--- id: RPF-WP-0027 type: workplan title: "Coordinate KeyCape live Secret exposure recovery" domain: financials repo: railiance-platform status: blocked flavor: implementation owner: codex topic_slug: railiance created: "2026-08-23" updated: "2026-09-15" related: - KEY-WP-0011 origin: routed origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4" state_hub_workstream_id: "b2c25a01-4a80-55c1-90cf-8538000f7e0e" --- # RPF-WP-0027 — KeyCape live Secret exposure recovery ## Goal Coordinate a forward-only, value-safe rotation of every credential class in the exposed `sso/keycape-config` bundle. Never reproduce or decode the exposed payload and never treat repository access as live mutation authority. ## T01 — Contain and establish the recovery boundary ```task id: RPF-WP-0027-T01 status: done priority: high state_hub_task_id: "53f47272-92ab-563b-9d69-5eafee733e6b" ``` Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection, and routed custody through `warden route show openbao-api-key`. Metadata-only preflight pinned Secret UID/resource version, Deployment generation/image, and the public JWKS digest/kid. The legacy value-printing rotation helper is banned. ## T02 — Publish the governed bundle cutover ```task id: RPF-WP-0027-T02 status: done priority: high state_hub_task_id: "3c55b1cd-8f6b-5a48-b416-18ab711954e3" ``` `docs/keycape-live-secret-exposure-recovery.md` defines owners, required revision/window/operator receipts, private-file handling, one guarded bundle apply, provider/consumer ordering, forward-only abort, positive/negative proof, predecessor revocation, and sanitized evidence. ## T03 — Collect exact owner acknowledgements ```task id: RPF-WP-0027-T03 status: wait priority: high state_hub_task_id: "714ae011-903d-55e2-ac47-801b8ef879d1" ``` KeyCape supplied source revision `93704fd2424503007c20b458b62a7f7d994bb288`, post-rotation JWKS SHA-256 `c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156`, and rollout/predecessor evidence (messages `05b49688-76a8-4be9-a00d-95408c798697` and `538046b9-2dbb-4704-b7b6-2dbf16c5e3bb`). NetKingdom pinned the value-safe dependency and provider sequence at `c24d67b` (message `71b1008a-7fd7-4500-85c6-e8893a6d80d4`). The persistent privacyIDEA `lldap-coulomb` resolver still requires an attended provider-admin update, so T04 remains blocked for that explicit follow-up. The digest-bound approval template is published at `docs/keycape-exposure-rotation-approval.example.json`; no additional Secret apply is authorized by this receipt. NetKingdom has now pinned the remaining attended resolver procedure at `eec7007` (procedure checkout `f2e578c`, owner receipt `45b236c8-052f-43d3-a472-44f8e9694da2`). It performs one resolver-only POST, protected interactive inputs, boolean postchecks, replacement-success and predecessor-denial evidence, and forward-only abort. T03 is ready for the attended run; T04/T05 remain open until that run produces a sanitized receipt. The operator completed the resolver-only update and received `privacyIDEA resolver update: PASS`. Postchecks were not yet run; the operator was instructed to stop rather than improvise. NetKingdom has been asked to package the complete sequence as one receipt-producing command for the next run. The Railiance-side custody contract is drafted at `docs/net-kingdom-credential-custody-contract.md`. It deliberately leaves the OpenBao path and field names unfilled pending owner confirmation; the routing lane remains unresolved and no credential fetch or retry is authorized. ## T04 — Execute the attended rotation ```task id: RPF-WP-0027-T04 status: done priority: high state_hub_task_id: "28b31e57-7a76-5100-8a61-9aa87339c5d7" ``` Requires a fresh exact human GO, an at-most-30-minute window, named driver and abort operator, approved revisions, provider access, private workspace cleanup, and all T03 acknowledgements. No value may enter captured output. ## T05 — Prove predecessor denial and close ```task id: RPF-WP-0027-T05 status: wait priority: high state_hub_task_id: "9cb5fa67-012a-58cf-bafb-e7c7d4f9782d" ``` Verify replacement operation and predecessor rejection for the signing key, LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe fingerprints, resource versions, public JWKS metadata, boolean results, rollout status, timestamps, and cleanup receipts. ## T06 — Publish the Railiance/OpenBao custody handoff ```task id: RPF-WP-0027-T06 status: wait priority: high state_hub_task_id: "3b9748c4-2906-5ba7-9d34-0a7067a59283" ``` The platform/OpenBao owner must publish a non-secret receipt for both routing lanes: canonical mount/path, field name, KV version semantics, least-privilege policy and auth method, expiry/rotation/revocation semantics, and the approved attended handoff identifier. Do not infer or invent any of these values. After publication, update `docs/net-kingdom-credential-custody-contract.md`, ask ops-warden to refresh lane resolvability, and pass only protected inputs to NetKingdom's minimal resolver reconciliation flow. **Operator decision, 2026-09-15:** leave both historical resolver lanes blocked. Do not invent mount/path/field names. The KeyCape factor service lane from RPF-WP-0040 remains the separate active custody; it does not close these incident lanes. ## Portfolio review — 2026-09-05 INTENT binding: secure custody and incident closure. The goal above is historical; the remaining platform scope is custody and acceptance of owner evidence. **T04 is complete by existing owner evidence, not by a new action here.** `key-cape/workplans/KEY-WP-0011-live-secret-exposure-recovery.md` T02/T03 and `net-kingdom/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md` T04 record the approved 2026-08-23 bundle replacement. Do not repeat that rotation merely because this platform task previously remained `wait`. The 2026-08-27 NK-WP-0033-T05 update is newer than the earlier notes above: the resolver binding was reconciled, but there is no complete green receipt. The predecessor value is unavailable; manual observations are not a recorded negative proof. No one should recover or fabricate a predecessor just to make a test pass. The incident owner must rule explicitly on the residual evidence and acceptable disposition. Overall incident closure remains open. - T03 waits for current NetKingdom/provider evidence disposition and the exact platform custody acknowledgements; old procedure acknowledgements exist. - T05 waits for the repaired owner command's sanitized receipt and the incident owner's explicit disposition of the unavailable predecessor. NetKingdom owns resolver/MFA execution (NK-WP-0033-T03/T05); this repo accepts custody-related results without taking over the identity provider. - T06 waits for confirmed mount/path/fields, writer/reader authority and the operator handoff. The existing draft leaves those facts intentionally blank. No new owner acceptance or coordination message is asserted by this review. Keep this incident separate from the new-lane queue; broad lane approval cannot close an exposure.