Record verified live upstream issuer and completed probe cleanup
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
codex 2026-09-09 00:15:25 +02:00
parent a632b7aa87
commit 06382a3156
3 changed files with 472 additions and 2 deletions

View file

@ -2,7 +2,7 @@
Implemented and published prerequisite corrections in ops-warden, key-cape,
approval-engine and audit-core, followed by local runtime installation and an
attended OpenBao capability preflight. The canonical integration workplan and next
attended OpenBao capability preflight, then verified the actual upstream issuer. The canonical integration workplan and next
admission sequence remain in
[prj-helixforge-factory](/home/worsch/prj-helixforge-factory/operations/identity-admission.md).
@ -25,7 +25,7 @@ RPF-WP-0035-T05 / proposed CCR-2026-0017/0018 and WARDEN-WP-0039-T03.
The two CCRs explicitly cover verifier-side delivery only. Client-side read
lanes and linked approval audit receiver/sender custody remain distinct returns.
The immediate sequence is: verify the actual upstream ID-token issuer; obtain
The immediate sequence is: ensure the now-verified upstream issuer is pinned; obtain
the named custody reviews and run the contained attended first provision;
deploy and verify KeyCape; admit audit/consumer credentials; prove deployed
approval claim/consume and native model credential delivery. Exact policy
@ -119,3 +119,40 @@ custody/rollout reviews. No live issuer result is inferred from preparation.
This replaces an unspecified manual observation with a tested command and
bounded execution packet. The current receipt is
[key-cape/docs/evidence/upstream-issuer-probe.json](/home/worsch/key-cape/docs/evidence/upstream-issuer-probe.json).
## Live issuer observation completed
The user admitted the prepared ten-minute probe. At **2026-09-08 21:44:44 UTC**
it verified an actual signed upstream token with issuer exactly
**`https://auth.coulomb.social`**. Signature, audience, validity window and nonce
checks passed. The pinned container exited 0. This closes the unknown-issuer
observation in KEY-WP-0013-T02 and RPF-WP-0035-T05; the earlier preparation-only
state above is superseded by this live return.
Cleanup removed the dedicated route, Job/Pod, Service and both temporary network
policies. Deletion used the recorded object UIDs; every temporary resource is
absent. Normal KeyCape Deployment/config Secret metadata and image remained
unchanged. The probe retained no token and issued no downstream credential.
It did not prove downstream MFA/application login or activate custody.
KeyCape `41f6916` and Platform `8f40d73` published the owner returns. Project
`89041ec` consumes the live proof and records HFACT-DEC-2026-002 (Hub decision
`1c0d9fd1-4790-4d9a-be6c-0ed4c4890549`). The concrete probe approval is resolved;
its pending human-needed flag is cleared. HFACT-WP-0001-T03 remains wait for
the configuration owner to ensure `authelia.issuer` equals the verified HTTPS
value, named CCR-2026-0017/0018 reviews, and the admitted custody/compatible
KeyCape rollout. Separate client-side/audit/native delivery remains open.
The efficiency gain is one fewer unknown on the activation path and a retained
repeatable check for relevant provider/configuration changes. No renewed token
observation is needed for this unchanged proof context. Autonomous throughput,
spend and the fourteen-day factory observation are still unproved.
Final readback found stale KeyCape T02 and Platform T05 task descriptions despite
applied repository reconciliation receipts. Both were repaired from the published
source and verified. HFACT-WP-0001-T02 retains the underlying source/projection
parity work; these repairs do not establish that automatic synchronization is fixed.
[Live issuer and synchronization receipt](2026-09-08-helixforge-factory/live-upstream-issuer-continuation.json)
records the proof, cleanup, source/Hub parity and progress IDs.

View file

@ -17,6 +17,8 @@ Files:
- `dependency-coverage.json`: all 94 dependency responses, including empty ones.
- `human-flags.csv`: the nineteen flagged tasks' lifecycle metadata.
- `checkout-provenance.json`: principal source revisions and pre-existing dirty state.
- `live-upstream-issuer-continuation.json`: subsequent admitted live signed-token
proof, completed scoped cleanup and resolved probe decision/source parity.
- `upstream-issuer-probe-continuation.json`: completed upstream diagnostic
preparation, image and route checks, owner/source sync and pending live decision.
- `runtime-custody-continuation.json`: later runtime installation and attended

View file

@ -0,0 +1,431 @@
{
"schema": "custodian.factory-live-upstream-issuer-continuation.v1",
"recorded_at": "2026-09-08T22:15:16.787538+00:00",
"supersedes_preparation_state": "upstream-issuer-probe-continuation.json",
"owner_tasks": [
"KEY-WP-0013-T02",
"RPF-WP-0035-T05"
],
"project_task": "HFACT-WP-0001-T03",
"live_proof": {
"recorded_at": "2026-09-08T21:50:10.049099+00:00",
"authorization": {
"source": "User response in this session: yes, go on",
"scope": "Prepared ten-minute temporary issuer probe; existing config read in workload, exact-state callback and cleanup",
"custody_activation_authorized": false
},
"source": {
"repo": "key-cape",
"code_commit": "6f33abddcff6cbc348ced862057973cdcc4f78ec",
"published_owner_commit": "7ecc78f4100c04f9b4ea7751240114bcc485de03",
"packet": "docs/upstream-issuer-proof.md",
"image": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4"
},
"proof": {
"audience_verified": true,
"downstream_credential_issued": false,
"issuer": "https://auth.coulomb.social",
"nonce_verified": true,
"observed_at": "2026-09-08T21:44:44Z",
"schema": "keycape.upstream-issuer-proof.v1",
"signature_verified": true,
"status": "verified",
"tokens_retained": false,
"validity_window_verified": true
},
"job": {
"name": "keycape-issuer-proof-532da53dc96a",
"started_at": "2026-09-08T21:43:34.019545+00:00",
"created_resources": [
{
"kind": "Job",
"name": "keycape-issuer-proof-532da53dc96a",
"uid": "4e01daef-9184-4866-ac4d-9d61cd8d79ae"
},
{
"kind": "Service",
"name": "keycape-issuer-proof-532da53dc96a",
"uid": "3359ce09-cbe2-487b-b9d9-a4cc5c484047"
},
{
"kind": "NetworkPolicy",
"name": "keycape-issuer-proof-532da53dc96a",
"uid": "8940e5b4-3665-4395-8a0d-39b4b08ae12d"
},
{
"kind": "NetworkPolicy",
"name": "keycape-issuer-proof-532da53dc96a-authelia",
"uid": "13d72383-0864-4665-af28-eefc76452131"
},
{
"kind": "IngressRoute",
"name": "keycape-issuer-proof-532da53dc96a",
"uid": "7d705d80-f491-408f-a133-0bc4abd2c867"
}
]
},
"pod_evidence": [
{
"name": "keycape-issuer-proof-532da53dc96a-tgpxh",
"uid": "c9230c57-0fad-4dcf-b798-d586385db9a2",
"phase": "Succeeded",
"containers": [
{
"name": "probe",
"image": "sha256:204d8a4b04f47fa93c508b0a74c600e9954cfeab8e4e6566a8feaab327e8f793",
"imageID": "forgejo.coulomb.social/coulomb/key-cape@sha256:0c85ed377cae7ae6ca5b5c56b1a52930e706b3cb78009747e42f551e869a22e4",
"ready": false,
"state": {
"terminated": {
"exitCode": 0,
"finishedAt": "2026-09-08T21:44:44Z",
"reason": "Completed",
"startedAt": "2026-09-08T21:43:37Z"
}
}
}
]
}
],
"browser": {
"route_head_status": 405,
"launcher_exit": 0,
"url_scope": "exact generated HTTPS issuer-proof start path"
},
"cleanup": {
"completed_at": "2026-09-08T21:45:17.886281+00:00",
"removed": [
{
"kind": "IngressRoute",
"name": "keycape-issuer-proof-532da53dc96a",
"uid_precondition": true
},
{
"kind": "Job",
"name": "keycape-issuer-proof-532da53dc96a",
"uid_precondition": true
},
{
"kind": "Service",
"name": "keycape-issuer-proof-532da53dc96a",
"already_absent": true
},
{
"kind": "NetworkPolicy",
"name": "keycape-issuer-proof-532da53dc96a",
"already_absent": true
},
{
"kind": "NetworkPolicy",
"name": "keycape-issuer-proof-532da53dc96a-authelia",
"already_absent": true
}
],
"all_temporary_resources_absent": true,
"production_metadata_unchanged": true,
"before": {
"production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b",
"deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29",
"secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058"
},
"after": {
"production_image": "forgejo.coulomb.social/coulomb/key-cape:main-153258b",
"deployment": "99ddd83c-cb3f-4847-bcf8-35f1aa87627f 55113259 29",
"secret": "2e94519d-1550-41c7-9701-2efe47fe1fd3 51346058"
}
},
"config_issuer_pinned_by_this_run": false,
"custody_activated": false,
"normal_keycape_deployment_changed": false,
"downstream_mfa_or_application_login_proved": false,
"next_return": "Configuration owner ensures authelia.issuer equals the verified HTTPS issuer; named CCR reviews and attended custody/compatible image rollout remain open"
},
"projection_receipts": [
{
"repo": "key-cape",
"commit": "e30ba7b3c06112f49f85e79601a7e985885ba53c",
"status": "applied",
"instance_role": "primary",
"instance_label": "railiance01",
"derived_commit": "e30ba7b3c06112f49f85e79601a7e985885ba53c",
"outcome": "applied",
"counts": {
"created": 0,
"updated": 29,
"retired": 0,
"refused": 0,
"released": 0,
"created_tasks": 0,
"updated_tasks": 13,
"cancelled_tasks": 0
},
"refused": []
},
{
"repo": "railiance-platform",
"commit": "e06d7fc3903ec79579a104b511fd2ef224c8fefb",
"status": "applied",
"instance_role": "primary",
"instance_label": "railiance01",
"derived_commit": "e06d7fc3903ec79579a104b511fd2ef224c8fefb",
"outcome": "applied",
"counts": {
"created": 0,
"updated": 41,
"retired": 0,
"refused": 0,
"released": 0,
"created_tasks": 0,
"updated_tasks": 0,
"cancelled_tasks": 0
},
"refused": []
},
{
"repo": "prj-helixforge-factory",
"commit": "0a8a80cedf627dfdeb04d4737e119b7f4057b976",
"status": "applied",
"instance_role": "primary",
"instance_label": "railiance01",
"derived_commit": "0a8a80cedf627dfdeb04d4737e119b7f4057b976",
"outcome": "applied",
"counts": {
"created": 0,
"updated": 1,
"retired": 0,
"refused": 0,
"released": 0,
"created_tasks": 0,
"updated_tasks": 0,
"cancelled_tasks": 0
},
"refused": []
}
],
"consistency_checks": [
{
"repo": "key-cape",
"command": "statehub fix-consistency",
"summary": {
"fail": 0,
"automation_error": 0,
"warn": 14,
"info": 1
},
"result": "warn"
},
{
"repo": "prj-helixforge-factory",
"command": "statehub fix-consistency",
"summary": {
"fail": 0,
"automation_error": 0,
"warn": 3,
"info": 0
},
"result": "warn"
}
],
"final_readback": {
"recorded_at": "2026-09-08T22:14:28.496514+00:00",
"readbacks": [
{
"source_id": "RPF-WP-0035-T05",
"uuid": "e15d62c9-e5da-5721-a135-87c050f7851c",
"status": "wait",
"description_sha256": "ecf62d2324b14d5954546fc5dda757a8b2883695adf34787cb5672a6b88ecec0",
"description_repaired_from_source": true,
"repair_note": "Repaired in first closeout attempt before the KeyCape description assertion; verified again here.",
"verified": true
},
{
"source_id": "HFACT-WP-0001-T01",
"uuid": "5cee3251-faf9-5925-8ffd-7a8bf378b0a4",
"fields": {
"status": "wait",
"assignee": "the-custodian",
"needs_human": false,
"blocking_reason": "Project published and registered; both product PR receipts finalized. Exact unattended actor/project/profile, grants, operating owners and enforceable spend contract still require the G0 admission packet."
},
"repaired_fields": [],
"verified": true
},
{
"source_id": "HFACT-WP-0001-T02",
"uuid": "3a3a967d-5bec-52ee-be20-dc94524b8e85",
"fields": {
"status": "progress",
"assignee": "the-custodian"
},
"repaired_fields": [],
"verified": true
},
{
"source_id": "HFACT-WP-0001-T03",
"uuid": "67c80db1-01ba-54f1-80ff-76398f9e7823",
"fields": {
"status": "wait",
"assignee": "the-custodian",
"needs_human": false,
"intervention_note": "",
"blocking_reason": "Actual signed upstream issuer proved as https://auth.coulomb.social; probe admission and cleanup complete. Await configuration-owner pin, named CCR-2026-0017/0018 reviews, custody/compatible rollout and separate audit/client-side/native delivery returns."
},
"repaired_fields": [],
"verified": true
},
{
"source_id": "HFACT-WP-0001-T04",
"uuid": "1054b135-f367-57b1-9308-72a1fbb38f62",
"fields": {
"status": "wait",
"assignee": "the-custodian",
"blocking_reason": "Local protected artifact installation and installed-path startup proved by SAND-WP-0015-T06. Await trusted owner configuration, T03 native credentials, real-model acceptance and Railiance-specific placement."
},
"repaired_fields": [],
"verified": true
},
{
"source_id": "HFACT-WP-0001-T05",
"uuid": "2b171ebd-75f3-5ce2-85a9-98e8ab77fd19",
"fields": {
"status": "wait",
"assignee": "the-custodian",
"blocking_reason": "Await actionable admission records, owner credential chain and accepted profile/placement from T02-T04."
},
"repaired_fields": [],
"verified": true
},
{
"source_id": "HFACT-WP-0001-T06",
"uuid": "4d72717a-d5c9-571d-987b-9373f01253fa",
"fields": {
"status": "wait",
"assignee": "the-custodian",
"blocking_reason": "Await the current governed Railiance worker proof in T05."
},
"repaired_fields": [],
"verified": true
},
{
"source_id": "HFACT-WP-0001-T07",
"uuid": "a815d9b3-b03e-5764-95c2-fa1a2940611a",
"fields": {
"status": "wait",
"assignee": "the-custodian",
"blocking_reason": "Recovery matrix and measurement ledger are prepared; final live recovery proof requires the deployed T05/T06 configuration."
},
"repaired_fields": [],
"verified": true
},
{
"source_id": "HFACT-WP-0001-T08",
"uuid": "59cfddfb-7cd6-5103-9444-8764e9d51678",
"fields": {
"status": "wait",
"assignee": "the-custodian",
"blocking_reason": "Await useful delivery and operational controls from T06/T07, then the complete fourteen-day observation window."
},
"repaired_fields": [],
"verified": true
},
{
"source_id": "KEY-WP-0013-T02",
"uuid": "607897c5-bad9-55e5-86df-7802f592d6e8",
"status": "wait",
"description_sha256": "c7298c0b96f986c1ad16c54b86441b3129bdd96a5d461b9a97cb3c5feed9b745",
"description_repaired_from_source": true,
"live_proof_in_description": true,
"verified": true
}
],
"decision": {
"id": "1c0d9fd1-4790-4d9a-be6c-0ed4c4890549",
"status": "resolved"
},
"progress": [
{
"id": "df89c3c4-e2a9-4dfa-ad15-606ee58205eb",
"workplan_id": "6e815d88-b0e3-5ce0-be5d-13ab15917f7f",
"task_id": "607897c5-bad9-55e5-86df-7802f592d6e8",
"summary": "User-admitted upstream issuer probe completed: actual signed issuer https://auth.coulomb.social verified at 2026-09-08T21:44:44Z, signature/audience/validity/nonce passed, pinned Job exit 0. All five temporary resources and Pod removed with UID-scoped cleanup; normal KeyCape Deployment/config metadata unchanged. KEY-WP-0013-T02 unknown-issuer input resolved; configuration-owner pin, named custody reviews and compatible rollout remain open. No token retained or downstream credential issued."
},
{
"id": "893d78bb-4ec6-4eca-999d-053f55a62674",
"workplan_id": "975db491-5412-5e27-8e34-14a2417bb039",
"task_id": "e15d62c9-e5da-5721-a135-87c050f7851c",
"summary": "Accepted KeyCape live signed upstream issuer https://auth.coulomb.social. Probe approval is HFACT-DEC-2026-002; signature/audience/time/nonce checks and complete scoped cleanup proved. RPF-WP-0035-T05 stays wait for configuration pin and named CCR-2026-0017/0018 reviews before custody activation; separate client/audit returns remain. Canonical repository reconciliation omitted the updated task description; exact source-backed T05 description was repaired through the supported API and read back."
},
{
"id": "4062ff36-20c8-4f64-94cf-e971704d5c72",
"workplan_id": "ed4fe524-036f-5221-8deb-00e24e944de1",
"task_id": "67c80db1-01ba-54f1-80ff-76398f9e7823",
"summary": "HFACT-DEC-2026-002 resolved and executed: signed issuer https://auth.coulomb.social proved with four checks and pinned Job exit 0; all temporary resources removed, normal config/deployment unchanged. Cleared completed probe intervention and consumed KEY-WP-0013-T02/RPF-WP-0035-T05 owner returns. T03 still waits for exact config pin, named custody reviews and admitted custody/compatible rollout; no factory operating grant or paid execution."
},
{
"id": "8903b14e-0696-4bcc-b9c6-33c6f64ba4e3",
"workplan_id": null,
"task_id": null,
"summary": "Custodian completed the explicitly approved live issuer probe. At 2026-09-08T21:44:44Z it proved signed upstream issuer https://auth.coulomb.social, exited 0 and left no temporary resources; normal KeyCape deployment/config metadata unchanged. Published owner returns and HFACT-DEC-2026-002, cleared the completed probe decision and verified task/source parity including source-backed KeyCape and Platform description repairs. Existing KEY-WP-0013-T02, RPF-WP-0035-T05 and HFACT-WP-0001-T03 retain config pin, named custody reviews and activation/rollout residuals. No custody activated or downstream/paid factory credential issued."
}
],
"repositories": [
{
"repo": "key-cape",
"commit": "e30ba7b3c06112f49f85e79601a7e985885ba53c",
"remote_main_matches": true,
"clean": true
},
{
"repo": "railiance-platform",
"commit": "e06d7fc3903ec79579a104b511fd2ef224c8fefb",
"remote_main_matches": true,
"clean": true
},
{
"repo": "prj-helixforge-factory",
"commit": "0a8a80cedf627dfdeb04d4737e119b7f4057b976",
"remote_main_matches": true,
"clean": true
},
{
"repo": "net-kingdom",
"commit": "46455439cfbb24fc5d187403c8f9f4465fccc274",
"remote_main_matches": true,
"clean": true
}
],
"human_needed_count": 15
},
"projection_limit": {
"finding": "Applied repository reconciliation did not preserve both updated owner task descriptions.",
"repaired_from_published_source": [
"KEY-WP-0013-T02",
"RPF-WP-0035-T05"
],
"repair_method": "Supported task description PATCH, followed by exact source-body and status readback.",
"systemic_issue_resolved": false,
"existing_owner_task": "HFACT-WP-0001-T02"
},
"efficiency_change": {
"actual_signed_issuer_unknown_resolved": true,
"probe_approval_resolved": true,
"probe_intervention_flag_cleared": true,
"repeat_observation_required_without_context_change": false,
"autonomous_factory_throughput_proved": false,
"fourteen_day_factory_observation_started": false
},
"next_returns": [
{
"owner_task": "KEY-WP-0013-T02",
"return": "Configuration owner ensures authelia.issuer equals https://auth.coulomb.social before compatible rollout."
},
{
"owner_task": "RPF-WP-0035-T05",
"return": "Named CCR-2026-0017/0018 reviews, then admitted attended custody activation and verifier-side delivery."
},
{
"owner_task": "HFACT-WP-0001-T03",
"return": "Consume compatible KeyCape rollout and live verification, separate audit/client-side custody, live approval and native credential delivery."
}
]
}