railiance-platform/credential-change-requests/CCR-2026-0027-informed-decision-sitting-requester-reader.yaml
codex d2dbc19c25 Allocate sitting-requester CCR pair and record operator gates.
CCR-2026-0026/0027 are proposed source only: new KV path, no apply,
and no widening of 0024/0025. Record destroy-after-confirm for the
npm duplicate, coordinated 0018 disablement, blocked historical
NetKingdom paths, and no Forgejo retention cutover.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
2026-09-15 02:08:39 +02:00

103 lines
3.9 KiB
YAML

id: CCR-2026-0027
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Informed Decision sitting-requester attended operator reader
status: proposed
created: '2026-09-15'
updated: '2026-09-15'
requester:
agent: grok
reason: INFD-WP-0002-T03 requested a create-only sitting presenter whose binding.actor
is informed-decision. Allocate a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025
or platform/workloads/secrets-engine/approval-requester.
review:
required: true
required_approvers:
- platform-operator
- key-cape-owner
comments:
- at: '2026-09-15'
reviewer: operator instruction in Grok session
decision: allocated
comment: Operator selected allocation of the sitting-requester CCR pair. Source
only. No OpenBao apply, no secret seed, and no sitting POST from this allocation.
target:
domain: financials
tenant: platform
workload: informed-decision
environment: production
purpose: create-only sitting requester attended operator reader; approval:create
only; subject informed-decision; audience approval-engine.
openbao:
mount: platform
kv_path: platform/workloads/informed-decision/sitting-requester
fields:
- CLIENT_SECRET
policy_name: workload-kv-read-informed-decision-sitting-requester-client
policy_file: openbao/policies/workload-kv-read-informed-decision-sitting-requester-client.hcl
auth:
method: oidc
mount: netkingdom
role: informed-decision-sitting-requester-workload-kv-read
allowed_redirect_uris:
- https://bao.coulomb.social/ui/vault/auth/netkingdom/oidc/callback
- http://localhost:8250/oidc/callback
- http://127.0.0.1:8250/oidc/callback
oidc_scopes:
- openid
- profile
- email
- groups
user_claim: sub
groups_claim: groups
bound_claims:
groups:
- net-kingdom-admins
bound_claims_confirmed: true
policies:
- workload-kv-read-informed-decision-sitting-requester-client
ttl: 15m
access_frontdoor:
type: ops-warden
catalog_id: informed-decision-sitting-requester-login
selector: Informed Decision create-only sitting requester
command: warden access informed-decision-sitting-requester-login --exec -- <reviewed-requester-command>
resolvable: false
readiness: pending-review
delivery:
surface: operator-workstation
target: Contained attended reader session; secret stays in memory for native requester
exchange; no retained file or raw output.
risk:
classification: high
notes:
- Credential authenticates only the separate approval:create sitting requester.
Human disposition remains on the public PKCE client informed-decision-approver.
- Do not widen CCR-2026-0024/0025 or secrets-engine/approval-requester.
- Bound group is net-kingdom-admins, matching CCR-2026-0019/0025 operator binding.
verification:
positive:
- Exact path read of CLIENT_SECRET for the attended operator identity only.
- Sibling secrets-engine/approval-requester and parent listing denied.
negative:
- Approval and consume scopes refused at token exchange; wrong secret refused.
- Sibling KV paths and parent listing denied.
activation_conditions:
- Attended platform authority, CAS=0 custody, exact policy/auth readback and synchronized
verifier delivery.
- Separate reader verification and no human entry synthesized.
- No sitting POST until exchange proof exists.
lifecycle:
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025
and existing consumer/verifier lanes.
rotate: Rotate through KeyCape and platform using a new version with predecessor
refusal proof.
compromised: Disable sitting-requester issuance first; revoke sessions and rotate
under attended owner authority.
state_hub:
workplan_id: RPF-WP-0042
task_id: RPF-WP-0042-T01
related_request: CCR-2026-0026
related_workplan: INFD-WP-0002