diff --git a/intakes/intakes.md b/intakes/intakes.md index 47fb80b..1821dbd 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -76,3 +76,31 @@ description: >- complete, and changing a documented local checkout path ahead of the move would document a path that does not exist yet. Close by updating that one line when flex-auth confirms the rename has landed. + +## SECRETS-IN-0003 — railiance-clock: consumer review of the time-sample profile and adoption condition + +```yaml +id: SECRETS-IN-0003 +kind: intake +title: 'railiance-clock: review signing custody, rotation and lifecycle-consumer adoption condition' +status: open +origin: cross-repo +origin_ref: hub messages f90b9f17 and 302291b5 (railiance-clock, 2026-09-14) +priority: low +owner: secrets-engine +requested_by: railiance-clock +resolution: '' +description: >- + railiance-clock published its foundation (commit 0a144b6, RCLK-WP plans) and a + candidate time-sample profile (commit 7af595b, specs/sample-profile-v0.1.md: + JWS Compact ES256, decimal-string ns, pinned authority/environment/policy, + bounded elapsed intervals). Asked of secrets-engine: review signing custody + and library compatibility for ES256 JWS, rotation/revocation and independent + bootstrap, and return a linked lifecycle/consumer adoption condition + (RCLK-WP-0002-T04, RCLK-WP-0004 propose a future server-side clock contract). + Nothing is adopted or unblocked by it: the existing refusal of shifted + validation clocks stands, and no key, policy or OS clock changed. Recorded at + triage 2026-09-21 and not reviewed there: a custody and adoption review is + owner design work, not a cheap reply. No secret values requested or sent. +``` + diff --git a/workplans/SECRETS-WP-0006-catalog-lane-adoption.md b/workplans/SECRETS-WP-0006-catalog-lane-adoption.md index 3e27a1d..6c9e1c7 100644 --- a/workplans/SECRETS-WP-0006-catalog-lane-adoption.md +++ b/workplans/SECRETS-WP-0006-catalog-lane-adoption.md @@ -199,6 +199,16 @@ priority: high state_hub_task_id: "fb103f1e-2ff7-5de5-9a2c-191a19c43542" ``` +Inbox triage 2026-09-21. railiance-platform `e82bb289` (2026-09-09) answered +the openrouter-llm-connect first-lane request with an explicit **wait on T04 +serving**: no approval object path and no scoped attended authority yet, because +the canonical `action=apply` ActionAuthorization does not exist and llm-connect +has not confirmed ESO health. It accepts the apply shape and rollback +containment in principle, confirms CCR-2026-0003 is provenance and not +executable authorization for a native AppRole, and will name the approval path +and attended window together once T04 serves and llm-connect confirms. Keep +`forgejo-admin-api-token` last. Nothing changes here; T05 stays `wait`. + Progress 2026-09-03. Re-rendered guarded plans on the post-hardening engine. Every admitted lane is still `kv-mount-check` + exact-path read policy + bounded AppRole. First live candidate is `openrouter-llm-connect` (narrowest diff --git a/workplans/SECRETS-WP-0008-layer-model-lifecycle-conformance.md b/workplans/SECRETS-WP-0008-layer-model-lifecycle-conformance.md index 87a0544..abbdd63 100644 --- a/workplans/SECRETS-WP-0008-layer-model-lifecycle-conformance.md +++ b/workplans/SECRETS-WP-0008-layer-model-lifecycle-conformance.md @@ -339,7 +339,22 @@ does not read `BAO_TOKEN` on failure. `--bootstrap-token-file` is a named break-glass provider with `auth_break_glass` evidence. The platform-owned OpenBao JWT mount/role is still unpublished, so auto keeps -bootstrap/env and this task remains `wait`. Companion §7 / statute §3.4: an +bootstrap/env and this task remains `wait`. + +Inbox triage 2026-09-21. railiance-platform `29cccf8a` (2026-09-09): status, +not a contract. Their side is RPF-WP-0035-T02 (design +`docs/credential-lane-designs/secrets-engine-service-jwt.md`), still `wait`. +Designed: role/audience `secrets-engine-openbao`, subject +`service:secrets-engine`, token policy `secrets-engine-login-self`, five-minute +budget, login-only. KeyCape issuer `https://kc.coulomb.social` and its JWKS are +now confirmed live, so the remaining blocker is this registration's issued +claims, consumer readiness, an approved source and attended apply authority. +**Open question for secrets-engine, not answered in the triage session:** the +JWT design says `tenant:coulomb`, while the approval chain resolved to +`tenant:platform` (decision `5ed3fb35`) and approval-engine compares tenant by +exact string. Which tenant the OpenBao service identity carries is a design +decision for an owner session; platform will correct its design before the +role exists once told. A service login grants no lane mutation authority. Companion §7 / statute §3.4: an agent holds no long-lived credential of its own. Authority is per task, time-bounded, and attributable to the principal it acts for.