kaizen-agentic/engagements/pilots/eng-coulomb-railiance01-ho-001/access-plan.md

34 lines
1.1 KiB
Markdown
Raw Normal View History

# Access plan — eng-coulomb-railiance01-ho-001
**Target:** host `railiance01`
**Classes requested:** `host_observe`, `privileged_ops` (gated)
**Secrets:** never stored in this tree
## Intended path
| Step | Action | Owner |
|------|--------|-------|
| 1 | Inventory / facts from `railiance-hosts` (read-only) | operator |
| 2 | SSH cert via ops-warden (`warden sign` / `cert_command`) identity hint `agt` | operator |
| 3 | Tunnel if needed (`ops-bridge`, e.g. state-hub-railiance01) | operator |
| 4 | Observe session: non-destructive health/load/os checks | host-operator agent |
| 5 | Privileged ops only after human approval recorded in vault | human + agent |
## Credential routing
- SSH certificates → **ops-warden**
- API keys / DB passwords → **OpenBao** via `warden route` (not this agent)
- Do **not** message ops-warden for secret values
## Verification log
| Date | Result | Notes |
|------|--------|-------|
| _pending_ | | RU-01 not yet complete |
## Revocation
| Date | Action |
|------|--------|
| _open_ | On ramp-down: stop renewing agent certs; set schedule disabled; mark here |