#101 FTX-101: audit harness mints a platform key per run and never revokes it — 10 active platform-admin keys on prod
Description
EditEARS SPEC:
- When the audit harness finishes, it shall revoke every credential it created.
- Futex shall provide an operator command that revokes stale platform API keys while preserving a designated key.
- If a revocation command is run without an explicit key to preserve, then it shall refuse to revoke any platform key.
- When a stale key is revoked, Futex shall record it in the audit trail.
CAUSE: audit/evaluations/setup_harness.py calls scripts/bootstrap_platform_key.py on every run, prints the raw key to stdout, creates a tenant plus three tenant keys, and revokes none of it. Nine runs on 2026-07-30 between 01:13 and 01:52 left nine full-privilege platform-admin keys active on production, plus 17 'Audit Key' and 28 'probe' tenant keys.
Comments
Loading comments...
Context
Loading context...
Audit History
View AllLoading audit history...