cutover runbook: deploy-key attach via warden lane, not founder UI clicks

Per ops-warden INTENT §7 / WARDEN-WP-0029 (founder directive 2026-07-18).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-07-18 14:27:23 +02:00
parent 7425750e2b
commit b6c583f411

View file

@ -11,8 +11,12 @@
2. ~~Lane 2 + Lane 3 Red-lane provisioning~~ **done 2026-07-17**
(`integrations/executor-worker-secrets.md`): forgejo deploy key on
`coulomb/executor-sandbox` + AppRole `agent-harness-binky-mail` on
railiance01. **Still at cutover:** attach the same deploy key write
access to `coulomb/binky-control`.
railiance01. **Still at cutover** (agent-executable via the
`forgejo-admin-api-token` warden lane — founder act is one OIDC login,
per ops-warden INTENT §7, no UI clicks): fetch the public key from
`platform/workloads/agent-harness/forgejo-deploy-key` and POST it as a
write deploy key to `repos/coulomb/binky-control/keys` via
`warden access "forgejo admin pat" --exec -- …`.
3. ~~Harness on Railiance + tenant onboarding~~ **done 2026-07-18**:
HARNESS-WP-0001-T06 (image + k8s + host smoke) and T07 (instance
manifest + three definition runs). See