fluid-telegram/internal
tegwick ff2b19456f Make the secret layout configuration, not a constant
ops-warden routes API-key needs to railiance-platform, whose convention is
platform/workloads/<domain>/<workload>/<bundle>. This repository invented
secret/fluid-telegram/<campaign>/telegram instead, which is not its call to
make -- a service that picks its own paths in someone else's store is how a
policy ends up written around a mistake.

Mount and prefix are now BAO_MOUNT and FLUID_BAO_PREFIX, with the old scheme
kept as a development fallback. The runbook points at `warden access` for the
current shape and at OIDC login rather than a plain token, and names the
check that tells whether a login actually took.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0172sgCZEEDJcnQmr4SGDvKa

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1361245@bnt-lap001
Assistant-Session: b3b428ef-f3e6-4688-b091-01f71461d66a
2026-09-04 22:32:09 +02:00
..
apply Implement the avatar and a preflight dry run 2026-09-04 22:12:56 +02:00
avatar Implement the avatar and a preflight dry run 2026-09-04 22:12:56 +02:00
plan Implement the avatar and a preflight dry run 2026-09-04 22:12:56 +02:00
secrets Make the secret layout configuration, not a constant 2026-09-04 22:32:09 +02:00
spec Implement provision plan: spec, resolved state, and the diff 2026-09-04 21:25:49 +02:00
state Implement provision plan: spec, resolved state, and the diff 2026-09-04 21:25:49 +02:00
tg Implement the avatar and a preflight dry run 2026-09-04 22:12:56 +02:00