railiance-platform/workplans/RPF-WP-0029-backup-credential-default-removal.md
repo-manager 708ba5d174
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 20:35:14 +02:00

3.7 KiB

id type title domain repo status owner created updated state_hub_workstream_id
RPF-WP-0029 workplan Remove backup credential default and verify governed replacement financials railiance-platform active codex 2026-09-05 2026-09-05 bb326ebb-a313-549e-b35f-1bf17e1c58fd

Remove backup credential default and verify governed replacement

Source: State Hub message ee702ac9-9118-4b9b-963a-01943052b65a. Reviewed against current repository state on 2026-09-05. Repository implementation is complete; live closure remains pending.

Remove source fallback and verify fail-closed behavior

id: RPF-WP-0029-T01
status: done
priority: high
state_hub_task_id: "4b5aefdb-a746-54f9-ba29-ebb840e7848d"

Removed the literal upload credential default from tools/cmd/forgejo-backup. Missing governed input now fails before cluster operations with a value-free diagnostic; encryption dry-runs skip upload authentication. Offline tests prove missing-input denial, explicit input, and mocked OpenBao resolution.

2026-09-05 continuation: removed credentials and credential-bearing URLs from curl argv; curl config travels through stdin with curlrc disabled. Both upload backends suppress credential-bearing diagnostics, require HTTPS and reject redirects/non-success status. Added transport containment and failure tests.

Invalidate predecessor and prove replacement recovery

id: RPF-WP-0029-T02
status: wait
priority: high
state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8"

Provider-side invalidation and replacement custody need the attended provider owner and CCR-2026-0004 lifecycle procedure. Record only non-secret invalidation, encrypted upload and restore receipts. No provider authority or replacement receipt was available; source removal alone does not close the reported exposure. Never record the predecessor value, fingerprint, length, or shape.

Prepared owner execution procedure: docs/backup-credential-recovery.md. Awaiting the Nextcloud share owner/account and replacement custody coordinates; OpenBao authority is not provider share-management authority. Activity-core is also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical exposure evidence; upload-token rotation cannot clear recovery-key taint. No provider mutation, backup upload or restore has been run in this continuation.

Portfolio review — 2026-09-05

INTENT binding: dependable backup custody and recovery. Retain T02 until the provider owner invalidates the predecessor and supplies replacement upload and restore receipts through CCR-2026-0004. Source removal is already complete. S1 backup scheduling belongs to RAIL-HO-WP-0012; forge backup orchestration and artifact retention belong to railiance-forge. RPF-WP-0036-T06 will obtain an accepted compatibility handoff, but this exposure obligation stays visible here until its evidence is accepted. No rotation was executed in this review.

Move future backups to the dedicated Backup account

id: RPF-WP-0029-T03
status: progress
priority: high
state_hub_task_id: "f85b1b4e-9a20-56e2-9e7d-d1d6f1c77bd9"

User explicitly selected Nextcloud user Backup with 10 GB quota and operator credentials at UI secrets/operators/nextcloud/backup. Live resolution is KVv2 operators/nextcloud/backup, fields BACKUP_USERNAME/BACKUP_PASSWORD. Native WebDAV login verified; actual quota is 10737418240 bytes (10 GiB). Keep the account password in operator custody, create a Backup-owned create-only share for workload delivery, and preserve the existing age escrow and retained data. Prove encrypted upload/download/decryption and workload delivery. No automatic pruning or personal-account revocation is inferred from this account change. The historical predecessor invalidation obligation in T02 remains separate.