Pin deployed secrets-engine tenant policy v2
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
tegwick 2026-09-06 21:39:10 +02:00
parent cc311056b9
commit a96e970007
3 changed files with 22 additions and 2 deletions

View file

@ -299,3 +299,17 @@ waiting on consumer configuration/adoption and the owner handoff. Approval
service, KeyCape clients and real credential-lane activation are not supplied
by this deployment. First-install rollback is removal of this dedicated Helm
release, leaving the three existing consumers untouched.
## v2 production correction applied — 2026-09-06
Glas applied the existing operator production authorization to correct the
reported v1 tenant fail-open. Helm revision 2 uses CI main-d98323b digest
sha256:db1c4f7e621c7ea119489a321d7db0e05da09afc17be5f69d873b2b3c7f60cfc.
Lint/server dry-run/rollout passed. Six published Check requests on the live
service returned expected two allows/four denies, including wrong_tenant;
all matched_policy_version values are v2. Other consumer Deployment specs
are unchanged. Values pin updated. Caller authentication remains warn;
workstation consumer access/adoption remains outstanding despite T05 closure.
Glas has sent a follow-up requesting an explicit live owner work record for
that gate. Do not roll back to known over-permissive v1; stop this dedicated
release if v2 cannot be served.