Pin deployed secrets-engine tenant policy v2
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
parent
cc311056b9
commit
a96e970007
3 changed files with 22 additions and 2 deletions
|
|
@ -121,3 +121,9 @@ by immutable digest, caller-auth warn, and ingress restricted to namespace
|
|||
secrets-engine/pod label app.kubernetes.io/name=secrets-engine. Do not promote
|
||||
to enforce until the consumer identity is adopted and verified. See
|
||||
FLEX-WP-0021 for positive/negative policy and network evidence.
|
||||
|
||||
The secrets-engine pin is now revision 2, CI main-d98323b, policy v2, image
|
||||
sha256:db1c4f7e621c7ea119489a321d7db0e05da09afc17be5f69d873b2b3c7f60cfc.
|
||||
Live wrong_tenant denial and all six published requests pass. Revision 1 lacked
|
||||
tenant enforcement and is not a safe rollback target. Workstation caller
|
||||
access remains an adoption gate; warn is not authenticated production adoption.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue