fix: reconcile llm-connect provider secret delivery
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 8s

This commit is contained in:
tegwick 2026-08-20 22:47:18 +02:00
parent 944fd158de
commit a446de1c45
4 changed files with 48 additions and 4 deletions

View file

@ -39,6 +39,16 @@ HTTP 401. Credential ownership is the `railiance-platform` OpenBao lane
Track rotation/reconciliation, restart, and a successful fixture smoke as the
exit evidence.
Progress 2026-08-20: railiance-platform repaired the delivery half. The
activity-core ESO bootstrap default now includes the approved exact-path
llm-connect policy, its replacement token reports read capability, and the
reviewed `ExternalSecret` is `Ready=True` / `SecretSynced` on railiance01. It
took ownership of the one-key Secret, llm-connect rolled out, and the real
actcore-worker reaches `/health` through the Service. The post-restart fixture
still returns sanitized OpenRouter HTTP 401, proving the canonical key itself
is rejected. T01 remains `wait` on an attended OpenRouter account owner to mint
and safely provision a replacement key; no key value was read or printed.
## Emergency-pause weekly SBOM fan-out
```task