# Access plan — eng-coulomb-railiance01-ho-001 **Target:** host `railiance01` **Classes requested:** `host_observe`, `privileged_ops` (gated) **Secrets:** never stored in this tree ## Intended path | Step | Action | Owner | |------|--------|-------| | 1 | Inventory / facts from `railiance-hosts` (read-only) | operator | | 2 | SSH cert via ops-warden (`warden sign` / `cert_command`) identity hint `agt` | operator | | 3 | Tunnel if needed (`ops-bridge`, e.g. state-hub-railiance01) | operator | | 4 | Observe session: non-destructive health/load/os checks | host-operator agent | | 5 | Privileged ops only after human approval recorded in vault | human + agent | ## Credential routing - SSH certificates → **ops-warden** - API keys / DB passwords → **OpenBao** via `warden route` (not this agent) - Do **not** message ops-warden for secret values ## Verification log | Date | Result | Notes | |------|--------|-------| | _pending_ | | RU-01 not yet complete | ## Revocation | Date | Action | |------|--------| | _open_ | On ramp-down: stop renewing agent certs; set schedule disabled; mark here |