railiance-platform/workplans/RPF-WP-0029-backup-credential-default-removal.md
codex 5ef016be01
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s
Contain backup upload credentials and prepare provider recovery gates
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 19:21:06 +02:00

2.9 KiB

id type title domain repo status owner created updated state_hub_workstream_id
RPF-WP-0029 workplan Remove backup credential default and verify governed replacement financials railiance-platform blocked codex 2026-09-05 2026-09-05 bb326ebb-a313-549e-b35f-1bf17e1c58fd

Remove backup credential default and verify governed replacement

Source: State Hub message ee702ac9-9118-4b9b-963a-01943052b65a. Reviewed against current repository state on 2026-09-05. Repository implementation is complete; live closure remains pending.

Remove source fallback and verify fail-closed behavior

id: RPF-WP-0029-T01
status: done
priority: high
state_hub_task_id: "4b5aefdb-a746-54f9-ba29-ebb840e7848d"

Removed the literal upload credential default from tools/cmd/forgejo-backup. Missing governed input now fails before cluster operations with a value-free diagnostic; encryption dry-runs skip upload authentication. Offline tests prove missing-input denial, explicit input, and mocked OpenBao resolution.

2026-09-05 continuation: removed credentials and credential-bearing URLs from curl argv; curl config travels through stdin with curlrc disabled. Both upload backends suppress credential-bearing diagnostics, require HTTPS and reject redirects/non-success status. Added transport containment and failure tests.

Invalidate predecessor and prove replacement recovery

id: RPF-WP-0029-T02
status: wait
priority: high
state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8"

Provider-side invalidation and replacement custody need the attended provider owner and CCR-2026-0004 lifecycle procedure. Record only non-secret invalidation, encrypted upload and restore receipts. No provider authority or replacement receipt was available; source removal alone does not close the reported exposure. Never record the predecessor value, fingerprint, length, or shape.

Prepared owner execution procedure: docs/backup-credential-recovery.md. Awaiting the Nextcloud share owner/account and replacement custody coordinates; OpenBao authority is not provider share-management authority. Activity-core is also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical exposure evidence; upload-token rotation cannot clear recovery-key taint. No provider mutation, backup upload or restore has been run in this continuation.

Portfolio review — 2026-09-05

INTENT binding: dependable backup custody and recovery. Retain T02 until the provider owner invalidates the predecessor and supplies replacement upload and restore receipts through CCR-2026-0004. Source removal is already complete. S1 backup scheduling belongs to RAIL-HO-WP-0012; forge backup orchestration and artifact retention belong to railiance-forge. RPF-WP-0036-T06 will obtain an accepted compatibility handoff, but this exposure obligation stays visible here until its evidence is accepted. No rotation was executed in this review.