railiance-platform/docs/net-kingdom-credential-custody-contract.md
codex f607d747da
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Draft NetKingdom credential custody contract
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
2026-08-23 21:48:29 +02:00

45 lines
2.1 KiB
Markdown

# NetKingdom credential custody contract
Status: **draft / blocked pending OpenBao owner confirmation**
Incident: `KEYCAPE-EXPOSURE-20260823-01`
Consumer procedure: NetKingdom `NK-WP-0033`, resolver reconciliation revision
`eec7007` / checkout `f2e578c`
This document defines the Railiance-side contract without containing or
deriving any credential value. It is not an authorization to fetch, export,
apply, or rotate a secret.
## Ownership
- `railiance-platform` owns OpenBao custody, policy, delivery, rotation
metadata, and revocation evidence.
- `net-kingdom` owns the privacyIDEA resolver contract and attended consumer
reconciliation.
- `ops-warden` routes the lane only; it does not fetch or proxy either value.
## Required OpenBao metadata (owner must fill, never guess)
| Lane | Canonical path | Field | Delivery | Status |
| --- | --- | --- | --- | --- |
| `net-kingdom-lldap-bind-credential` | `REQUIRED_FROM_OPENBAO_OWNER` | `REQUIRED_FROM_OPENBAO_OWNER` | protected attended input to NetKingdom resolver helper | blocked |
| `net-kingdom-privacyidea-admin-token` | `REQUIRED_FROM_OPENBAO_OWNER` | `REQUIRED_FROM_OPENBAO_OWNER` | protected attended input to provider-admin helper | blocked |
The owner receipt must also identify the KV mount/version semantics, the
least-privilege read/update policy, the authentication method, the expiry or
rotation behavior, and the approved attended handoff. No value belongs in this
file, State Hub, Git, chat, argv, or ordinary logs.
## Consumer handoff
Once the OpenBao owner supplies the metadata above, Railiance-platform records
the receipt identifier and passes only protected input to the pinned
NetKingdom procedure. The resolver repair must use the minimal two-input
`--reconcile` flow; audit proofs (lookup, MFA, predecessor denial) remain a
separate read-only operation.
## Current gate
The routing lane is registered but remains `resolvable: false`. No
`warden access --fetch`, proxy execution, resolver retry, or predecessor
restoration is authorized until the OpenBao owner publishes the missing
metadata and the attended handoff is approved.