Harden ops run identity and leases
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 33s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028de-e2c8-7732-8521-46a7fc5db82f
This commit is contained in:
tegwick 2026-08-23 13:01:46 +02:00
parent 36161d346f
commit f0a897e088
13 changed files with 522 additions and 50 deletions

View file

@ -41,8 +41,10 @@ host-network bridge and workstation tunnel are not part of this deployment.
`OPS_RUN_QUEUE_ENABLED=true`. After image + migrate job (alembic **0007**),
workers insert claimable `ops_runs` on emit. Full railiance checklist:
`docs/deploy-ops-run-queue-railiance.md`. Keep host timers until REIN-A-0002.
Optional `ACTIVITY_CORE_WORKER_TOKEN` in `actcore-runtime-secret` for harness
claim auth.
`ACTIVITY_CORE_WORKER_TOKEN` in `actcore-runtime-secret` authenticates the
harness claim client. The non-secret `ACTIVITY_CORE_WORKER_ID` in the runtime
ConfigMap binds that credential to `rein-aharness@railiance01`; deploy both
settings together.
| ExternalSecret | OpenBao path | Secret key |
| --- | --- | --- |