diff --git a/docs/assessments/2026-09-08-helixforge-factory-critical-path.md b/docs/assessments/2026-09-08-helixforge-factory-critical-path.md index af3f18b..bd3711f 100644 --- a/docs/assessments/2026-09-08-helixforge-factory-critical-path.md +++ b/docs/assessments/2026-09-08-helixforge-factory-critical-path.md @@ -2,7 +2,7 @@ Implemented and published prerequisite corrections in ops-warden, key-cape, approval-engine and audit-core, followed by local runtime installation and an -attended OpenBao capability preflight. The canonical integration workplan and next +attended OpenBao capability preflight, then verified the actual upstream issuer. The canonical integration workplan and next admission sequence remain in [prj-helixforge-factory](/home/worsch/prj-helixforge-factory/operations/identity-admission.md). @@ -25,7 +25,7 @@ RPF-WP-0035-T05 / proposed CCR-2026-0017/0018 and WARDEN-WP-0039-T03. The two CCRs explicitly cover verifier-side delivery only. Client-side read lanes and linked approval audit receiver/sender custody remain distinct returns. -The immediate sequence is: verify the actual upstream ID-token issuer; obtain +The immediate sequence is: ensure the now-verified upstream issuer is pinned; obtain the named custody reviews and run the contained attended first provision; deploy and verify KeyCape; admit audit/consumer credentials; prove deployed approval claim/consume and native model credential delivery. Exact policy @@ -119,3 +119,40 @@ custody/rollout reviews. No live issuer result is inferred from preparation. This replaces an unspecified manual observation with a tested command and bounded execution packet. The current receipt is [key-cape/docs/evidence/upstream-issuer-probe.json](/home/worsch/key-cape/docs/evidence/upstream-issuer-probe.json). + + +## Live issuer observation completed + +The user admitted the prepared ten-minute probe. At **2026-09-08 21:44:44 UTC** +it verified an actual signed upstream token with issuer exactly +**`https://auth.coulomb.social`**. Signature, audience, validity window and nonce +checks passed. The pinned container exited 0. This closes the unknown-issuer +observation in KEY-WP-0013-T02 and RPF-WP-0035-T05; the earlier preparation-only +state above is superseded by this live return. + +Cleanup removed the dedicated route, Job/Pod, Service and both temporary network +policies. Deletion used the recorded object UIDs; every temporary resource is +absent. Normal KeyCape Deployment/config Secret metadata and image remained +unchanged. The probe retained no token and issued no downstream credential. +It did not prove downstream MFA/application login or activate custody. + +KeyCape `41f6916` and Platform `8f40d73` published the owner returns. Project +`89041ec` consumes the live proof and records HFACT-DEC-2026-002 (Hub decision +`1c0d9fd1-4790-4d9a-be6c-0ed4c4890549`). The concrete probe approval is resolved; +its pending human-needed flag is cleared. HFACT-WP-0001-T03 remains wait for +the configuration owner to ensure `authelia.issuer` equals the verified HTTPS +value, named CCR-2026-0017/0018 reviews, and the admitted custody/compatible +KeyCape rollout. Separate client-side/audit/native delivery remains open. + +The efficiency gain is one fewer unknown on the activation path and a retained +repeatable check for relevant provider/configuration changes. No renewed token +observation is needed for this unchanged proof context. Autonomous throughput, +spend and the fourteen-day factory observation are still unproved. + +Final readback found stale KeyCape T02 and Platform T05 task descriptions despite +applied repository reconciliation receipts. Both were repaired from the published +source and verified. HFACT-WP-0001-T02 retains the underlying source/projection +parity work; these repairs do not establish that automatic synchronization is fixed. + +[Live issuer and synchronization receipt](2026-09-08-helixforge-factory/live-upstream-issuer-continuation.json) +records the proof, cleanup, source/Hub parity and progress IDs. diff --git a/docs/assessments/2026-09-08-helixforge-factory/README.md b/docs/assessments/2026-09-08-helixforge-factory/README.md index 58580fb..50513ae 100644 --- a/docs/assessments/2026-09-08-helixforge-factory/README.md +++ b/docs/assessments/2026-09-08-helixforge-factory/README.md @@ -17,6 +17,8 @@ Files: - `dependency-coverage.json`: all 94 dependency responses, including empty ones. - `human-flags.csv`: the nineteen flagged tasks' lifecycle metadata. - `checkout-provenance.json`: principal source revisions and pre-existing dirty state. +- `live-upstream-issuer-continuation.json`: subsequent admitted live signed-token + proof, completed scoped cleanup and resolved probe decision/source parity. - `upstream-issuer-probe-continuation.json`: completed upstream diagnostic preparation, image and route checks, owner/source sync and pending live decision. - `runtime-custody-continuation.json`: later runtime installation and attended diff --git a/docs/assessments/2026-09-08-helixforge-factory/live-upstream-issuer-continuation.json b/docs/assessments/2026-09-08-helixforge-factory/live-upstream-issuer-continuation.json new file mode 100644 index 0000000..b4cd7df --- /dev/null +++ b/docs/assessments/2026-09-08-helixforge-factory/live-upstream-issuer-continuation.json @@ -0,0 +1,431 @@ +{ + "schema": "custodian.factory-live-upstream-issuer-continuation.v1", + "recorded_at": "2026-09-08T22:15:16.787538+00:00", + "supersedes_preparation_state": "upstream-issuer-probe-continuation.json", + "owner_tasks": [ + "KEY-WP-0013-T02", + "RPF-WP-0035-T05" + ], + "project_task": "HFACT-WP-0001-T03", + "live_proof": { + "recorded_at": "2026-09-08T21:50:10.049099+00:00", + "authorization": { + "source": "User response in this session: yes, go on", + "scope": "Prepared ten-minute temporary issuer probe; existing config read in workload, exact-state callback and cleanup", + "custody_activation_authorized": false + }, + "source": { + "repo": "key-cape", + "code_commit": "6f33abddcff6cbc348ced862057973cdcc4f78ec", + "published_owner_commit": "7ecc78f4100c04f9b4ea7751240114bcc485de03", + "packet": "docs/upstream-issuer-proof.md", + "image": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4" + }, + "proof": { + "audience_verified": true, + "downstream_credential_issued": false, + "issuer": "https://auth.coulomb.social", + "nonce_verified": true, + "observed_at": "2026-09-08T21:44:44Z", + "schema": "keycape.upstream-issuer-proof.v1", + "signature_verified": true, + "status": "verified", + "tokens_retained": false, + "validity_window_verified": true + }, + "job": { + "name": "keycape-issuer-proof-532da53dc96a", + "started_at": "2026-09-08T21:43:34.019545+00:00", + "created_resources": [ + { + "kind": "Job", + "name": "keycape-issuer-proof-532da53dc96a", + "uid": "4e01daef-9184-4866-ac4d-9d61cd8d79ae" + }, + { + "kind": "Service", + "name": "keycape-issuer-proof-532da53dc96a", + "uid": "3359ce09-cbe2-487b-b9d9-a4cc5c484047" + }, + { + "kind": "NetworkPolicy", + "name": "keycape-issuer-proof-532da53dc96a", + "uid": "8940e5b4-3665-4395-8a0d-39b4b08ae12d" + }, + { + "kind": "NetworkPolicy", + "name": "keycape-issuer-proof-532da53dc96a-authelia", + "uid": "13d72383-0864-4665-af28-eefc76452131" + }, + { + "kind": "IngressRoute", + "name": "keycape-issuer-proof-532da53dc96a", + "uid": "7d705d80-f491-408f-a133-0bc4abd2c867" + } + ] + }, + "pod_evidence": [ + { + "name": "keycape-issuer-proof-532da53dc96a-tgpxh", + "uid": "c9230c57-0fad-4dcf-b798-d586385db9a2", + "phase": "Succeeded", + "containers": [ + { + "name": "probe", + "image": "sha256:204d8a4b04f47fa93c508b0a74c600e9954cfeab8e4e6566a8feaab327e8f793", + "imageID": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4", + "ready": false, + "state": { + "terminated": { + "exitCode": 0, + "finishedAt": "2026-09-08T21:44:44Z", + "reason": "Completed", + "startedAt": "2026-09-08T21:43:37Z" + } + } + } + ] + } + ], + "browser": { + "route_head_status": 405, + "launcher_exit": 0, + "url_scope": "exact generated HTTPS issuer-proof start path" + }, + "cleanup": { + "completed_at": "2026-09-08T21:45:17.886281+00:00", + "removed": [ + { + "kind": "IngressRoute", + "name": "keycape-issuer-proof-532da53dc96a", + "uid_precondition": true + }, + { + "kind": "Job", + "name": "keycape-issuer-proof-532da53dc96a", + "uid_precondition": true + }, + { + "kind": "Service", + "name": "keycape-issuer-proof-532da53dc96a", + "already_absent": true + }, + { + "kind": "NetworkPolicy", + "name": "keycape-issuer-proof-532da53dc96a", + "already_absent": true + }, + { + "kind": "NetworkPolicy", + "name": "keycape-issuer-proof-532da53dc96a-authelia", + "already_absent": true + } + ], + "all_temporary_resources_absent": true, + "production_metadata_unchanged": true, + "before": { + "production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b", + "deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29", + "secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058" + }, + "after": { + "production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b", + "deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29", + "secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058" + } + }, + "config_issuer_pinned_by_this_run": false, + "custody_activated": false, + "normal_keycape_deployment_changed": false, + "downstream_mfa_or_application_login_proved": false, + "next_return": "Configuration owner ensures authelia.issuer equals the verified HTTPS issuer; named CCR reviews and attended custody/compatible image rollout remain open" + }, + "projection_receipts": [ + { + "repo": "key-cape", + "commit": "e30ba7b3c06112f49f85e79601a7e985885ba53c", + "status": "applied", + "instance_role": "primary", + "instance_label": "railiance01", + "derived_commit": "e30ba7b3c06112f49f85e79601a7e985885ba53c", + "outcome": "applied", + "counts": { + "created": 0, + "updated": 29, + "retired": 0, + "refused": 0, + "released": 0, + "created_tasks": 0, + "updated_tasks": 13, + "cancelled_tasks": 0 + }, + "refused": [] + }, + { + "repo": "railiance-platform", + "commit": "e06d7fc3903ec79579a104b511fd2ef224c8fefb", + "status": "applied", + "instance_role": "primary", + "instance_label": "railiance01", + "derived_commit": "e06d7fc3903ec79579a104b511fd2ef224c8fefb", + "outcome": "applied", + "counts": { + "created": 0, + "updated": 41, + "retired": 0, + "refused": 0, + "released": 0, + "created_tasks": 0, + "updated_tasks": 0, + "cancelled_tasks": 0 + }, + "refused": [] + }, + { + "repo": "prj-helixforge-factory", + "commit": "0a8a80cedf627dfdeb04d4737e119b7f4057b976", + "status": "applied", + "instance_role": "primary", + "instance_label": "railiance01", + "derived_commit": "0a8a80cedf627dfdeb04d4737e119b7f4057b976", + "outcome": "applied", + "counts": { + "created": 0, + "updated": 1, + "retired": 0, + "refused": 0, + "released": 0, + "created_tasks": 0, + "updated_tasks": 0, + "cancelled_tasks": 0 + }, + "refused": [] + } + ], + "consistency_checks": [ + { + "repo": "key-cape", + "command": "statehub fix-consistency", + "summary": { + "fail": 0, + "automation_error": 0, + "warn": 14, + "info": 1 + }, + "result": "warn" + }, + { + "repo": "prj-helixforge-factory", + "command": "statehub fix-consistency", + "summary": { + "fail": 0, + "automation_error": 0, + "warn": 3, + "info": 0 + }, + "result": "warn" + } + ], + "final_readback": { + "recorded_at": "2026-09-08T22:14:28.496514+00:00", + "readbacks": [ + { + "source_id": "RPF-WP-0035-T05", + "uuid": "e15d62c9-e5da-5721-a135-87c050f7851c", + "status": "wait", + "description_sha256": "ecf62d2324b14d5954546fc5dda757a8b2883695adf34787cb5672a6b88ecec0", + "description_repaired_from_source": true, + "repair_note": "Repaired in first closeout attempt before the KeyCape description assertion; verified again here.", + "verified": true + }, + { + "source_id": "HFACT-WP-0001-T01", + "uuid": "5cee3251-faf9-5925-8ffd-7a8bf378b0a4", + "fields": { + "status": "wait", + "assignee": "the-custodian", + "needs_human": false, + "blocking_reason": "Project published and registered; both product PR receipts finalized. Exact unattended actor/project/profile, grants, operating owners and enforceable spend contract still require the G0 admission packet." + }, + "repaired_fields": [], + "verified": true + }, + { + "source_id": "HFACT-WP-0001-T02", + "uuid": "3a3a967d-5bec-52ee-be20-dc94524b8e85", + "fields": { + "status": "progress", + "assignee": "the-custodian" + }, + "repaired_fields": [], + "verified": true + }, + { + "source_id": "HFACT-WP-0001-T03", + "uuid": "67c80db1-01ba-54f1-80ff-76398f9e7823", + "fields": { + "status": "wait", + "assignee": "the-custodian", + "needs_human": false, + "intervention_note": "", + "blocking_reason": "Actual signed upstream issuer proved as https://auth.coulomb.social; probe admission and cleanup complete. Await configuration-owner pin, named CCR-2026-0017/0018 reviews, custody/compatible rollout and separate audit/client-side/native delivery returns." + }, + "repaired_fields": [], + "verified": true + }, + { + "source_id": "HFACT-WP-0001-T04", + "uuid": "1054b135-f367-57b1-9308-72a1fbb38f62", + "fields": { + "status": "wait", + "assignee": "the-custodian", + "blocking_reason": "Local protected artifact installation and installed-path startup proved by SAND-WP-0015-T06. Await trusted owner configuration, T03 native credentials, real-model acceptance and Railiance-specific placement." + }, + "repaired_fields": [], + "verified": true + }, + { + "source_id": "HFACT-WP-0001-T05", + "uuid": "2b171ebd-75f3-5ce2-85a9-98e8ab77fd19", + "fields": { + "status": "wait", + "assignee": "the-custodian", + "blocking_reason": "Await actionable admission records, owner credential chain and accepted profile/placement from T02-T04." + }, + "repaired_fields": [], + "verified": true + }, + { + "source_id": "HFACT-WP-0001-T06", + "uuid": "4d72717a-d5c9-571d-987b-9373f01253fa", + "fields": { + "status": "wait", + "assignee": "the-custodian", + "blocking_reason": "Await the current governed Railiance worker proof in T05." + }, + "repaired_fields": [], + "verified": true + }, + { + "source_id": "HFACT-WP-0001-T07", + "uuid": "a815d9b3-b03e-5764-95c2-fa1a2940611a", + "fields": { + "status": "wait", + "assignee": "the-custodian", + "blocking_reason": "Recovery matrix and measurement ledger are prepared; final live recovery proof requires the deployed T05/T06 configuration." + }, + "repaired_fields": [], + "verified": true + }, + { + "source_id": "HFACT-WP-0001-T08", + "uuid": "59cfddfb-7cd6-5103-9444-8764e9d51678", + "fields": { + "status": "wait", + "assignee": "the-custodian", + "blocking_reason": "Await useful delivery and operational controls from T06/T07, then the complete fourteen-day observation window." + }, + "repaired_fields": [], + "verified": true + }, + { + "source_id": "KEY-WP-0013-T02", + "uuid": "607897c5-bad9-55e5-86df-7802f592d6e8", + "status": "wait", + "description_sha256": "c7298c0b96f986c1ad16c54b86441b3129bdd96a5d461b9a97cb3c5feed9b745", + "description_repaired_from_source": true, + "live_proof_in_description": true, + "verified": true + } + ], + "decision": { + "id": "1c0d9fd1-4790-4d9a-be6c-0ed4c4890549", + "status": "resolved" + }, + "progress": [ + { + "id": "df89c3c4-e2a9-4dfa-ad15-606ee58205eb", + "workplan_id": "6e815d88-b0e3-5ce0-be5d-13ab15917f7f", + "task_id": "607897c5-bad9-55e5-86df-7802f592d6e8", + "summary": "User-admitted upstream issuer probe completed: actual signed issuer https://auth.coulomb.social verified at 2026-09-08T21:44:44Z, signature/audience/validity/nonce passed, pinned Job exit 0. All five temporary resources and Pod removed with UID-scoped cleanup; normal KeyCape Deployment/config metadata unchanged. KEY-WP-0013-T02 unknown-issuer input resolved; configuration-owner pin, named custody reviews and compatible rollout remain open. No token retained or downstream credential issued." + }, + { + "id": "893d78bb-4ec6-4eca-999d-053f55a62674", + "workplan_id": "975db491-5412-5e27-8e34-14a2417bb039", + "task_id": "e15d62c9-e5da-5721-a135-87c050f7851c", + "summary": "Accepted KeyCape live signed upstream issuer https://auth.coulomb.social. Probe approval is HFACT-DEC-2026-002; signature/audience/time/nonce checks and complete scoped cleanup proved. RPF-WP-0035-T05 stays wait for configuration pin and named CCR-2026-0017/0018 reviews before custody activation; separate client/audit returns remain. Canonical repository reconciliation omitted the updated task description; exact source-backed T05 description was repaired through the supported API and read back." + }, + { + "id": "4062ff36-20c8-4f64-94cf-e971704d5c72", + "workplan_id": "ed4fe524-036f-5221-8deb-00e24e944de1", + "task_id": "67c80db1-01ba-54f1-80ff-76398f9e7823", + "summary": "HFACT-DEC-2026-002 resolved and executed: signed issuer https://auth.coulomb.social proved with four checks and pinned Job exit 0; all temporary resources removed, normal config/deployment unchanged. Cleared completed probe intervention and consumed KEY-WP-0013-T02/RPF-WP-0035-T05 owner returns. T03 still waits for exact config pin, named custody reviews and admitted custody/compatible rollout; no factory operating grant or paid execution." + }, + { + "id": "8903b14e-0696-4bcc-b9c6-33c6f64ba4e3", + "workplan_id": null, + "task_id": null, + "summary": "Custodian completed the explicitly approved live issuer probe. At 2026-09-08T21:44:44Z it proved signed upstream issuer https://auth.coulomb.social, exited 0 and left no temporary resources; normal KeyCape deployment/config metadata unchanged. Published owner returns and HFACT-DEC-2026-002, cleared the completed probe decision and verified task/source parity including source-backed KeyCape and Platform description repairs. Existing KEY-WP-0013-T02, RPF-WP-0035-T05 and HFACT-WP-0001-T03 retain config pin, named custody reviews and activation/rollout residuals. No custody activated or downstream/paid factory credential issued." + } + ], + "repositories": [ + { + "repo": "key-cape", + "commit": "e30ba7b3c06112f49f85e79601a7e985885ba53c", + "remote_main_matches": true, + "clean": true + }, + { + "repo": "railiance-platform", + "commit": "e06d7fc3903ec79579a104b511fd2ef224c8fefb", + "remote_main_matches": true, + "clean": true + }, + { + "repo": "prj-helixforge-factory", + "commit": "0a8a80cedf627dfdeb04d4737e119b7f4057b976", + "remote_main_matches": true, + "clean": true + }, + { + "repo": "net-kingdom", + "commit": "46455439cfbb24fc5d187403c8f9f4465fccc274", + "remote_main_matches": true, + "clean": true + } + ], + "human_needed_count": 15 + }, + "projection_limit": { + "finding": "Applied repository reconciliation did not preserve both updated owner task descriptions.", + "repaired_from_published_source": [ + "KEY-WP-0013-T02", + "RPF-WP-0035-T05" + ], + "repair_method": "Supported task description PATCH, followed by exact source-body and status readback.", + "systemic_issue_resolved": false, + "existing_owner_task": "HFACT-WP-0001-T02" + }, + "efficiency_change": { + "actual_signed_issuer_unknown_resolved": true, + "probe_approval_resolved": true, + "probe_intervention_flag_cleared": true, + "repeat_observation_required_without_context_change": false, + "autonomous_factory_throughput_proved": false, + "fourteen_day_factory_observation_started": false + }, + "next_returns": [ + { + "owner_task": "KEY-WP-0013-T02", + "return": "Configuration owner ensures authelia.issuer equals https://auth.coulomb.social before compatible rollout." + }, + { + "owner_task": "RPF-WP-0035-T05", + "return": "Named CCR-2026-0017/0018 reviews, then admitted attended custody activation and verifier-side delivery." + }, + { + "owner_task": "HFACT-WP-0001-T03", + "return": "Consume compatible KeyCape rollout and live verification, separate audit/client-side custody, live approval and native credential delivery." + } + ] +}