BINKY-WP-0004-T03: executor worker secret lanes prepared

- Lane 1 (LLM provider): reuse verified — warden catalog
  openrouter-llm-connect, policy workload-kv-read-llm-connect-provider-secrets
- Lane 2 (forgejo deploy key): new, per-repo write deploy key design,
  founder Red lane
- Lane 3 (mail-scan AppRole): executor-worker-binky-mail bound to the
  existing IMAP read policy — closes email checklist item 9's auth
  blocker on paper; provisioning founder Red lane
- No secret values anywhere; T04 can proceed on Lane 1 alone

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-07-17 17:08:33 +02:00
parent 0f91a98d08
commit ce14c254db
3 changed files with 92 additions and 3 deletions

View file

@ -42,7 +42,7 @@ or direct PR in that repo per its governance. Green lane (code + tests).
```task
id: BINKY-WP-0004-T02
status: todo
status: done
priority: high
state_hub_task_id: "b44af058-22e4-4d63-a28c-8f6c69d65ea1"
```
@ -60,7 +60,7 @@ Catalog metadata only; any new secret provisioning is founder Red lane.
```task
id: BINKY-WP-0004-T03
status: todo
status: done
priority: medium
state_hub_task_id: "e4740aa0-94f7-4ebe-9217-aaca3ef902cc"
```