railiance-platform/credential-change-requests/CCR-2026-0021-approval-engine-audit.yaml
codex b75729b799
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record verified independent factory audit readback
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-11 16:35:14 +02:00

173 lines
8.6 KiB
YAML

id: CCR-2026-0021
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: approval-engine load-bearing audit sender custody and delivery
status: applied
created: '2026-09-11'
updated: '2026-09-11'
requester:
agent: codex
reason: AUDIT-WP-0009-T09 and HFACT-WP-0001-T03 require the existing exact sender
declaration. This request supplies the missing platform custody and ESO delivery;
receiver compatibility and service rollout remain explicit gates.
review:
required: true
required_approvers:
- platform-operator
- audit-core-owner
- approval-engine-owner
comments:
- at: '2026-09-11T04:36:46+00:00'
reviewer: user (platform-operator, audit-core-owner, approval-engine-owner)
decision: approved
comment: User replied "good, go on" on 2026-09-11 to the explicit approval question
for CCR-2026-0021 and CCR-2026-0022 as platform operator and owner of Audit
Core, Approval Engine, and Informed Decision. Record this as approval of the
reviewed exact sender lane. Compatible receiver, namespace readiness, attended
custody and native verification remain prerequisites; no factory execution or
broader grant is admitted.
target:
domain: financials
tenant: platform
workload: approval-engine
environment: production
purpose: Provide only the approval-engine sender with source=approval-engine, tenants=[tenant:platform],
may_write=true, may_read=false, evidence_kind=load-bearing, secret_policy=redact.
Preserve the existing receiver registry and every other sender.
openbao:
mount: platform
kv_path: platform/workloads/approval-engine/audit-sender
fields:
- AUDIT_TOKEN
- CUSTODY_REQUEST
policy_name: workload-kv-read-approval-engine-audit
policy_file: openbao/policies/workload-kv-read-approval-engine-audit.hcl
metadata_read: false
auth:
method: kubernetes
mount: kubernetes
role: external-secrets-approval-engine-audit
bound_claims:
service_account_names:
- external-secrets
service_account_namespaces:
- external-secrets
bound_claims_confirmed: true
policies:
- workload-kv-read-approval-engine-audit
ttl: 15m
access_frontdoor:
type: external-secrets
catalog_id: approval-engine-audit
readiness: pending-review
resolvable: false
delivery:
surface: external-secrets
target: 'ClusterSecretStore openbao-approval-engine-audit restricted to namespace
approval-engine; ExternalSecret and Secret approval-engine/approval-engine-audit,
key audit-token. Source: manifests/factory-audit-senders.yaml. A missing namespace
stays a workload-owner prerequisite; this packet creates none.'
risk:
classification: high
notes:
- A bearer permits append for its exact sender and tenant, never reading or changing
stored evidence.
- The registry update reads existing sender credentials inside the attended platform
process only. No registry is delivered to a producer.
- OpenBao login TTL limits the ESO reader session, not the audit bearer. Revocation
must remove the sender token from the receiver registry and prove refusal.
- New paths extend the existing coding-agent deny boundary. No existing high-risk
grant is widened.
verification:
positive:
- Independent CAS=0 token creation and exact sender merge with registry-version
compare-and-set; repeated runs preserve both tokens and other registry fields.
- ESO delivers only AUDIT_TOKEN into approval-engine/approval-engine-audit:audit-token;
source and receiver copies agree without displaying values.
- Compatible deployed receiver accepts and deduplicates a declared synthetic event
for the exact sender and tenant, retaining load-bearing/redact declarations.
negative:
- Sibling sender path, full registry and parent listing are denied to each workload
reader. Wrong service account/namespace and disallowed store namespace fail.
- Receiver denies sibling source, wrong tenant, every read route and revoked token.
No existing sender is removed or re-scoped.
- Proposed or altered CCR, legacy receiver, malformed/duplicate registry identity,
token collision, stale registry version or partial/conflicting custody refuses
without overwriting.
activation_conditions:
- All three named owner reviews are approved before any native credential mutation.
- A current image supporting evidence_kind is published/admitted by audit-core and
deployed with its source scope and network policy; current c2fe39a image fails
compatibility.
- Use the Warden attended platform-admin login envelope; preserve independent receipt
and revoke the session on exit.
- Apply reviewed policy/auth metadata and ESO projection only after receiver compatibility
and namespace readiness. An interrupted seed resumes from durable KV values, never
blindly rotates or deletes.
- Record native positive/negative evidence before declaring verified or active.
Custody alone does not admit UI, human approval or factory execution.
evidence:
- at: '2026-09-11T07:32:51+00:00'
actor: codex via attended user platform-admin
kind: factory_audit_initial_custody
result: passed
details:
- Both independently generated sender credentials persisted at version 1 with
exact request provenance. Shared registry CAS advanced from version 7 to 8;
existing senders and registry fields preserved.
- 'Attended retry completed with exit 0 and confirmed self-revocation. Receipt:
docs/evidence/2026-09-11-factory-audit-sender-seed.json.'
- 'Status applied: native ESO delivery, scope verification, receiver reload and
producer acceptance remain.'
- at: '2026-09-11T08:30:43+00:00'
actor: codex via attended user platform-admin
kind: factory_audit_native_delivery
result: passed
details:
- Fresh attended retry completed in 28 seconds; wrapper exit 0 and session self-revocation
confirmed. Both exact projections are ESO-owned and match independent version-1
custody.
- Native readers denied sibling, registry, metadata and listing access. Wrong
service account and namespace login failed; disallowed store namespace created
no Secret. Coding-agent deny boundary prevailed. Temporary readers revoked and
namespace deletion verified.
- 'Registry version 8 was delivered exactly before Audit Core reload. Receiver
c82e0442 is Ready and operational/durable. Receipt: docs/evidence/2026-09-11-factory-audit-delivery-live.json.'
- Status remains applied pending native producer accepted/duplicate, source/tenant/read-refusal
and bearer-revocation evidence. Reader-session revocation does not revoke audit
bearer credentials.
- at: '2026-09-11T13:11:08+00:00'
actor: codex via attended user platform-admin
kind: factory_audit_native_producer_and_independent_readback
result: passed
details:
- Native adapters accepted synthetic events (202), retried after process restart
as duplicates (200), reconciled count one and refused wrong source/tenant,
sibling reconciliation, seven read routes and invalid bearers.
- Independent read-only operator found both retained exact source/tenant events;
the 36-event chain is intact. Readback wrapper exit 0 confirms this session
self-revocation and private-helper cleanup; earlier failed-session uncertainty
is not retroactively closed.
- 'Receipt: docs/evidence/2026-09-11-factory-native-readback.json.'
- Status remains applied pending formerly-valid audit-bearer revocation proof.
Invalid-bearer refusal and OpenBao session revocation are distinct checks.
lifecycle:
deactivate: Stop the exact producer; remove only its admitted token from the registry
using CAS and reload/verify receiver refusal. Then detach its reader policy and
remove its ExternalSecret/projection, retaining KV versions for investigation.
Do not delete audit events or other sender entries.
rotate: 'Reviewed overlap-first rotation: append a replacement to this sender only,
deliver it, prove acceptance, then remove the predecessor and prove refusal. The
first-provision helper refuses rotation and unexpected existing values.'
compromised: Stop affected producer and revoke the exact receiver token first; inspect
affected source/tenant events, rotate through a separate reviewed action, and
preserve the independent audit trail.
state_hub:
workplan_id: RPF-WP-0035
task_id: RPF-WP-0035-T08
related_workplan: AUDIT-WP-0009-T09
decision_id: 2c9fe9f0-034a-41d7-9d49-b99df488fdc8
decision_api_url: http://127.0.0.1:8000/decisions/2c9fe9f0-034a-41d7-9d49-b99df488fdc8
decision_resolved_at: '2026-09-11T04:36:46.312720Z'