WP-0039-T03: record option (b) and add silent seeding script
The founder chose to mint fresh tokens for both worker identities. Add the reviewed, idempotent, silent script for the attended OpenBao admin lane, and the cutover order that keeps the claim loop's gap to seconds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 151606@bnt-lap001 Assistant-Session: 3c0a4ad5-bb8b-4bf7-b9f0-fa5f29204e48
This commit is contained in:
parent
b690ce03fa
commit
a129249d25
2 changed files with 71 additions and 0 deletions
40
scripts/wp0039-seed-worker-tokens.sh
Executable file
40
scripts/wp0039-seed-worker-tokens.sh
Executable file
|
|
@ -0,0 +1,40 @@
|
|||
#!/bin/sh
|
||||
# ACTIVITY-WP-0039-T03 (option b): mint fresh ops_run worker tokens into OpenBao.
|
||||
#
|
||||
# Founder-attended only, through the silent admin lane (orientation section 5):
|
||||
#
|
||||
# BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 \
|
||||
# warden access openbao-platform-admin-login --exec -- \
|
||||
# sh scripts/wp0039-seed-worker-tokens.sh
|
||||
#
|
||||
# Silent by design: warden fails closed on any child output. The value is
|
||||
# generated inside a pipe and sent to bao on stdin, so it never appears in
|
||||
# argv, output, Git, or the hub. Idempotent: an existing path is never
|
||||
# overwritten. Rerunning after success is a no-op that re-verifies.
|
||||
#
|
||||
# Exit codes: 0 both paths present and verified · 3 a path exists without a
|
||||
# usable token field (left untouched) · 4 write failed · 5 verification failed.
|
||||
exec >/dev/null 2>&1
|
||||
set -u
|
||||
|
||||
MOUNT=platform
|
||||
BASE=workloads/activity-core/ops-run-workers
|
||||
PATHS="rein-aharness-railiance01 rein-aharness-metered-railiance01"
|
||||
|
||||
token_len() {
|
||||
bao kv get -mount="$MOUNT" -field=token "$BASE/$1" 2>/dev/null | tr -d '\n' | wc -c
|
||||
}
|
||||
|
||||
for slug in $PATHS; do
|
||||
if bao kv metadata get -mount="$MOUNT" "$BASE/$slug"; then
|
||||
[ "$(token_len "$slug")" -eq 64 ] || exit 3
|
||||
continue
|
||||
fi
|
||||
openssl rand -hex 32 | tr -d '\n' \
|
||||
| bao kv put -mount="$MOUNT" "$BASE/$slug" token=- || exit 4
|
||||
done
|
||||
|
||||
for slug in $PATHS; do
|
||||
[ "$(token_len "$slug")" -eq 64 ] || exit 5
|
||||
done
|
||||
exit 0
|
||||
Loading…
Add table
Add a link
Reference in a new issue