RPF-WP-0035-T06. Adds CCR-2026-0019 (secrets-engine) and CCR-2026-0020 (approval-engine-operator) with their exact-path read policies, reusing the existing version-1 custody from the verifier activation. No reseed, rotation, shared reader or verifier Secret reuse; both requests are in_flight and nothing is applied. The two shapes were decided by read-only survey rather than assumed. secrets-engine consumes its client secret through an operator-run CLI reading a protected file, and its namespace holds no workload, so reader 1 is an attended operator-workstation OIDC lane rather than an ESO lane; its one missing input is the operator group claim, which NetKingdom and KeyCape own. approval-engine is not deployed and no owner source names who presents the operator client, so reader 2 records the undetermined actor instead of guessing one for the widest approval scope in the pair. Both declare openbao.auth missing rather than carrying a placeholder binding. T06 moves to wait on those two owner inputs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB Assistant: claude-code Assistant-Model: opus Assistant-Process: 1275505@bnt-lap001 Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5 |
||
|---|---|---|
| .. | ||
| archived | ||
| .gitkeep | ||
| README.md | ||
| RPF-WP-0015-audit-core-custody-and-recovery-coordination.md | ||
| RPF-WP-0025-openbao-operator-only-access.md | ||
| RPF-WP-0027-keycape-live-secret-exposure-recovery.md | ||
| RPF-WP-0029-backup-credential-default-removal.md | ||
| RPF-WP-0035-credential-lane-implementation.md | ||
| RPF-WP-0036-platform-service-assurance.md | ||
| RPF-WP-0038-forgejo-scaleway-primary-coverage.md | ||
Current platform work
Reviewed 2026-09-06. Seven open workplans: WP-0038 active, six blocked on explicit owner/live
gates; RPF-WP-0036 now has its repository implementation. Completed designs and implementations are
under archived/; their IDs and UUIDs are preserved. The number of blocked
plans is not a count of missing implementations or independent incidents.
| Workplan | Purpose and next gate | S3 boundary |
|---|---|---|
| RPF-WP-0027 | Incident custody and final evidence; accept NetKingdom's residual disposition and publish exact custody handoff | The bundle was already rotated. Provider/MFA reconciliation belongs to NetKingdom. |
| RPF-WP-0029 | Backup cutover and full offsite application recovery complete; old share invalidation receipt remains | S3 retains custody acceptance; S1 and forge own their backup execution. |
| RPF-WP-0025 | Private OpenBao access; fresh attended callback/login then guarded retraction | Coordinate package, issuer, tunnel and DNS owners; keep the window separate. |
| RPF-WP-0015 | Two prepared recovery exercises; registered load driver exists; fresh sender/window/abort approvals and custody readiness remain | S3 contributes lease/ESO and snapshot/unseal proof; S1/S2 and audit-core execute their parts. |
| RPF-WP-0035 | Three remaining lanes: secrets-engine JWT, Fluid operator KV, KeyCape approval clients | Signing T04 is complete; T05 admission answered and awaiting owner approval plus a founder-attended window. |
| RPF-WP-0036 | Implemented local assurance/admission; waits for recurring restore evidence, Q2 reception and owner handoff | Run the assurance commands; live acceptance and external ownership remain gated. |
| RPF-WP-0038 | Native backup, full Scaleway archive recovery and 273 MiB Nextcloud essentials recovery verified; scheduled tier cutover remains | Bind recurring caller/dependencies, verified inventory, quota checks and separate owner retention. |
RPF-WP-0036-T02/T05/T07 are complete; T03/T04/T06 retain the remaining acceptance gates. Treat credential exposure closure as the highest-priority attended work; task order does not combine or waive approvals.
Assessment and disposition of every plan and generated current record index.
Do not recreate completed workplans because an old Hub alias or generated brief still shows them active. Use source IDs, and follow AGENTS.md for verified sync.
Latest closure review
2026-09-05 blocker review: At that review: 12 unfinished tasks across six genuine blocked plans. The September 6 follow-up adds WP-0038 with one remaining full-archive task. All terminal plans have only done/cancel tasks. Completed ESO recovery RPF-WP-0037 is archived. Three retired Hub aliases still appear open; they are a derived-view defect, not three more workplans. Use this file before the dated generated brief.