railiance-platform/workplans/RAILIANCE-WP-0029-keycape-live-secret-exposure-recovery.md
codex 7ce3bc8380
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record KeyCape exposure owner receipts
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
2026-08-23 14:37:36 +02:00

93 lines
3 KiB
Markdown

---
id: RAILIANCE-WP-0029
type: workplan
title: "Coordinate KeyCape live Secret exposure recovery"
domain: financials
repo: railiance-platform
status: active
owner: codex
topic_slug: railiance
created: "2026-08-23"
updated: "2026-08-23"
related:
- KEY-WP-0011
origin: routed
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4"
---
# RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery
## Goal
Coordinate a forward-only, value-safe rotation of every credential class in
the exposed `sso/keycape-config` bundle. Never reproduce or decode the exposed
payload and never treat repository access as live mutation authority.
## T01 — Contain and establish the recovery boundary
```task
id: RAILIANCE-WP-0029-T01
status: done
priority: high
```
Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection,
and routed custody through `warden route show openbao-api-key`. Metadata-only
preflight pinned Secret UID/resource version, Deployment generation/image, and
the public JWKS digest/kid. The legacy value-printing rotation helper is banned.
## T02 — Publish the governed bundle cutover
```task
id: RAILIANCE-WP-0029-T02
status: done
priority: high
```
`docs/keycape-live-secret-exposure-recovery.md` defines owners, required
revision/window/operator receipts, private-file handling, one guarded bundle
apply, provider/consumer ordering, forward-only abort, positive/negative proof,
predecessor revocation, and sanitized evidence.
## T03 — Collect exact owner acknowledgements
```task
id: RAILIANCE-WP-0029-T03
status: progress
priority: high
```
KeyCape acknowledged emergency rotation with deliberate JWT invalidation and
JWKS/cache refresh required (message `aeb216b5-9f1b-404b-a483-fb08a00a49b1`),
but has not yet supplied the non-secret client-config revision or a post-change
JWKS digest. NetKingdom pinned the value-safe dependency and provider sequence
at `c24d67b` (message `71b1008a-7fd7-4500-85c6-e8893a6d80d4`), including the
expiry-based privacyIDEA predecessor decision. The digest-bound approval
template is published at
`docs/keycape-exposure-rotation-approval.example.json`; all authorization
gates remain false pending the missing receipts and an exact human GO.
## T04 — Execute the attended rotation
```task
id: RAILIANCE-WP-0029-T04
status: wait
priority: high
```
Requires a fresh exact human GO, an at-most-30-minute window, named driver and
abort operator, approved revisions, provider access, private workspace cleanup,
and all T03 acknowledgements. No value may enter captured output.
## T05 — Prove predecessor denial and close
```task
id: RAILIANCE-WP-0029-T05
status: wait
priority: high
```
Verify replacement operation and predecessor rejection for the signing key,
LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe
fingerprints, resource versions, public JWKS metadata, boolean results, rollout
status, timestamps, and cleanup receipts.