Accept now extends a single-schema chain. Verify walks it; a rewritten payload_hash is a break. Tamper evidence is that detector plus an external chain-head attestation, not WORM. |
||
|---|---|---|
| .. | ||
| audit-core.yaml | ||
| clustersecretstore.yaml | ||
| externalsecret-senders.yaml | ||
| externalsecrets.yaml | ||
| migrate-job.yaml | ||
| networkpolicies.yaml | ||
| README.md | ||
| senders-scope.json | ||
| senders-scope.yaml | ||
railiance01 package
Target: railiance01 only. The workstation kubeconfig that talks to that API
is the k3s-api-railiance01 tunnel (local port 16444).
~/.kube/config-hosteurope currently points at 16443 (coulombcore); rewrite
the server port or export a copy before applying.
Apply order is documented in docs/operator-runbook.md. Do not apply the
Deployment until:
- The image digest is pinned (currently
sha256:05fe1c06…from commit40dcadd). - Secrets
audit-core-database,audit-core-database-migrate, andaudit-core-sendersexist. ConfigMapaudit-core-senders-scopeis applied (deploy/senders-scope.yaml) before the Deployment mounts it. - Job
audit-core-migratehas completed.
make image-build
make deploy-dry-run