fluid-telegram/internal
tegwick c2ba960aee Adopt the confirmed secret layout
platform/workloads/infotech/fluid-telegram/<campaign>/<key>, confirmed with
the owner. The campaign sits between workload and bundle so two campaigns on
one interface cannot read each other's credentials, and both halves stay
overridable because the layout belongs to railiance-platform.

Records what ops-warden is for while it is fresh: it issues SSH certificates
and routes every other credential need to its owner, so it answers how to
authenticate to OpenBao and never holds what is stored there.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0172sgCZEEDJcnQmr4SGDvKa

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1361245@bnt-lap001
Assistant-Session: b3b428ef-f3e6-4688-b091-01f71461d66a
2026-09-04 23:03:52 +02:00
..
apply Implement the avatar and a preflight dry run 2026-09-04 22:12:56 +02:00
avatar Implement the avatar and a preflight dry run 2026-09-04 22:12:56 +02:00
plan Implement the avatar and a preflight dry run 2026-09-04 22:12:56 +02:00
secrets Adopt the confirmed secret layout 2026-09-04 23:03:52 +02:00
spec Implement provision plan: spec, resolved state, and the diff 2026-09-04 21:25:49 +02:00
state Implement provision plan: spec, resolved state, and the diff 2026-09-04 21:25:49 +02:00
tg Implement the avatar and a preflight dry run 2026-09-04 22:12:56 +02:00