From 1a20c8595b2fc947ef7c27b5aaf62293aa2940d2 Mon Sep 17 00:00:00 2001 From: tegwick Date: Wed, 23 Sep 2026 19:15:20 +0200 Subject: [PATCH] WP-0039-T02: record secrets-engine path confirmation Co-Authored-By: Claude Opus 5.5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 151606@bnt-lap001 Assistant-Session: 3c0a4ad5-bb8b-4bf7-b9f0-fa5f29204e48 --- ...VITY-WP-0039-multi-worker-identity-and-token-custody.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/workplans/ACTIVITY-WP-0039-multi-worker-identity-and-token-custody.md b/workplans/ACTIVITY-WP-0039-multi-worker-identity-and-token-custody.md index 4d33de4..38fc4ed 100644 --- a/workplans/ACTIVITY-WP-0039-multi-worker-identity-and-token-custody.md +++ b/workplans/ACTIVITY-WP-0039-multi-worker-identity-and-token-custody.md @@ -100,6 +100,13 @@ Waiting on railiance-platform to add both exact paths to the `activity-core-eso` role policy (RPF-WP-0045 pattern), and on secrets-engine to confirm the metered path for its catalog. +2026-09-23: secrets-engine confirmed the metered path (message `a0e9afaf`). It +catalogs only `.../rein-aharness-metered-railiance01` as lane +`activity-core-metered-worker-token`, read through its own exact-path AppRole. +Only the railiance-platform policy change remains. The paths are requested in +activity-core's message to railiance-platform. The HCL is two `read` stanzas +on `platform/data/workloads/activity-core/ops-run-workers/`. + ## Seed the tokens in OpenBao ```task