railiance-platform/credential-change-requests
codex 32d5cf0211
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Prepare the two approval client-side reader admissions
RPF-WP-0035-T06. Adds CCR-2026-0019 (secrets-engine) and CCR-2026-0020
(approval-engine-operator) with their exact-path read policies, reusing the
existing version-1 custody from the verifier activation. No reseed, rotation,
shared reader or verifier Secret reuse; both requests are in_flight and nothing
is applied.

The two shapes were decided by read-only survey rather than assumed.
secrets-engine consumes its client secret through an operator-run CLI reading a
protected file, and its namespace holds no workload, so reader 1 is an attended
operator-workstation OIDC lane rather than an ESO lane; its one missing input is
the operator group claim, which NetKingdom and KeyCape own. approval-engine is
not deployed and no owner source names who presents the operator client, so
reader 2 records the undetermined actor instead of guessing one for the widest
approval scope in the pair. Both declare openbao.auth missing rather than
carrying a placeholder binding.

T06 moves to wait on those two owner inputs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275505@bnt-lap001
Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5
2026-09-09 14:41:01 +02:00
..
CCR-2026-0001-whynot-design-npm-publish.yaml Close delegated prod applier pilot 2026-07-01 23:34:13 +02:00
CCR-2026-0002-issue-core-ingestion-api-key.yaml RAILIANCE-WP-0009/0010 finished: front doors active; WP-0005 T10 done 2026-07-02 20:54:29 +02:00
CCR-2026-0003-llm-connect-openrouter-api-key.yaml RAILIANCE-WP-0009/0010 finished: front doors active; WP-0005 T10 done 2026-07-02 20:54:29 +02:00
CCR-2026-0004-railiance-backup-offsite-lane.yaml Record verified Backup account activation and consumer refresh 2026-09-05 20:50:26 +02:00
CCR-2026-0005-reuse-surface-runtime-secrets-lane.yaml Close three-lane ESO recovery with live verification and cleanup evidence 2026-09-05 19:00:19 +02:00
CCR-2026-0006-forgejo-admin-api-token-lane.yaml Apply CCR-2026-0006 Forgejo admin PAT lane metadata 2026-07-12 16:07:32 +02:00
CCR-2026-0007-binky-company-email-imap.yaml CCR-2026-0007: activate binky IMAP lane after founder provision 2026-07-17 00:33:20 +02:00
CCR-2026-0008-binky-qonto-api.yaml CCR-2026-0008 active: tenants/binky/qonto-api lane live 2026-07-21 21:42:10 +02:00
CCR-2026-0009-qonto-assistant-workload-kv-read.yaml Close RAILIANCE-WP-0015-T06 rapp credential-lane binding 2026-08-14 00:47:28 +02:00
CCR-2026-0010-email-connect-transactional.yaml Close CCR drift and high-risk policy gaps 2026-08-21 01:29:28 +02:00
CCR-2026-0011-scaleway-object-storage-bootstrap.yaml Close CCR drift and high-risk policy gaps 2026-08-21 01:29:28 +02:00
CCR-2026-0012-backup-object-storage.yaml feat: vend platform-pg-backup-s3 via AppRole ESO 2026-08-14 20:00:15 +02:00
CCR-2026-0013-core-hub-runtime-api-token.yaml Finish Core Hub private shadow onboarding 2026-08-21 00:51:06 +02:00
CCR-2026-0014-policy-nexus-forgejo-source-read.yaml Activate Policy Nexus source credential lane 2026-09-01 01:35:48 +02:00
CCR-2026-0015-state-hub-preflight-signing.yaml Complete live State Hub signing activation and rotation acceptance 2026-09-05 18:12:37 +02:00
CCR-2026-0016-glas-claude-anthropic.yaml docs: link Anthropic custody to native delivery adoption 2026-09-06 00:25:06 +02:00
CCR-2026-0017-keycape-secrets-engine-approval-client.yaml feat: verify live KeyCape custody and preserve versions on resume 2026-09-09 02:18:12 +02:00
CCR-2026-0018-keycape-approval-engine-operator-client.yaml feat: verify live KeyCape custody and preserve versions on resume 2026-09-09 02:18:12 +02:00
CCR-2026-0019-secrets-engine-approval-client-read.yaml Prepare the two approval client-side reader admissions 2026-09-09 14:41:01 +02:00
CCR-2026-0020-approval-engine-operator-client-read.yaml Prepare the two approval client-side reader admissions 2026-09-09 14:41:01 +02:00