ACTIVITY-WP-0020-T07: dry-run via warden lane instead of PAT file drop
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-07-18 14:27:24 +02:00
parent 8e74932db5
commit aed1437608

View file

@ -279,9 +279,11 @@ coulombcore cluster's live forgejo tags: `issue-core:0.2.1`,
`state-hub:f2e042a`, `vergabe-teilnahme:064d295`. Both clusters' exports
staged (workstation scratchpad; coulombcore list also copied to
`railiance01:~/.local/share/forgejo-prune/live-images-coulombcore.txt`).
**Remaining (operator, ~5 min):** provide a Forgejo PAT
(`/tmp/forgejo-tegwick-api-token`, chmod 600) and run
`tools/cmd/forgejo-package-prune --live-images-file <railiance01 export>`
**Remaining (~5 min, agent-executable after one founder OIDC login —
no PAT files, per ops-warden INTENT §7 / WARDEN-WP-0029):**
`bao login -method=oidc -path=netkingdom role=forgejo-admin-workload-kv-read`
then
`warden access "forgejo admin pat" --field FORGEJO_ADMIN_TOKEN --exec -- tools/cmd/forgejo-package-prune --live-images-file <railiance01 export>`
— if all live tags land in protected/absent from would_delete, T07
acceptance is met and T05 enable + T06 apply unblock.