The founder chose to mint fresh tokens for both worker identities. Add the reviewed, idempotent, silent script for the attended OpenBao admin lane, and the cutover order that keeps the claim loop's gap to seconds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 151606@bnt-lap001 Assistant-Session: 3c0a4ad5-bb8b-4bf7-b9f0-fa5f29204e48
40 lines
1.4 KiB
Bash
Executable file
40 lines
1.4 KiB
Bash
Executable file
#!/bin/sh
|
|
# ACTIVITY-WP-0039-T03 (option b): mint fresh ops_run worker tokens into OpenBao.
|
|
#
|
|
# Founder-attended only, through the silent admin lane (orientation section 5):
|
|
#
|
|
# BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 \
|
|
# warden access openbao-platform-admin-login --exec -- \
|
|
# sh scripts/wp0039-seed-worker-tokens.sh
|
|
#
|
|
# Silent by design: warden fails closed on any child output. The value is
|
|
# generated inside a pipe and sent to bao on stdin, so it never appears in
|
|
# argv, output, Git, or the hub. Idempotent: an existing path is never
|
|
# overwritten. Rerunning after success is a no-op that re-verifies.
|
|
#
|
|
# Exit codes: 0 both paths present and verified · 3 a path exists without a
|
|
# usable token field (left untouched) · 4 write failed · 5 verification failed.
|
|
exec >/dev/null 2>&1
|
|
set -u
|
|
|
|
MOUNT=platform
|
|
BASE=workloads/activity-core/ops-run-workers
|
|
PATHS="rein-aharness-railiance01 rein-aharness-metered-railiance01"
|
|
|
|
token_len() {
|
|
bao kv get -mount="$MOUNT" -field=token "$BASE/$1" 2>/dev/null | tr -d '\n' | wc -c
|
|
}
|
|
|
|
for slug in $PATHS; do
|
|
if bao kv metadata get -mount="$MOUNT" "$BASE/$slug"; then
|
|
[ "$(token_len "$slug")" -eq 64 ] || exit 3
|
|
continue
|
|
fi
|
|
openssl rand -hex 32 | tr -d '\n' \
|
|
| bao kv put -mount="$MOUNT" "$BASE/$slug" token=- || exit 4
|
|
done
|
|
|
|
for slug in $PATHS; do
|
|
[ "$(token_len "$slug")" -eq 64 ] || exit 5
|
|
done
|
|
exit 0
|