BINKY-WP-0004-T03: executor worker secret lanes prepared

- Lane 1 (LLM provider): reuse verified — warden catalog
  openrouter-llm-connect, policy workload-kv-read-llm-connect-provider-secrets
- Lane 2 (forgejo deploy key): new, per-repo write deploy key design,
  founder Red lane
- Lane 3 (mail-scan AppRole): executor-worker-binky-mail bound to the
  existing IMAP read policy — closes email checklist item 9's auth
  blocker on paper; provisioning founder Red lane
- No secret values anywhere; T04 can proceed on Lane 1 alone

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-07-17 17:08:33 +02:00
parent 0f91a98d08
commit ce14c254db
3 changed files with 92 additions and 3 deletions

View file

@ -97,7 +97,10 @@ Scan output under `mailmeta/` — metadata only (no message bodies in git).
`mailmeta/reports/` (scan c3c7e784…). Notable: Stripe webhook
failure notice, Qonto Beleg reminders, HUB31 correspondence,
2 suspicious external mails (ignored, never acted on)
9. [ ] Recurring scan via activity-core (BINKY-WP-0003 follow-ons)
9. [ ] Recurring scan via activity-core (BINKY-WP-0004 T03/T05; auth
blocker solved on paper — non-interactive AppRole lane designed in
`integrations/executor-worker-secrets.md`, provisioning is founder
Red lane)
### Founder provision (step 6) — interactive human shell