Record the sign-out page image.

Assistant: grok
Assistant-Session: 01a0d25d-d358-7e13-b84a-d007fbb7e34f
This commit is contained in:
tegwick 2026-09-27 00:58:22 +02:00
parent 13afaa916d
commit df823d3950

View file

@ -174,14 +174,23 @@ workload or customer data, any sign the transcript left the workstation, or a
planned key rotation. The same workplan removes the problem class by giving
agents a cluster identity that cannot read these objects at all.
## Fail-closed startup changes shipped in the live image
## Current image (2026-09-26)
The live issuer is
`sha256:82f1e5ac481e4f963dbd4b05256aee75412c9e9b465d31c9356f5d17f26a6897`,
source `13afaa9`. The sign-out confirmation uses the NetKingdom Identity
page design. Recorded as `ADMINISTER @ realm:kubernetes/railiance01`,
`activation=APPROVED`. The patch replaced only the image. Strategy stayed
Recreate and requests stayed 25m/32Mi. Rollback is
`sha256:8dc35801d1d2b0905a43530c40b1fed0107fc179141fe5b2b614c52c01714fc9`.
## Fail-closed startup changes from source 11ce29a
These remain in the current image. They first shipped in
`sha256:8dc35801d1d2b0905a43530c40b1fed0107fc179141fe5b2b614c52c01714fc9`,
Forgejo run 69, source `11ce29a`, confirmed running on 2026-09-25. The changes
below shipped in that image. They fail closed. The 2026-09-24 Vergabe journey
completed after one token-exchange failure; see
`docs/evidence/2026-09-24-fresh-login-and-account-switch.md`.
Forgejo run 69, source `11ce29a`, confirmed running on 2026-09-25. They fail
closed. The 2026-09-24 Vergabe journey completed after one token-exchange
failure; see `docs/evidence/2026-09-24-fresh-login-and-account-switch.md`.
**1. Browser clients reject service-identity fields (`74b35b6`, KEY-WP-0028).**
Config validation now rejects `serviceSubject` or `roles` on a client whose