deploy: add verified secrets-engine production policy pin
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
tegwick 2026-09-06 19:45:40 +02:00
parent b7cc96b7b2
commit 0b4e5c28bc
3 changed files with 59 additions and 1 deletions

View file

@ -110,3 +110,14 @@ or re-apply the last-known-good digest in `deploy/README.md`.
| `flex-auth-user-engine` | `sha256:138aa3471c46bca6e814691fa1e6520aedda3dffd743e6b09141ab433afdb64b` | **live** — caller-auth enforce (FLEX-WP-0015-T02), CI `main-3de72fe`, A2 probe 2026-08-19 |
| `flex-auth-user-engine` *(previous)* | `sha256:1f5290376dc5fcf456dc7a785e394d8b90949dabecd1d3e856f38557149bb5f4` | FLEX-WP-0009-T04, nine fixtures, live 2026-08-16 |
| `flex-auth-user-engine` *(previous)* | `sha256:a31961c45215aa6baf3bc748c6741ab703c2c8325e61aa7983a355026195e51b` | FLEX-WP-0009-T03, six fixtures |
## Secrets-engine production pin (2026-09-06)
`values/secrets-engine.yaml` deploys the independent release
`flex-auth-secrets-engine` in namespace `flex-auth`. Service DNS is
`flex-auth-secrets-engine.flex-auth.svc.cluster.local:8080`, package
`secrets-engine.catalog-lane.lifecycle` v1. Revision 1 uses CI main-dd3ce4c
by immutable digest, caller-auth warn, and ingress restricted to namespace
secrets-engine/pod label app.kubernetes.io/name=secrets-engine. Do not promote
to enforce until the consumer identity is adopted and verified. See
FLEX-WP-0021 for positive/negative policy and network evidence.