railiance-platform/docs/net-kingdom-credential-custody-contract.md
codex f607d747da
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Draft NetKingdom credential custody contract
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
2026-08-23 21:48:29 +02:00

2.1 KiB

NetKingdom credential custody contract

Status: draft / blocked pending OpenBao owner confirmation Incident: KEYCAPE-EXPOSURE-20260823-01 Consumer procedure: NetKingdom NK-WP-0033, resolver reconciliation revision eec7007 / checkout f2e578c

This document defines the Railiance-side contract without containing or deriving any credential value. It is not an authorization to fetch, export, apply, or rotate a secret.

Ownership

  • railiance-platform owns OpenBao custody, policy, delivery, rotation metadata, and revocation evidence.
  • net-kingdom owns the privacyIDEA resolver contract and attended consumer reconciliation.
  • ops-warden routes the lane only; it does not fetch or proxy either value.

Required OpenBao metadata (owner must fill, never guess)

Lane Canonical path Field Delivery Status
net-kingdom-lldap-bind-credential REQUIRED_FROM_OPENBAO_OWNER REQUIRED_FROM_OPENBAO_OWNER protected attended input to NetKingdom resolver helper blocked
net-kingdom-privacyidea-admin-token REQUIRED_FROM_OPENBAO_OWNER REQUIRED_FROM_OPENBAO_OWNER protected attended input to provider-admin helper blocked

The owner receipt must also identify the KV mount/version semantics, the least-privilege read/update policy, the authentication method, the expiry or rotation behavior, and the approved attended handoff. No value belongs in this file, State Hub, Git, chat, argv, or ordinary logs.

Consumer handoff

Once the OpenBao owner supplies the metadata above, Railiance-platform records the receipt identifier and passes only protected input to the pinned NetKingdom procedure. The resolver repair must use the minimal two-input --reconcile flow; audit proofs (lookup, MFA, predecessor denial) remain a separate read-only operation.

Current gate

The routing lane is registered but remains resolvable: false. No warden access --fetch, proxy execution, resolver retry, or predecessor restoration is authorized until the OpenBao owner publishes the missing metadata and the attended handoff is approved.