CCR-2026-0026/0027 are proposed source only: new KV path, no apply, and no widening of 0024/0025. Record destroy-after-confirm for the npm duplicate, coordinated 0018 disablement, blocked historical NetKingdom paths, and no Forgejo retention cutover. Assistant: grok Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
46 lines
1.3 KiB
Markdown
46 lines
1.3 KiB
Markdown
---
|
|
id: RPF-WP-0042
|
|
type: workplan
|
|
title: "Allocate Informed Decision sitting-requester custody"
|
|
domain: financials
|
|
repo: railiance-platform
|
|
status: ready
|
|
flavor: implementation
|
|
owner: grok
|
|
topic_slug: railiance
|
|
created: "2026-09-15"
|
|
updated: "2026-09-15"
|
|
related: [INFD-WP-0002]
|
|
---
|
|
|
|
INFD-WP-0002 requested a create-only KeyCape sitting presenter. Platform
|
|
allocates a new CCR pair. Do not widen CCR-2026-0024, CCR-2026-0025, or
|
|
`platform/workloads/secrets-engine/approval-requester`. No apply, secret seed,
|
|
or sitting POST from allocation.
|
|
|
|
## Allocate the verifier and attended-reader CCR pair
|
|
|
|
```task
|
|
id: RPF-WP-0042-T01
|
|
status: done
|
|
priority: high
|
|
```
|
|
|
|
CCR-2026-0026 (KeyCape ESO verifier) and CCR-2026-0027 (attended OIDC reader)
|
|
use KV `platform/workloads/informed-decision/sitting-requester`, field
|
|
`CLIENT_SECRET` only. Exact-path policies, Kubernetes ESO role, and
|
|
`net-kingdom-admins` reader binding are source-declared. Front door remains
|
|
non-resolvable. ESO projection is unapplied source.
|
|
|
|
## Attended first provision and exchange proof
|
|
|
|
```task
|
|
id: RPF-WP-0042-T02
|
|
status: wait
|
|
priority: high
|
|
```
|
|
|
|
Requires named owner reviews, KeyCape row `informed-decision-sitting-requester`,
|
|
attended CAS=0 custody, exact policy/auth readback, sibling
|
|
`secrets-engine/approval-requester` denial, and create-only token-exchange proof.
|
|
No sitting POST until that proof exists.
|