railiance-platform/credential-change-requests/CCR-2026-0026-informed-decision-sitting-requester-verifier.yaml
codex 50f031091c
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Record sitting-requester custody apply; keep exchange proof open.
Attended helper returned applied, KV version 1, ESO synced, KeyCape
ready. No sitting POST. CCRs 0026/0027 are applied metadata only.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
2026-09-15 20:31:00 +02:00

110 lines
4.6 KiB
YAML

id: CCR-2026-0026
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Informed Decision sitting-requester KeyCape verifier custody
status: applied
created: '2026-09-15'
updated: '2026-09-15'
requester:
agent: grok
reason: INFD-WP-0002-T03 requested a create-only sitting presenter whose binding.actor
is informed-decision. Allocate a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025
or platform/workloads/secrets-engine/approval-requester.
review:
required: true
required_approvers:
- platform-operator
- key-cape-owner
comments:
- at: '2026-09-15'
reviewer: operator instruction in Grok session
decision: allocated
comment: Operator selected allocation of the sitting-requester CCR pair. Source
only. No OpenBao apply, no secret seed, no KeyCape registration, and no sitting
POST from this allocation.
- at: '2026-09-15'
reviewer: User (platform-operator; key-cape-owner)
decision: approved
comment: User instructed register sitting-requester. Apply remains the attended
helper with CAS=0 custody, exact create-only client, and no sitting POST.
target:
domain: financials
tenant: platform
workload: informed-decision
environment: production
purpose: create-only sitting requester KeyCape verifier custody; approval:create
only; subject informed-decision; audience approval-engine.
openbao:
mount: platform
kv_path: platform/workloads/informed-decision/sitting-requester
fields:
- CLIENT_SECRET
policy_name: workload-kv-read-keycape-informed-decision-sitting-requester
policy_file: openbao/policies/workload-kv-read-keycape-informed-decision-sitting-requester.hcl
auth:
method: kubernetes
mount: kubernetes
role: external-secrets-keycape-informed-decision-sitting-requester
bound_claims:
service_account_names:
- external-secrets
service_account_namespaces:
- external-secrets
bound_claims_confirmed: true
policies:
- workload-kv-read-keycape-informed-decision-sitting-requester
ttl: 15m
access_frontdoor:
type: ops-warden
catalog_id: informed-decision-sitting-requester-login
selector: Informed Decision create-only sitting requester
command: warden access informed-decision-sitting-requester-login --exec -- <reviewed-requester-command>
resolvable: false
readiness: pending-review
delivery:
surface: external-secrets
target: sso/keycape-informed-decision-sitting-requester-client via ESO; env KEYCAPE_INFORMED_DECISION_SITTING_REQUESTER_CLIENT_SECRET
risk:
classification: high
notes:
- Credential authenticates only the separate approval:create sitting requester.
Human disposition remains on the public PKCE client informed-decision-approver.
- Do not widen CCR-2026-0024/0025 or secrets-engine/approval-requester.
- No approval, consume, or read scope. No sitting POST until exchange proof exists.
verification:
positive:
- Exact path read of CLIENT_SECRET for the KeyCape verifier ServiceAccount only.
- Sibling secrets-engine/approval-requester and parent listing denied.
negative:
- Approval and consume scopes refused at token exchange; wrong secret refused.
- Sibling KV paths and parent listing denied.
activation_conditions:
- KeyCape row informed-decision-sitting-requester exists and remains unregistered
until attended CAS=0 custody and exact policy/auth readback.
- Separate reader verification and no human entry synthesized.
- No sitting POST until exchange proof exists.
evidence:
- at: '2026-09-15T18:28:28+00:00'
actor: operator via attended sitting-requester custody session
kind: delegated_metadata_apply
result: passed
details:
- Delegated metadata applier ran as operator via attended sitting-requester custody
session using local bao CLI ambient authority.
- 'Policy metadata write: sys/policies/acl/workload-kv-read-keycape-informed-decision-sitting-requester'
- 'Auth role metadata write: auth/kubernetes/role/external-secrets-keycape-informed-decision-sitting-requester'
- No secret values were read, written, printed, or accepted in argv.
lifecycle:
deactivate: Disable the informed-decision-sitting-requester KeyCape registration
and detach only these two sitting-requester reader roles. Preserve CCR-2026-0024/0025
and existing consumer/verifier lanes.
rotate: Rotate through KeyCape and platform using a new version with predecessor
refusal proof.
compromised: Disable sitting-requester issuance first; revoke sessions and rotate
under attended owner authority.
state_hub:
workplan_id: RPF-WP-0042
task_id: RPF-WP-0042-T01
related_request: CCR-2026-0027
related_workplan: INFD-WP-0002