Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
2.6 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | origin | origin_ref | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RAILIANCE-WP-0029 | workplan | Coordinate KeyCape live Secret exposure recovery | financials | railiance-platform | active | codex | railiance | 2026-08-23 | 2026-08-23 |
|
routed | State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d and acf98be3-ff6b-4270-bd21-0193bebd806b |
RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery
Goal
Coordinate a forward-only, value-safe rotation of every credential class in
the exposed sso/keycape-config bundle. Never reproduce or decode the exposed
payload and never treat repository access as live mutation authority.
T01 — Contain and establish the recovery boundary
id: RAILIANCE-WP-0029-T01
status: done
priority: high
Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection,
and routed custody through warden route show openbao-api-key. Metadata-only
preflight pinned Secret UID/resource version, Deployment generation/image, and
the public JWKS digest/kid. The legacy value-printing rotation helper is banned.
T02 — Publish the governed bundle cutover
id: RAILIANCE-WP-0029-T02
status: done
priority: high
docs/keycape-live-secret-exposure-recovery.md defines owners, required
revision/window/operator receipts, private-file handling, one guarded bundle
apply, provider/consumer ordering, forward-only abort, positive/negative proof,
predecessor revocation, and sanitized evidence.
T03 — Collect exact owner acknowledgements
id: RAILIANCE-WP-0029-T03
status: progress
priority: high
KeyCape must pin the non-secret client-config revision and either a unique-kid overlap implementation or the exact immediate-invalidation/cache-refresh procedure. NetKingdom must pin the LLDAP, Authelia, and privacyIDEA provider steps. Railiance-platform must then issue one digest-bound approval template.
T04 — Execute the attended rotation
id: RAILIANCE-WP-0029-T04
status: wait
priority: high
Requires a fresh exact human GO, an at-most-30-minute window, named driver and abort operator, approved revisions, provider access, private workspace cleanup, and all T03 acknowledgements. No value may enter captured output.
T05 — Prove predecessor denial and close
id: RAILIANCE-WP-0029-T05
status: wait
priority: high
Verify replacement operation and predecessor rejection for the signing key, LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe fingerprints, resource versions, public JWKS metadata, boolean results, rollout status, timestamps, and cleanup receipts.