Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2.6 KiB
Audit-core Whitehat E2 credential projection
This is the attended custody procedure for
WH-ENG-20260822-AUDIT-E2-01. It creates two ordinary, tenant-scoped audit-core
sender identities and projects only token-a and token-b into the Whitehat
runner mount. It never returns credential values.
Safety gates
projectis hard-gated to 18:00Z–18:03Z on 2026-08-22. This leaves the remainder of the approved 18:00Z–18:15Z window for the bounded probe and cleanup.- Both audit-core identities carry
expires_at: 2026-08-22T18:15:00Z, checked by the receiver on every authentication. - OpenBao stores the two values at separate engagement paths. The ephemeral ESO policy can read only those paths; it cannot read the full sender registry.
- The generated Kubernetes Secret has exactly
token-aandtoken-band is consumed only through the read-only volume declared by Whitehat. - Cleanup removes identities by exact name, preserving every unrelated sender. It deletes the two KV paths, ESO role/policy, ClusterSecretStore, ExternalSecret, and mounted Secret, then reloads audit-core if required.
Attended sequence
Keep the operator terminal attached from projection through cleanup. The
platform-admin token file must remain outside Git with mode 0600.
python3 scripts/audit-core-whitehat-e2-credentials.py preflight
# Run only after 18:00Z and no later than 18:03Z.
python3 scripts/audit-core-whitehat-e2-credentials.py project \
--confirm WH-ENG-20260822-AUDIT-E2-01:attended
After projection succeeds, Whitehat may apply its approved runner contract and
execute only the invocation recorded in
whitehat-security/engagements/runtime/WH-ENG-20260822-AUDIT-E2-01-invocation.md.
Stop immediately on an engagement abort threshold.
Whether the probe succeeds, fails, or aborts, clean up before 18:15Z:
python3 scripts/audit-core-whitehat-e2-credentials.py cleanup \
--confirm WH-ENG-20260822-AUDIT-E2-01:attended
The command output is a value-safe JSON receipt. Record that receipt, the audit-core rollout/readiness result, the Whitehat runner result, and the absence of the mounted Secret. Never record a bearer, Secret data, sender registry payload, or OpenBao response body.
Abort path
If project fails after changing custody, it invokes the same exact cleanup
automatically. If the process itself is interrupted, run cleanup immediately;
it is idempotent and is allowed before or after the projection window. If
audit-core does not return 1/1 Ready after registry cleanup, do not re-add the
temporary identities—keep the Whitehat Secret absent and escalate the target
recovery separately.