Attended helper returned applied, KV version 1, ESO synced, KeyCape ready. No sitting POST. CCRs 0026/0027 are applied metadata only. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
110 lines
4.6 KiB
YAML
110 lines
4.6 KiB
YAML
id: CCR-2026-0026
|
|
kind: credential-change-request
|
|
schema_version: 1
|
|
request_type: workload-kv-read
|
|
title: Informed Decision sitting-requester KeyCape verifier custody
|
|
status: applied
|
|
created: '2026-09-15'
|
|
updated: '2026-09-15'
|
|
requester:
|
|
agent: grok
|
|
reason: INFD-WP-0002-T03 requested a create-only sitting presenter whose binding.actor
|
|
is informed-decision. Allocate a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025
|
|
or platform/workloads/secrets-engine/approval-requester.
|
|
review:
|
|
required: true
|
|
required_approvers:
|
|
- platform-operator
|
|
- key-cape-owner
|
|
comments:
|
|
- at: '2026-09-15'
|
|
reviewer: operator instruction in Grok session
|
|
decision: allocated
|
|
comment: Operator selected allocation of the sitting-requester CCR pair. Source
|
|
only. No OpenBao apply, no secret seed, no KeyCape registration, and no sitting
|
|
POST from this allocation.
|
|
- at: '2026-09-15'
|
|
reviewer: User (platform-operator; key-cape-owner)
|
|
decision: approved
|
|
comment: User instructed register sitting-requester. Apply remains the attended
|
|
helper with CAS=0 custody, exact create-only client, and no sitting POST.
|
|
target:
|
|
domain: financials
|
|
tenant: platform
|
|
workload: informed-decision
|
|
environment: production
|
|
purpose: create-only sitting requester KeyCape verifier custody; approval:create
|
|
only; subject informed-decision; audience approval-engine.
|
|
openbao:
|
|
mount: platform
|
|
kv_path: platform/workloads/informed-decision/sitting-requester
|
|
fields:
|
|
- CLIENT_SECRET
|
|
policy_name: workload-kv-read-keycape-informed-decision-sitting-requester
|
|
policy_file: openbao/policies/workload-kv-read-keycape-informed-decision-sitting-requester.hcl
|
|
auth:
|
|
method: kubernetes
|
|
mount: kubernetes
|
|
role: external-secrets-keycape-informed-decision-sitting-requester
|
|
bound_claims:
|
|
service_account_names:
|
|
- external-secrets
|
|
service_account_namespaces:
|
|
- external-secrets
|
|
bound_claims_confirmed: true
|
|
policies:
|
|
- workload-kv-read-keycape-informed-decision-sitting-requester
|
|
ttl: 15m
|
|
access_frontdoor:
|
|
type: ops-warden
|
|
catalog_id: informed-decision-sitting-requester-login
|
|
selector: Informed Decision create-only sitting requester
|
|
command: warden access informed-decision-sitting-requester-login --exec -- <reviewed-requester-command>
|
|
resolvable: false
|
|
readiness: pending-review
|
|
delivery:
|
|
surface: external-secrets
|
|
target: sso/keycape-informed-decision-sitting-requester-client via ESO; env KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
|
|
risk:
|
|
classification: high
|
|
notes:
|
|
- Credential authenticates only the separate approval:create sitting requester.
|
|
Human disposition remains on the public PKCE client informed-decision-approver.
|
|
- Do not widen CCR-2026-0024/0025 or secrets-engine/approval-requester.
|
|
- No approval, consume, or read scope. No sitting POST until exchange proof exists.
|
|
verification:
|
|
positive:
|
|
- Exact path read of CLIENT_SECRET for the KeyCape verifier ServiceAccount only.
|
|
- Sibling secrets-engine/approval-requester and parent listing denied.
|
|
negative:
|
|
- Approval and consume scopes refused at token exchange; wrong secret refused.
|
|
- Sibling KV paths and parent listing denied.
|
|
activation_conditions:
|
|
- KeyCape row informed-decision-sitting-requester exists and remains unregistered
|
|
until attended CAS=0 custody and exact policy/auth readback.
|
|
- Separate reader verification and no human entry synthesized.
|
|
- No sitting POST until exchange proof exists.
|
|
evidence:
|
|
- at: '2026-09-15T18:28:28+00:00'
|
|
actor: operator via attended sitting-requester custody session
|
|
kind: delegated_metadata_apply
|
|
result: passed
|
|
details:
|
|
- Delegated metadata applier ran as operator via attended sitting-requester custody
|
|
session using local bao CLI ambient authority.
|
|
- 'Policy metadata write: sys/policies/acl/workload-kv-read-keycape-informed-decision-sitting-requester'
|
|
- 'Auth role metadata write: auth/kubernetes/role/external-secrets-keycape-informed-decision-sitting-requester'
|
|
- No secret values were read, written, printed, or accepted in argv.
|
|
lifecycle:
|
|
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
|
|
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025
|
|
and existing consumer/verifier lanes.
|
|
rotate: Rotate through KeyCape and platform using a new version with predecessor
|
|
refusal proof.
|
|
compromised: Disable sitting-requester issuance first; revoke sessions and rotate
|
|
under attended owner authority.
|
|
state_hub:
|
|
workplan_id: RPF-WP-0042
|
|
task_id: RPF-WP-0042-T01
|
|
related_request: CCR-2026-0027
|
|
related_workplan: INFD-WP-0002
|