Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
168 lines
6.8 KiB
Markdown
168 lines
6.8 KiB
Markdown
---
|
|
id: RPF-WP-0027
|
|
type: workplan
|
|
title: "Coordinate KeyCape live Secret exposure recovery"
|
|
domain: financials
|
|
repo: railiance-platform
|
|
status: blocked
|
|
owner: codex
|
|
topic_slug: railiance
|
|
created: "2026-08-23"
|
|
updated: "2026-09-05"
|
|
related:
|
|
- KEY-WP-0011
|
|
origin: routed
|
|
origin_ref: "State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4"
|
|
state_hub_workstream_id: "b2c25a01-4a80-55c1-90cf-8538000f7e0e"
|
|
---
|
|
|
|
# RPF-WP-0027 — KeyCape live Secret exposure recovery
|
|
|
|
## Goal
|
|
|
|
Coordinate a forward-only, value-safe rotation of every credential class in
|
|
the exposed `sso/keycape-config` bundle. Never reproduce or decode the exposed
|
|
payload and never treat repository access as live mutation authority.
|
|
|
|
## T01 — Contain and establish the recovery boundary
|
|
|
|
```task
|
|
id: RPF-WP-0027-T01
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "53f47272-92ab-563b-9d69-5eafee733e6b"
|
|
```
|
|
|
|
Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection,
|
|
and routed custody through `warden route show openbao-api-key`. Metadata-only
|
|
preflight pinned Secret UID/resource version, Deployment generation/image, and
|
|
the public JWKS digest/kid. The legacy value-printing rotation helper is banned.
|
|
|
|
## T02 — Publish the governed bundle cutover
|
|
|
|
```task
|
|
id: RPF-WP-0027-T02
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "3c55b1cd-8f6b-5a48-b416-18ab711954e3"
|
|
```
|
|
|
|
`docs/keycape-live-secret-exposure-recovery.md` defines owners, required
|
|
revision/window/operator receipts, private-file handling, one guarded bundle
|
|
apply, provider/consumer ordering, forward-only abort, positive/negative proof,
|
|
predecessor revocation, and sanitized evidence.
|
|
|
|
## T03 — Collect exact owner acknowledgements
|
|
|
|
```task
|
|
id: RPF-WP-0027-T03
|
|
status: wait
|
|
priority: high
|
|
state_hub_task_id: "714ae011-903d-55e2-ac47-801b8ef879d1"
|
|
```
|
|
|
|
KeyCape supplied source revision `93704fd2424503007c20b458b62a7f7d994bb288`,
|
|
post-rotation JWKS SHA-256
|
|
`c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156`, and
|
|
rollout/predecessor evidence (messages `05b49688-76a8-4be9-a00d-95408c798697`
|
|
and `538046b9-2dbb-4704-b7b6-2dbf16c5e3bb`). NetKingdom pinned the value-safe
|
|
dependency and provider sequence at `c24d67b` (message
|
|
`71b1008a-7fd7-4500-85c6-e8893a6d80d4`). The persistent privacyIDEA
|
|
`lldap-coulomb` resolver still requires an attended provider-admin update, so
|
|
T04 remains blocked for that explicit follow-up. The digest-bound approval
|
|
template is published at
|
|
`docs/keycape-exposure-rotation-approval.example.json`; no additional Secret
|
|
apply is authorized by this receipt.
|
|
|
|
NetKingdom has now pinned the remaining attended resolver procedure at
|
|
`eec7007` (procedure checkout `f2e578c`, owner receipt
|
|
`45b236c8-052f-43d3-a472-44f8e9694da2`). It performs one resolver-only POST,
|
|
protected interactive inputs, boolean postchecks, replacement-success and
|
|
predecessor-denial evidence, and forward-only abort. T03 is ready for the
|
|
attended run; T04/T05 remain open until that run produces a sanitized receipt.
|
|
|
|
The operator completed the resolver-only update and received
|
|
`privacyIDEA resolver update: PASS`. Postchecks were not yet run; the operator
|
|
was instructed to stop rather than improvise. NetKingdom has been asked to
|
|
package the complete sequence as one receipt-producing command for the next
|
|
run.
|
|
|
|
The Railiance-side custody contract is drafted at
|
|
`docs/net-kingdom-credential-custody-contract.md`. It deliberately leaves the
|
|
OpenBao path and field names unfilled pending owner confirmation; the routing
|
|
lane remains unresolved and no credential fetch or retry is authorized.
|
|
|
|
## T04 — Execute the attended rotation
|
|
|
|
```task
|
|
id: RPF-WP-0027-T04
|
|
status: done
|
|
priority: high
|
|
state_hub_task_id: "28b31e57-7a76-5100-8a61-9aa87339c5d7"
|
|
```
|
|
|
|
Requires a fresh exact human GO, an at-most-30-minute window, named driver and
|
|
abort operator, approved revisions, provider access, private workspace cleanup,
|
|
and all T03 acknowledgements. No value may enter captured output.
|
|
|
|
## T05 — Prove predecessor denial and close
|
|
|
|
```task
|
|
id: RPF-WP-0027-T05
|
|
status: wait
|
|
priority: high
|
|
state_hub_task_id: "9cb5fa67-012a-58cf-bafb-e7c7d4f9782d"
|
|
```
|
|
|
|
Verify replacement operation and predecessor rejection for the signing key,
|
|
LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe
|
|
fingerprints, resource versions, public JWKS metadata, boolean results, rollout
|
|
status, timestamps, and cleanup receipts.
|
|
|
|
## T06 — Publish the Railiance/OpenBao custody handoff
|
|
|
|
```task
|
|
id: RPF-WP-0027-T06
|
|
status: wait
|
|
priority: high
|
|
state_hub_task_id: "3b9748c4-2906-5ba7-9d34-0a7067a59283"
|
|
```
|
|
|
|
The platform/OpenBao owner must publish a non-secret receipt for both routing
|
|
lanes: canonical mount/path, field name, KV version semantics, least-privilege
|
|
policy and auth method, expiry/rotation/revocation semantics, and the approved
|
|
attended handoff identifier. Do not infer or invent any of these values. After
|
|
publication, update `docs/net-kingdom-credential-custody-contract.md`, ask
|
|
ops-warden to refresh lane resolvability, and pass only protected inputs to
|
|
NetKingdom's minimal resolver reconciliation flow.
|
|
|
|
## Portfolio review — 2026-09-05
|
|
|
|
INTENT binding: secure custody and incident closure. The goal above is historical;
|
|
the remaining platform scope is custody and acceptance of owner evidence.
|
|
|
|
**T04 is complete by existing owner evidence, not by a new action here.**
|
|
`key-cape/workplans/KEY-WP-0011-live-secret-exposure-recovery.md` T02/T03 and
|
|
`net-kingdom/workplans/NK-WP-0033-keycape-secret-exposure-rotation.md` T04
|
|
record the approved 2026-08-23 bundle replacement. Do not repeat that rotation
|
|
merely because this platform task previously remained `wait`.
|
|
|
|
The 2026-08-27 NK-WP-0033-T05 update is newer than the earlier notes above:
|
|
the resolver binding was reconciled, but there is no complete green receipt.
|
|
The predecessor value is unavailable; manual observations are not a recorded
|
|
negative proof. No one should recover or fabricate a predecessor just to make
|
|
a test pass. The incident owner must rule explicitly on the residual evidence
|
|
and acceptable disposition. Overall incident closure remains open.
|
|
|
|
- T03 waits for current NetKingdom/provider evidence disposition and the exact
|
|
platform custody acknowledgements; old procedure acknowledgements exist.
|
|
- T05 waits for the repaired owner command's sanitized receipt and the
|
|
incident owner's explicit disposition of the unavailable predecessor.
|
|
NetKingdom owns resolver/MFA execution (NK-WP-0033-T03/T05); this repo accepts
|
|
custody-related results without taking over the identity provider.
|
|
- T06 waits for confirmed mount/path/fields, writer/reader authority and the
|
|
operator handoff. The existing draft leaves those facts intentionally blank.
|
|
|
|
No new owner acceptance or coordination message is asserted by this review.
|
|
Keep this incident separate from the new-lane queue; broad lane approval cannot
|
|
close an exposure.
|