railiance-platform/workplans/RPF-WP-0032-secrets-engine-service-jwt-design.md
repo-manager 9d958f8e09
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 10:42:02 +02:00

1.5 KiB

id type title domain repo status owner created updated state_hub_workstream_id
RPF-WP-0032 workplan Design secrets-engine service JWT login financials railiance-platform blocked codex 2026-09-05 2026-09-05 bd036850-e1bf-5b70-bbc3-683dfa4b125c

Design secrets-engine service JWT login

Prepare the platform design

id: RPF-WP-0032-T01
status: done
priority: high
state_hub_task_id: "166ece0b-840b-54b8-b10c-45f96eda0429"

Reviewed owner source and the current platform CCR contract. Delivered docs/credential-lane-designs/secrets-engine-service-jwt.md with proposed exact scope, custody, lifecycle, implementation gaps, approval requirements and positive/negative acceptance evidence. This is a completed design deliverable, not a live lane or approval. No secrets accessed, production objects changed or owner messages sent.

Obtain owner inputs and implement the approved lane

id: RPF-WP-0032-T02
status: wait
priority: high
state_hub_task_id: "d1f4a9f6-4ea5-5daa-97bb-039856855bc2"

Confirm issuer, verification endpoint, actual KeyCape registration and live auth mount survey. Approve the login-only role/self policy, implement reviewed declarative support and prove effective-policy, wrong-claim, expiry and cleanup checks. Native lane execution still requires its separate exact authorization and scoped authority.

Review the linked design and pin current source revisions before implementation. Do not interpret this workplan or a proposed coordinate as live authorization.