Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
93 lines
3 KiB
Markdown
93 lines
3 KiB
Markdown
---
|
|
id: RAILIANCE-WP-0029
|
|
type: workplan
|
|
title: "Coordinate KeyCape live Secret exposure recovery"
|
|
domain: financials
|
|
repo: railiance-platform
|
|
status: active
|
|
owner: codex
|
|
topic_slug: railiance
|
|
created: "2026-08-23"
|
|
updated: "2026-08-23"
|
|
related:
|
|
- KEY-WP-0011
|
|
origin: routed
|
|
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4"
|
|
---
|
|
|
|
# RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery
|
|
|
|
## Goal
|
|
|
|
Coordinate a forward-only, value-safe rotation of every credential class in
|
|
the exposed `sso/keycape-config` bundle. Never reproduce or decode the exposed
|
|
payload and never treat repository access as live mutation authority.
|
|
|
|
## T01 — Contain and establish the recovery boundary
|
|
|
|
```task
|
|
id: RAILIANCE-WP-0029-T01
|
|
status: done
|
|
priority: high
|
|
```
|
|
|
|
Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection,
|
|
and routed custody through `warden route show openbao-api-key`. Metadata-only
|
|
preflight pinned Secret UID/resource version, Deployment generation/image, and
|
|
the public JWKS digest/kid. The legacy value-printing rotation helper is banned.
|
|
|
|
## T02 — Publish the governed bundle cutover
|
|
|
|
```task
|
|
id: RAILIANCE-WP-0029-T02
|
|
status: done
|
|
priority: high
|
|
```
|
|
|
|
`docs/keycape-live-secret-exposure-recovery.md` defines owners, required
|
|
revision/window/operator receipts, private-file handling, one guarded bundle
|
|
apply, provider/consumer ordering, forward-only abort, positive/negative proof,
|
|
predecessor revocation, and sanitized evidence.
|
|
|
|
## T03 — Collect exact owner acknowledgements
|
|
|
|
```task
|
|
id: RAILIANCE-WP-0029-T03
|
|
status: progress
|
|
priority: high
|
|
```
|
|
|
|
KeyCape acknowledged emergency rotation with deliberate JWT invalidation and
|
|
JWKS/cache refresh required (message `aeb216b5-9f1b-404b-a483-fb08a00a49b1`),
|
|
but has not yet supplied the non-secret client-config revision or a post-change
|
|
JWKS digest. NetKingdom pinned the value-safe dependency and provider sequence
|
|
at `c24d67b` (message `71b1008a-7fd7-4500-85c6-e8893a6d80d4`), including the
|
|
expiry-based privacyIDEA predecessor decision. The digest-bound approval
|
|
template is published at
|
|
`docs/keycape-exposure-rotation-approval.example.json`; all authorization
|
|
gates remain false pending the missing receipts and an exact human GO.
|
|
|
|
## T04 — Execute the attended rotation
|
|
|
|
```task
|
|
id: RAILIANCE-WP-0029-T04
|
|
status: wait
|
|
priority: high
|
|
```
|
|
|
|
Requires a fresh exact human GO, an at-most-30-minute window, named driver and
|
|
abort operator, approved revisions, provider access, private workspace cleanup,
|
|
and all T03 acknowledgements. No value may enter captured output.
|
|
|
|
## T05 — Prove predecessor denial and close
|
|
|
|
```task
|
|
id: RAILIANCE-WP-0029-T05
|
|
status: wait
|
|
priority: high
|
|
```
|
|
|
|
Verify replacement operation and predecessor rejection for the signing key,
|
|
LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe
|
|
fingerprints, resource versions, public JWKS metadata, boolean results, rollout
|
|
status, timestamps, and cleanup receipts.
|