railiance-platform/workplans/RPF-WP-0042-informed-decision-sitting-requester.md
codex 4b34c239bc
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Approve sitting-requester CCRs and add the attended provisioner.
CCR-2026-0026/0027 are approved for the create-only informed-decision
client. Live KeyCape registration and CAS=0 custody stay in the
contained helper; no sitting POST.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
2026-09-15 20:08:02 +02:00

49 lines
1.6 KiB
Markdown

---
id: RPF-WP-0042
type: workplan
title: "Allocate Informed Decision sitting-requester custody"
domain: financials
repo: railiance-platform
status: active
flavor: implementation
owner: grok
topic_slug: railiance
created: "2026-09-15"
updated: "2026-09-15"
related: [INFD-WP-0002]
state_hub_workstream_id: "8a9a4e03-3500-58bd-ac09-60927dadd6fa"
---
INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform
allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or
`platform/workloads/secrets-engine/approval-requester`. No apply, secret seed,
or sitting POST from allocation.
## Allocate the verifier and attended-reader CCR pair
```task
id: RPF-WP-0042-T01
status: done
priority: high
state_hub_task_id: "448af717-0604-56d7-a0fa-e10e1418b2d9"
```
CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader)
use KV `platform/workloads/informed-decision/sitting-requester`, field
`CLIENT_SECRET` only. Exact-path policies, Kubernetes ESO role, and
`net-kingdom-admins` reader binding are source-declared. Front door remains
non-resolvable. ESO projection is unapplied source.
## Attended first provision and exchange proof
```task
id: RPF-WP-0042-T02
status: progress
priority: high
state_hub_task_id: "c6fbf99c-de2b-55be-9f0c-58be9fe7c518"
```
Operator approved CCR-2026-0026/0027 on 2026-09-15. Source registration is in
`key-cape/config/service-clients.example.yaml`. Live apply is the silent helper
`scripts/provision-sitting-requester.sh` through `openbao-attended-exec.py`.
No sitting POST until exchange proof exists. Do not widen CCR-2026-0024/0025.