deploy: add verified secrets-engine production policy pin
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
parent
b7cc96b7b2
commit
0b4e5c28bc
3 changed files with 59 additions and 1 deletions
|
|
@ -110,3 +110,14 @@ or re-apply the last-known-good digest in `deploy/README.md`.
|
|||
| `flex-auth-user-engine` | `sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b` | **live** — caller-auth enforce (FLEX-WP-0015-T02), CI `main-3de72fe`, A2 probe 2026-08-19 |
|
||||
| `flex-auth-user-engine` *(previous)* | `sha256:1f5290376dc5fcf456dc7a785e394d8b90949dabecd1d3e856f38557149bb5f4` | FLEX-WP-0009-T04, nine fixtures, live 2026-08-16 |
|
||||
| `flex-auth-user-engine` *(previous)* | `sha256:a31961c45215aa6baf3bc748c6741ab703c2c8325e61aa7983a355026195e51b` | FLEX-WP-0009-T03, six fixtures |
|
||||
|
||||
## Secrets-engine production pin (2026-09-06)
|
||||
|
||||
`values/secrets-engine.yaml` deploys the independent release
|
||||
`flex-auth-secrets-engine` in namespace `flex-auth`. Service DNS is
|
||||
`flex-auth-secrets-engine.flex-auth.svc.cluster.local:8080`, package
|
||||
`secrets-engine.catalog-lane.lifecycle` v1. Revision 1 uses CI main-dd3ce4c
|
||||
by immutable digest, caller-auth warn, and ingress restricted to namespace
|
||||
secrets-engine/pod label app.kubernetes.io/name=secrets-engine. Do not promote
|
||||
to enforce until the consumer identity is adopted and verified. See
|
||||
FLEX-WP-0021 for positive/negative policy and network evidence.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue