Cut audit-core ClusterSecretStores over to the Mason AppRole
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-08-13 10:42:59 +02:00
parent 74575c4f32
commit 52d8545952
2 changed files with 32 additions and 18 deletions

View file

@ -213,8 +213,14 @@ are `SecretSynced`. ops-mason plan
founder approve to replace the interim ESO token with an AppRole. Catalog
draft: `warden route find "audit-core senders" --all`.
Remaining before T02 done: approve the Mason plan (AppRole cutover + empty
KV path), then a live rotation drill. Unseal OpenBao only if it is sealed.
Mason plan approved 2026-08-13 and built: AppRole
`external-secrets-audit-core`, Secret `openbao-audit-core-approle`, both
ClusterSecretStores on AppRole and `Valid`. Interim ESO token Secret
removed. Receiver stayed Ready.
Remaining before T02 done: a live rotation drill (refresh lease, confirm
no delivery gap). Empty senders KV path is a later wrap-migrate, not a
founder paste.
## T03 - Deploy the receiver