railiance-platform/workplans/RPF-WP-0042-informed-decision-sitting-requester.md
codex be8f18c464
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Close RPF-WP-0042 after sitting-requester exchange proof.
Verified create-only token, sibling deny, and no sitting POST.
Sittings remain INFD-WP-0002.

Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
2026-09-15 20:57:50 +02:00

2.9 KiB

id type title domain repo status flavor owner topic_slug created updated related state_hub_workstream_id
RPF-WP-0042 workplan Allocate Informed Decision sitting-requester custody financials railiance-platform finished implementation grok railiance 2026-09-15 2026-09-15
INFD-WP-0002
8a9a4e03-3500-58bd-ac09-60927dadd6fa

INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or platform/workloads/secrets-engine/approval-requester. No apply, secret seed, or sitting POST from allocation.

Allocate the verifier and attended-reader CCR pair

id: RPF-WP-0042-T01
status: done
priority: high
state_hub_task_id: "448af717-0604-56d7-a0fa-e10e1418b2d9"

CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader) use KV platform/workloads/informed-decision/sitting-requester, field CLIENT_SECRET only. Exact-path policies, Kubernetes ESO role, and net-kingdom-admins reader binding are source-declared. Front door remains non-resolvable. ESO projection is unapplied source.

Attended first provision and exchange proof

id: RPF-WP-0042-T02
status: done
priority: high
state_hub_task_id: "c6fbf99c-de2b-55be-9f0c-58be9fe7c518"

Operator approved CCR-2026-0026/0027 on 2026-09-15. Source registration is in key-cape/config/service-clients.example.yaml. Live apply is the silent helper scripts/provision-sitting-requester.sh through openbao-attended-exec.py. No sitting POST until exchange proof exists. Do not widen CCR-2026-0024/0025.

2026-09-15 attended attempt failed before command handoff: revocation could not be confirmed. Public Ingress is already absent, and the shell still had BAO_ADDR=https://bao.coulomb.social. The wrapper now pins the operator tunnel. Retry that same helper; do not treat this attempt as custody.

Retry 2026-09-15T18:28:25Z succeeded: receipt applied, phase keycape_ready, KV version 1, ESO Ready/SecretSynced, KeyCape single Ready replica, CCRs applied. No sitting POST. Remaining: create-only token-exchange proof (positive create scope, refuse approve/consume, sibling path deny). Evidence: docs/evidence/2026-09-15-sitting-requester-provision.json.

Exchange proof uses reader lane informed-decision-sitting-requester-login and scripts/prove-sitting-requester-exchange.sh. It does not POST sittings.

2026-09-15T18:47Z reader login reached a helper-backed session; the child failed at preflight with no failure class. A first browser sign-in did not complete. Retry records a named failure class, reads KV through bao, and overwrites a failed receipt only.

Retry 2026-09-15T18:56:32Z: receipt verified. Exact KV read, sibling and parent deny, create-only RS256 token, excess scopes refused, wrong secret refused. No sitting POST. Evidence: docs/evidence/2026-09-15-sitting-requester-exchange.json. Platform custody for this client is complete; sittings are INFD-WP-0002.