railiance-platform/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md
codex 7ce3bc8380
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record KeyCape exposure owner receipts
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
2026-08-23 14:37:36 +02:00

3 KiB

id type title domain repo status owner topic_slug created updated related origin origin_ref
RAILIANCE-WP-0029 workplan Coordinate KeyCape live Secret exposure recovery financials railiance-platform active codex railiance 2026-08-23 2026-08-23
KEY-WP-0011
routed State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4

RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery

Goal

Coordinate a forward-only, value-safe rotation of every credential class in the exposed sso/keycape-config bundle. Never reproduce or decode the exposed payload and never treat repository access as live mutation authority.

T01 — Contain and establish the recovery boundary

id: RAILIANCE-WP-0029-T01
status: done
priority: high

Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection, and routed custody through warden route show openbao-api-key. Metadata-only preflight pinned Secret UID/resource version, Deployment generation/image, and the public JWKS digest/kid. The legacy value-printing rotation helper is banned.

T02 — Publish the governed bundle cutover

id: RAILIANCE-WP-0029-T02
status: done
priority: high

docs/keycape-live-secret-exposure-recovery.md defines owners, required revision/window/operator receipts, private-file handling, one guarded bundle apply, provider/consumer ordering, forward-only abort, positive/negative proof, predecessor revocation, and sanitized evidence.

T03 — Collect exact owner acknowledgements

id: RAILIANCE-WP-0029-T03
status: progress
priority: high

KeyCape acknowledged emergency rotation with deliberate JWT invalidation and JWKS/cache refresh required (message aeb216b5-9f1b-404b-a483-fb08a00a49b1), but has not yet supplied the non-secret client-config revision or a post-change JWKS digest. NetKingdom pinned the value-safe dependency and provider sequence at c24d67b (message 71b1008a-7fd7-4500-85c6-e8893a6d80d4), including the expiry-based privacyIDEA predecessor decision. The digest-bound approval template is published at docs/keycape-exposure-rotation-approval.example.json; all authorization gates remain false pending the missing receipts and an exact human GO.

T04 — Execute the attended rotation

id: RAILIANCE-WP-0029-T04
status: wait
priority: high

Requires a fresh exact human GO, an at-most-30-minute window, named driver and abort operator, approved revisions, provider access, private workspace cleanup, and all T03 acknowledgements. No value may enter captured output.

T05 — Prove predecessor denial and close

id: RAILIANCE-WP-0029-T05
status: wait
priority: high

Verify replacement operation and predecessor rejection for the signing key, LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe fingerprints, resource versions, public JWKS metadata, boolean results, rollout status, timestamps, and cleanup receipts.