railiance-platform/credential-change-requests/CCR-2026-0023-keycape-factor-read.yaml
codex 2e2c31d237
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
KeyCape factor custody acceptance / acceptance (push) Successful in 7s
Establish scoped KeyCape factor custody and verified automatic renewal
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
2026-09-13 16:25:33 +02:00

94 lines
3.3 KiB
YAML

id: CCR-2026-0023
kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: KeyCape realm-scoped factor credential delivery
status: active
created: '2026-09-13'
updated: '2026-09-13'
requester:
agent: codex
reason: User authorized establishing provider credential custody and delivery for
platform P05; RPF-WP-0040 and KEY-WP-0035.
review:
required: true
required_approvers:
- platform-operator
comments:
- at: '2026-09-13T00:00:00+00:00'
reviewer: user (platform operator)
decision: approved
comment: User offered administrative authentication and replied "ok, lets do that"
to establishing credential storage and delivery. Exact dedicated path, least-privilege
workload binding and secret-free attended execution implement that authorized
scope. Provider recovery and policy acceptance remain separate gates.
target:
domain: infotech
tenant: platform
workload: key-cape
environment: production
purpose: Deliver only a provider-issued coulomb factor-read JWT to KeyCape, separating
it from issuer credentials and signing keys.
openbao:
mount: platform
kv_path: platform/workloads/net-kingdom/keycape-factor-read
fields:
- TOKEN
- EXPIRES_AT
policy_name: workload-kv-read-keycape-factor-read
policy_file: openbao/policies/workload-kv-read-keycape-factor-read.hcl
metadata_read: true
token_self_lifecycle: true
auth:
method: kubernetes
mount: kubernetes
role: keycape-factor-workload-kv-read
bound_claims:
service_account_names:
- keycape-factor-eso
service_account_namespaces:
- sso
bound_claims_confirmed: true
policies:
- workload-kv-read-keycape-factor-read
ttl: 15m
access_frontdoor:
type: external-secrets
catalog_id: keycape-factor-read
readiness: ready
resolvable: true
delivery:
surface: external-secrets
target: Namespace-restricted ClusterSecretStore openbao-keycape-factor-read -> sso/keycape-factor-read
Secret admin-token. Mount only the JWT in KeyCape; provider password remains in
separate custody.
risk:
classification: high
notes:
- JWT can list factors only in coulomb; enforce provider policy before activation.
- OpenBao TTL does not renew or revoke the privacyIDEA JWT.
- No personal admin credentials delivered to the issuer.
verification:
positive:
- Exact metadata readback and correct-SA Kubernetes login.
- Provider-issued JWT accepted and projected file reread after renewal.
negative:
- Sibling KV paths and writes denied; wrong SA or namespace cannot authenticate.
- Provider mutation permission denied and expired credential fails closed.
activation_conditions:
- Attended metadata apply and exact readback.
- Dedicated provider identity with verified rights/expiry and separate renewable
custody.
- Native delivery and positive/negative factor lookup evidence.
evidence:
- docs/evidence/2026-09-13-keycape-factor-custody.md
lifecycle:
deactivate: Detach reader role, stop renewal and revoke/expire provider token; preserve
custody history.
rotate: Issue replacement before expiry, CAS update exact KV, verify ESO projection
and consumer acceptance; retain no plaintext artifacts.
compromised: Disable the dedicated provider principal and reconcile JWT revocation
or expiry before recovery.
state_hub:
workplan_id: RPF-WP-0040
task_id: RPF-WP-0040-T01