railiance-platform/credential-change-requests/CCR-2026-0025-t03-requester-reader.yaml
codex 703d552ee7
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Provision scoped T03 requester custody and native requests
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
2026-09-14 02:47:32 +02:00

115 lines
4.4 KiB
YAML

id: CCR-2026-0025
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: T03 create-only requester attended operator reader
status: applied
created: '2026-09-14'
updated: '2026-09-14'
requester:
agent: codex
reason: User instructed completion of SECRETS-WP-0010-T03 and explicitly confirmed
its scoped human review mandate. A separate create-only requester is required;
the withdrawn combined operator client remains unused.
review:
required: true
required_approvers:
- platform-operator
- secrets-engine-owner
comments:
- at: '2026-09-14'
reviewer: operator instruction in Codex session
decision: approved
comment: Necessary implementation of the user-authorized T03 completion. Exact
requester has only approval:create, subject secrets-engine matching the existing
evaluator actor, audience approval-engine, tenant:platform, lifetime 15m. No
approval, consume, provider-key access or model-spending scope. Separate reader
and verifier remain exact to this new path; no old credential or registration
is widened.
target:
domain: financials
tenant: platform
workload: secrets-engine
environment: production
purpose: T03 create-only requester attended operator reader; execute only the three
fixed T03 request records.
openbao:
mount: platform
kv_path: platform/workloads/secrets-engine/approval-requester
fields:
- CLIENT_SECRET
policy_name: workload-kv-read-secrets-engine-requester-client
policy_file: openbao/policies/workload-kv-read-secrets-engine-requester-client.hcl
auth:
method: oidc
mount: netkingdom
role: secrets-engine-requester-workload-kv-read
allowed_redirect_uris:
- https://bao.coulomb.social/ui/vault/auth/netkingdom/oidc/callback
- http://localhost:8250/oidc/callback
- http://127.0.0.1:8250/oidc/callback
oidc_scopes:
- openid
- profile
- email
- groups
user_claim: sub
groups_claim: groups
bound_claims:
groups:
- net-kingdom-admins
bound_claims_confirmed: true
policies:
- workload-kv-read-secrets-engine-requester-client
ttl: 15m
access_frontdoor:
type: ops-warden
catalog_id: secrets-engine-requester-login
selector: T03 create-only approval requester
command: warden access secrets-engine-requester-login --exec -- <reviewed-requester-command>
resolvable: false
readiness: pending-review
delivery:
surface: operator-workstation
target: Contained attended reader session; secret stays in memory for native requester
exchange; no retained file or raw output.
risk:
classification: high
notes:
- Credential authenticates only the separate approval:create requester. Human disposition
remains mandatory and uses a different public PKCE client.
- The stable subject secrets-engine matches the existing evaluator and Approval
Engine binding.actor check; it is not an alias for consumer subject service:secrets-engine.
verification:
positive:
- Exact scope and 900-second token lifetime; native create of only the reviewed
three records.
negative:
- Approval and consume scopes refused; sibling KV paths and parent listing denied.
activation_conditions:
- Attended platform authority, CAS=0 custody, exact policy/auth readback and synchronized
verifier delivery.
- Separate reader verification and no human entry synthesized.
evidence:
- at: '2026-09-14T00:23:32+00:00'
actor: operator via attended T03 requester custody session
kind: delegated_metadata_apply
result: passed
details:
- Delegated metadata applier ran as operator via attended T03 requester custody
session using local bao CLI ambient authority.
- 'Policy metadata write: sys/policies/acl/workload-kv-read-secrets-engine-requester-client'
- 'Auth role metadata write: auth/netkingdom/role/secrets-engine-requester-workload-kv-read'
- No secret values were read, written, printed, or accepted in argv.
lifecycle:
deactivate: Disable the secrets-engine-requester KeyCape registration and detach
only the two requester reader roles. Preserve approvals and existing consumer/verifier
lanes.
rotate: Rotate through KeyCape and platform using a new version with predecessor
refusal proof.
compromised: Disable requester issuance first; revoke sessions and rotate under
attended owner authority.
state_hub:
workplan_id: RPF-WP-0035
task_id: RPF-WP-0035-T06
related_request: CCR-2026-0024