Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
4.1 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | related | origin | origin_ref | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RAILIANCE-WP-0029 | workplan | Coordinate KeyCape live Secret exposure recovery | financials | railiance-platform | active | codex | railiance | 2026-08-23 | 2026-08-23 |
|
routed | State Hub messages e88abb61-e393-4a82-817c-5ac378a2ee3d, acf98be3-ff6b-4270-bd21-0193bebd806b, aeb216b5-9f1b-404b-a483-fb08a00a49b1, and 71b1008a-7fd7-4500-85c6-e8893a6d80d4 |
RAILIANCE-WP-0029 — KeyCape live Secret exposure recovery
Goal
Coordinate a forward-only, value-safe rotation of every credential class in
the exposed sso/keycape-config bundle. Never reproduce or decode the exposed
payload and never treat repository access as live mutation authority.
T01 — Contain and establish the recovery boundary
id: RAILIANCE-WP-0029-T01
status: done
priority: high
Accepted the KeyCape/NetKingdom incident reports, stopped payload inspection,
and routed custody through warden route show openbao-api-key. Metadata-only
preflight pinned Secret UID/resource version, Deployment generation/image, and
the public JWKS digest/kid. The legacy value-printing rotation helper is banned.
T02 — Publish the governed bundle cutover
id: RAILIANCE-WP-0029-T02
status: done
priority: high
docs/keycape-live-secret-exposure-recovery.md defines owners, required
revision/window/operator receipts, private-file handling, one guarded bundle
apply, provider/consumer ordering, forward-only abort, positive/negative proof,
predecessor revocation, and sanitized evidence.
T03 — Collect exact owner acknowledgements
id: RAILIANCE-WP-0029-T03
status: progress
priority: high
KeyCape supplied source revision 93704fd2424503007c20b458b62a7f7d994bb288,
post-rotation JWKS SHA-256
c6faac5dfeef2453daf9cfc14671f62b535dd321befdf6014e3ee5c2cf1f1156, and
rollout/predecessor evidence (messages 05b49688-76a8-4be9-a00d-95408c798697
and 538046b9-2dbb-4704-b7b6-2dbf16c5e3bb). NetKingdom pinned the value-safe
dependency and provider sequence at c24d67b (message
71b1008a-7fd7-4500-85c6-e8893a6d80d4). The persistent privacyIDEA
lldap-coulomb resolver still requires an attended provider-admin update, so
T04 remains blocked for that explicit follow-up. The digest-bound approval
template is published at
docs/keycape-exposure-rotation-approval.example.json; no additional Secret
apply is authorized by this receipt.
NetKingdom has now pinned the remaining attended resolver procedure at
eec7007 (procedure checkout f2e578c, owner receipt
45b236c8-052f-43d3-a472-44f8e9694da2). It performs one resolver-only POST,
protected interactive inputs, boolean postchecks, replacement-success and
predecessor-denial evidence, and forward-only abort. T03 is ready for the
attended run; T04/T05 remain open until that run produces a sanitized receipt.
The operator completed the resolver-only update and received
privacyIDEA resolver update: PASS. Postchecks were not yet run; the operator
was instructed to stop rather than improvise. NetKingdom has been asked to
package the complete sequence as one receipt-producing command for the next
run.
The Railiance-side custody contract is drafted at
docs/net-kingdom-credential-custody-contract.md. It deliberately leaves the
OpenBao path and field names unfilled pending owner confirmation; the routing
lane remains unresolved and no credential fetch or retry is authorized.
T04 — Execute the attended rotation
id: RAILIANCE-WP-0029-T04
status: wait
priority: high
Requires a fresh exact human GO, an at-most-30-minute window, named driver and abort operator, approved revisions, provider access, private workspace cleanup, and all T03 acknowledgements. No value may enter captured output.
T05 — Prove predecessor denial and close
id: RAILIANCE-WP-0029-T05
status: wait
priority: high
Verify replacement operation and predecessor rejection for the signing key, LLDAP binding, Authelia client, and privacyIDEA token. Retain only safe fingerprints, resource versions, public JWKS metadata, boolean results, rollout status, timestamps, and cleanup receipts.