railiance-platform/workplans/RPF-WP-0029-backup-credential-default-removal.md
codex 0349a08e1b
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Harden backup credentials and add durable image inventory publication
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 01:53:24 +02:00

36 lines
1.4 KiB
Markdown

---
id: RPF-WP-0029
type: workplan
title: "Remove backup credential default and verify governed replacement"
domain: financials
repo: railiance-platform
status: blocked
owner: codex
created: "2026-09-05"
updated: "2026-09-05"
---
# Remove backup credential default and verify governed replacement
Source: State Hub message `ee702ac9-9118-4b9b-963a-01943052b65a`. Reviewed against current repository state
on 2026-09-05. Repository implementation is complete; live closure remains pending.
## Remove source fallback and verify fail-closed behavior
```task
id: RPF-WP-0029-T01
status: done
priority: high
```
Removed the literal upload credential default from tools/cmd/forgejo-backup. Missing governed input now fails before cluster operations with a value-free diagnostic; encryption dry-runs skip upload authentication. Offline tests prove missing-input denial, explicit input, and mocked OpenBao resolution.
## Invalidate predecessor and prove replacement recovery
```task
id: RPF-WP-0029-T02
status: wait
priority: high
```
Provider-side invalidation and replacement custody need the attended provider owner and CCR-2026-0004 lifecycle procedure. Record only non-secret invalidation, encrypted upload and restore receipts. No provider authority or replacement receipt was available; source removal alone does not close the reported exposure. Never record the predecessor value, fingerprint, length, or shape.