Lock DEC-FDA-001 working defaults; add roles/host-operator package with OS/security and load protocols; scaffold eng-coulomb-railiance01-ho-001 with bound agent, vault, ramp checklists, and Kai quote/ledger.
33 lines
1.1 KiB
Markdown
33 lines
1.1 KiB
Markdown
# Access plan — eng-coulomb-railiance01-ho-001
|
|
|
|
**Target:** host `railiance01`
|
|
**Classes requested:** `host_observe`, `privileged_ops` (gated)
|
|
**Secrets:** never stored in this tree
|
|
|
|
## Intended path
|
|
|
|
| Step | Action | Owner |
|
|
|------|--------|-------|
|
|
| 1 | Inventory / facts from `railiance-hosts` (read-only) | operator |
|
|
| 2 | SSH cert via ops-warden (`warden sign` / `cert_command`) identity hint `agt` | operator |
|
|
| 3 | Tunnel if needed (`ops-bridge`, e.g. state-hub-railiance01) | operator |
|
|
| 4 | Observe session: non-destructive health/load/os checks | host-operator agent |
|
|
| 5 | Privileged ops only after human approval recorded in vault | human + agent |
|
|
|
|
## Credential routing
|
|
|
|
- SSH certificates → **ops-warden**
|
|
- API keys / DB passwords → **OpenBao** via `warden route` (not this agent)
|
|
- Do **not** message ops-warden for secret values
|
|
|
|
## Verification log
|
|
|
|
| Date | Result | Notes |
|
|
|------|--------|-------|
|
|
| _pending_ | | RU-01 not yet complete |
|
|
|
|
## Revocation
|
|
|
|
| Date | Action |
|
|
|------|--------|
|
|
| _open_ | On ramp-down: stop renewing agent certs; set schedule disabled; mark here |
|