fix: require signature invalidation in live rotation acceptance
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Multi-Context Image / build-and-push (push) Successful in 31s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
This commit is contained in:
tegwick 2026-09-05 18:30:49 +02:00
parent 29428bb304
commit 022cf4b727
3 changed files with 36 additions and 7 deletions

View file

@ -43,16 +43,16 @@ priority: high
state_hub_task_id: "55b32d0d-d30a-50c2-bae0-d6e3a357e6d1"
```
Fresh live flex-auth -> access-engine preflight returns exactly the
`preflight_signing_unavailable` blocker. Target is primary/railiance01,
Before activation, the live flex-auth -> access-engine preflight returned
exactly the `preflight_signing_unavailable` blocker. Target is primary/railiance01,
namespace/release/deployment state-hub, current API SA state-hub and one replica.
After platform custody verification, enable the chart, prove API-only delivery,
all-replica key equality, health and non-mutating signed preflight. Then stop all
API replicas (including terminating pods), rotate with CAS through platform,
wait ESO, restart and prove predecessor invalidation and forward recovery.
Runbook: railiance-platform/docs/credential-lane-designs/state-hub-preflight-activation.md.
No repository rename is in scope. Live completion is pending attended OpenBao
OIDC/MFA; ambient session returned 403.
No repository rename is in scope. Initial activation required attended OpenBao
OIDC/MFA because the ambient session returned 403; completion is recorded below.
Completed 2026-09-05 under the user's instruction to lead activation from
@ -69,3 +69,9 @@ Evidence is owned by platform:
`railiance-platform/docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json`.
Protected predecessor fixture removed after verification. No residual scope;
the consuming FLEX-WP-0020 cutover remains separately governed.
Independent review reverified the new API replica against the materialized key
and the predecessor captured before rotation. The verifier now rejects expiry
as sufficient rotation evidence and also requires primary/railiance01 health.
Receipt: `docs/evidence/STATE-WP-0088-independent-signing-verification-20260905.json`.
The private predecessor token was removed after this verification.