state-hub/workplans/STATE-WP-0088-preflight-signing-runtime-acceptance.md
tegwick 022cf4b727
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Multi-Context Image / build-and-push (push) Successful in 31s
fix: require signature invalidation in live rotation acceptance
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
2026-09-05 18:30:49 +02:00

3.5 KiB

id type title domain repo status owner topic_slug created updated related quality_dod quality_dod_note quality_dor quality_dor_note state_hub_workstream_id
STATE-WP-0088 workplan Accept the platform preflight signing lane in the State Hub API infotech state-hub finished codex infotech 2026-09-05 2026-09-05
RPF-WP-0035
STATE-WP-0085
FLEX-WP-0020
DoD-Ok Live API-only signing and fenced CAS rotation accepted; predecessor signature denial and recovered primary health evidenced. No residual implementation work. DoR-Ok Exact platform design and user-requested task reviewed against live primary; bounded API-only delivery and controlled-outage rotation fence. 22f2d7dc-5766-5b09-9f18-12abd4b5512b

Wire and validate API-only delivery

id: STATE-WP-0088-T01
status: done
priority: high
state_hub_task_id: "1d6a3deb-588c-5b3f-a334-8ab5ff9a8ee6"

Chart opt-in renamePreflight.enabled adds a required explicit Secret ref only to the API container. Default disabled; no plaintext chart values or shared env Secret ownership. Helm rendering proves MCP/migration exclusion. Existing repository-rename API tests pass (13 tests). Platform owns CCR-2026-0015 and ESO.

Accept live signing and fenced rotation

id: STATE-WP-0088-T02
status: done
priority: high
state_hub_task_id: "55b32d0d-d30a-50c2-bae0-d6e3a357e6d1"

Before activation, the live flex-auth -> access-engine preflight returned exactly the preflight_signing_unavailable blocker. Target is primary/railiance01, namespace/release/deployment state-hub, current API SA state-hub and one replica. After platform custody verification, enable the chart, prove API-only delivery, all-replica key equality, health and non-mutating signed preflight. Then stop all API replicas (including terminating pods), rotate with CAS through platform, wait ESO, restart and prove predecessor invalidation and forward recovery. Runbook: railiance-platform/docs/credential-lane-designs/state-hub-preflight-activation.md. No repository rename is in scope. Initial activation required attended OpenBao OIDC/MFA because the ambient session returned 403; completion is recorded below.

Completed 2026-09-05 under the user's instruction to lead activation from railiance-platform. CCR-2026-0015 is active. Production chart commit 49e3182 was fetched from Forge into ephemeral deployment storage; server dry-run changed only the API Deployment. Helm revision 59 retained image main-cdff3b7. One API replica matched the ESO key and signed preflight passed with zero blockers. Every API pod then stopped; platform rotated CAS 1 to KV version 2; ESO refreshed and one API replica recovered. New preflight passed, predecessor failed specifically by signature, and primary health passed. MCP and shared env Secret excluded from signing delivery. No repository rename executed.

Evidence is owned by platform: railiance-platform/docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json. Protected predecessor fixture removed after verification. No residual scope; the consuming FLEX-WP-0020 cutover remains separately governed.

Independent review reverified the new API replica against the materialized key and the predecessor captured before rotation. The verifier now rejects expiry as sufficient rotation evidence and also requires primary/railiance01 health. Receipt: docs/evidence/STATE-WP-0088-independent-signing-verification-20260905.json. The private predecessor token was removed after this verification.