railiance-platform/workplans/RPF-WP-0029-backup-credential-default-removal.md
codex cb6396caab
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record verified Backup account activation and consumer refresh
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 20:50:26 +02:00

4.3 KiB

id type title domain repo status owner created updated state_hub_workstream_id
RPF-WP-0029 workplan Remove backup credential default and verify governed replacement financials railiance-platform blocked codex 2026-09-05 2026-09-05 bb326ebb-a313-549e-b35f-1bf17e1c58fd

Remove backup credential default and verify governed replacement

Source: State Hub message ee702ac9-9118-4b9b-963a-01943052b65a. Reviewed against current repository state on 2026-09-05. Repository implementation is complete; live closure remains pending.

Remove source fallback and verify fail-closed behavior

id: RPF-WP-0029-T01
status: done
priority: high
state_hub_task_id: "4b5aefdb-a746-54f9-ba29-ebb840e7848d"

Removed the literal upload credential default from tools/cmd/forgejo-backup. Missing governed input now fails before cluster operations with a value-free diagnostic; encryption dry-runs skip upload authentication. Offline tests prove missing-input denial, explicit input, and mocked OpenBao resolution.

2026-09-05 continuation: removed credentials and credential-bearing URLs from curl argv; curl config travels through stdin with curlrc disabled. Both upload backends suppress credential-bearing diagnostics, require HTTPS and reject redirects/non-success status. Added transport containment and failure tests.

Invalidate predecessor and prove replacement recovery

id: RPF-WP-0029-T02
status: wait
priority: high
state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8"

Provider-side invalidation and replacement custody need the attended provider owner and CCR-2026-0004 lifecycle procedure. Record only non-secret invalidation, encrypted upload and restore receipts. No provider authority or replacement receipt was available; source removal alone does not close the reported exposure. Never record the predecessor value, fingerprint, length, or shape.

Prepared owner execution procedure: docs/backup-credential-recovery.md. The dedicated Backup account cutover is complete under T03. Awaiting owner authority for invalidating the old Bernd-owned share and a real offsite restore. Activity-core is also a consumer of this upload lane. Preserve AGE_PRIVATE_KEY and historical exposure evidence; upload-token rotation cannot clear recovery-key taint. T03 proves encrypted fixture transport and decryption; full application restore and historical predecessor invalidation remain open.

Portfolio review — 2026-09-05

INTENT binding: dependable backup custody and recovery. Retain T02 until the provider owner invalidates the predecessor and supplies replacement upload and restore receipts through CCR-2026-0004. Source removal is already complete. S1 backup scheduling belongs to RAIL-HO-WP-0012; forge backup orchestration and artifact retention belong to railiance-forge. RPF-WP-0036-T06 will obtain an accepted compatibility handoff, but this exposure obligation stays visible here until its evidence is accepted. No rotation was executed in this review.

Move future backups to the dedicated Backup account

id: RPF-WP-0029-T03
status: done
priority: high
state_hub_task_id: "f85b1b4e-9a20-56e2-9e7d-d1d6f1c77bd9"

User explicitly selected Nextcloud user Backup with 10 GB quota and operator credentials at UI secrets/operators/nextcloud/backup. Live resolution is KVv2 operators/nextcloud/backup, fields BACKUP_USERNAME/BACKUP_PASSWORD. Native WebDAV login verified; actual quota is 10737418240 bytes (10 GiB). Keep the account password in operator custody, create a Backup-owned create-only share for workload delivery, and preserve the existing age escrow and retained data. Prove encrypted upload/download/decryption and workload delivery. No automatic pruning or personal-account revocation is inferred from this account change. The historical predecessor invalidation obligation in T02 remains separate.

Completed 2026-09-05: Backup-owned share permissions 4; upload HTTP 201, owner download/decryption passed, runtime GET/DELETE denied with HTTP 405. Workload KV CAS 2→3 preserved age escrow. ExternalSecret delivery and all three activity-core deployments verified ready with new credentials loaded. All test fixtures removed. Account quota is enforced by Nextcloud; no automatic pruning. Evidence: docs/evidence/RPF-WP-0029-backup-account-2026-09-05.json.