Adopt the agent environment orientation for KeyCape's live objects.

Write Secrets with kubectl replace in the rotation script, since apply copies
the data into the last-applied annotation. Record in operations.md the
live-change rules that apply here and the open finding: four live Secrets
carry that annotation, and removing it waits for the founder's go-ahead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 352750@bnt-lap001
Assistant-Session: de41ef1c-2113-4dd2-9b92-f318ffa7f98b
This commit is contained in:
tegwick 2026-09-23 22:07:23 +02:00
parent 012e695947
commit 51e541c9a1
3 changed files with 50 additions and 4 deletions

View file

@ -3,6 +3,10 @@
Dev Hub (State Hub API): http://127.0.0.1:8000
MCP server name in `~/.claude.json`: `dev-hub`
**Before production, credential or GitOps work** read
`~/the-custodian/docs/agent-environment-orientation.md`; KeyCape specifics are
in `docs/operations.md`, "Before any live change".
**Step 1 — Orient**
Read the offline-safe brief first — it works without a live hub connection: