Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
94 lines
3.3 KiB
YAML
94 lines
3.3 KiB
YAML
id: CCR-2026-0023
|
|
kind: credential-change-request
|
|
schema_version: 1
|
|
request_type: workload-kv-read
|
|
title: KeyCape realm-scoped factor credential delivery
|
|
status: active
|
|
created: '2026-09-13'
|
|
updated: '2026-09-13'
|
|
requester:
|
|
agent: codex
|
|
reason: User authorized establishing provider credential custody and delivery for
|
|
platform P05; RPF-WP-0040 and KEY-WP-0035.
|
|
review:
|
|
required: true
|
|
required_approvers:
|
|
- platform-operator
|
|
comments:
|
|
- at: '2026-09-13T00:00:00+00:00'
|
|
reviewer: user (platform operator)
|
|
decision: approved
|
|
comment: User offered administrative authentication and replied "ok, lets do that"
|
|
to establishing credential storage and delivery. Exact dedicated path, least-privilege
|
|
workload binding and secret-free attended execution implement that authorized
|
|
scope. Provider recovery and policy acceptance remain separate gates.
|
|
target:
|
|
domain: infotech
|
|
tenant: platform
|
|
workload: key-cape
|
|
environment: production
|
|
purpose: Deliver only a provider-issued coulomb factor-read JWT to KeyCape, separating
|
|
it from issuer credentials and signing keys.
|
|
openbao:
|
|
mount: platform
|
|
kv_path: platform/workloads/net-kingdom/keycape-factor-read
|
|
fields:
|
|
- TOKEN
|
|
- EXPIRES_AT
|
|
policy_name: workload-kv-read-keycape-factor-read
|
|
policy_file: openbao/policies/workload-kv-read-keycape-factor-read.hcl
|
|
metadata_read: true
|
|
token_self_lifecycle: true
|
|
auth:
|
|
method: kubernetes
|
|
mount: kubernetes
|
|
role: keycape-factor-workload-kv-read
|
|
bound_claims:
|
|
service_account_names:
|
|
- keycape-factor-eso
|
|
service_account_namespaces:
|
|
- sso
|
|
bound_claims_confirmed: true
|
|
policies:
|
|
- workload-kv-read-keycape-factor-read
|
|
ttl: 15m
|
|
access_frontdoor:
|
|
type: external-secrets
|
|
catalog_id: keycape-factor-read
|
|
readiness: ready
|
|
resolvable: true
|
|
delivery:
|
|
surface: external-secrets
|
|
target: Namespace-restricted ClusterSecretStore openbao-keycape-factor-read -> sso/keycape-factor-read
|
|
Secret admin-token. Mount only the JWT in KeyCape; provider password remains in
|
|
separate custody.
|
|
risk:
|
|
classification: high
|
|
notes:
|
|
- JWT can list factors only in coulomb; enforce provider policy before activation.
|
|
- OpenBao TTL does not renew or revoke the privacyIDEA JWT.
|
|
- No personal admin credentials delivered to the issuer.
|
|
verification:
|
|
positive:
|
|
- Exact metadata readback and correct-SA Kubernetes login.
|
|
- Provider-issued JWT accepted and projected file reread after renewal.
|
|
negative:
|
|
- Sibling KV paths and writes denied; wrong SA or namespace cannot authenticate.
|
|
- Provider mutation permission denied and expired credential fails closed.
|
|
activation_conditions:
|
|
- Attended metadata apply and exact readback.
|
|
- Dedicated provider identity with verified rights/expiry and separate renewable
|
|
custody.
|
|
- Native delivery and positive/negative factor lookup evidence.
|
|
evidence:
|
|
- docs/evidence/2026-09-13-keycape-factor-custody.md
|
|
lifecycle:
|
|
deactivate: Detach reader role, stop renewal and revoke/expire provider token; preserve
|
|
custody history.
|
|
rotate: Issue replacement before expiry, CAS update exact KV, verify ESO projection
|
|
and consumer acceptance; retain no plaintext artifacts.
|
|
compromised: Disable the dedicated provider principal and reconcile JWT revocation
|
|
or expiry before recovery.
|
|
state_hub:
|
|
workplan_id: RPF-WP-0040
|
|
task_id: RPF-WP-0040-T01
|