railiance-platform/docs/audit-core-whitehat-e2-credential-projection.md
codex 864cc20b96
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Add attended Whitehat E2 credential projection
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
2026-08-22 12:59:38 +02:00

2.6 KiB
Raw Permalink Blame History

Audit-core Whitehat E2 credential projection

This is the attended custody procedure for WH-ENG-20260822-AUDIT-E2-01. It creates two ordinary, tenant-scoped audit-core sender identities and projects only token-a and token-b into the Whitehat runner mount. It never returns credential values.

Safety gates

  • project is hard-gated to 18:00Z18:03Z on 2026-08-22. This leaves the remainder of the approved 18:00Z18:15Z window for the bounded probe and cleanup.
  • Both audit-core identities carry expires_at: 2026-08-22T18:15:00Z, checked by the receiver on every authentication.
  • OpenBao stores the two values at separate engagement paths. The ephemeral ESO policy can read only those paths; it cannot read the full sender registry.
  • The generated Kubernetes Secret has exactly token-a and token-b and is consumed only through the read-only volume declared by Whitehat.
  • Cleanup removes identities by exact name, preserving every unrelated sender. It deletes the two KV paths, ESO role/policy, ClusterSecretStore, ExternalSecret, and mounted Secret, then reloads audit-core if required.

Attended sequence

Keep the operator terminal attached from projection through cleanup. The platform-admin token file must remain outside Git with mode 0600.

python3 scripts/audit-core-whitehat-e2-credentials.py preflight

# Run only after 18:00Z and no later than 18:03Z.
python3 scripts/audit-core-whitehat-e2-credentials.py project \
  --confirm WH-ENG-20260822-AUDIT-E2-01:attended

After projection succeeds, Whitehat may apply its approved runner contract and execute only the invocation recorded in whitehat-security/engagements/runtime/WH-ENG-20260822-AUDIT-E2-01-invocation.md. Stop immediately on an engagement abort threshold.

Whether the probe succeeds, fails, or aborts, clean up before 18:15Z:

python3 scripts/audit-core-whitehat-e2-credentials.py cleanup \
  --confirm WH-ENG-20260822-AUDIT-E2-01:attended

The command output is a value-safe JSON receipt. Record that receipt, the audit-core rollout/readiness result, the Whitehat runner result, and the absence of the mounted Secret. Never record a bearer, Secret data, sender registry payload, or OpenBao response body.

Abort path

If project fails after changing custody, it invokes the same exact cleanup automatically. If the process itself is interrupted, run cleanup immediately; it is idempotent and is allowed before or after the projection window. If audit-core does not return 1/1 Ready after registry cleanup, do not re-add the temporary identities—keep the Whitehat Secret absent and escalate the target recovery separately.