PVC or Secret mutation, reboot, restore, or RMASTER-WP-0020-T08 cleanup. ## Portfolio review — 2026-09-05 INTENT binding: secure custody and an operable operator access path. Retain T03 as the one attended cutover task; do not merge its approval/window with incident rotation or reboot. Platform owns the exact OpenBao callback and custody acceptance; rapp-openbao owns package exposure, KeyCape/NetKingdom the issuer callback, ops-bridge the tunnel, and S1/S2 DNS/network primitives. Unblock with a fresh attended OIDC/MFA callback update and loopback login, then the guarded retraction and owner-specific DNS handoff. Existing source readiness is not evidence of a completed live cutover. ## Callback preservation repair — 2026-09-06 T03 advanced locally: the attended callback helper now reads and preserves the existing platform-admin role, appends only the exact loopback callback, skips writes when already present, detects observed drift before writing, and verifies all settings on readback. `--check-only` is silent and returns 3 if absent. The role endpoint has no CAS; exclusive attended administration is still needed. Tests cover settings preservation, idempotence, drift, readback failure and unexpected roles. No live role update or ingress retraction was performed in this follow-up; attended loopback UI login remains the cutover gate.