docs: record verified identity provisioner credential repair
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-11 22:00:37 +02:00
parent 2bc6e37f9f
commit c8ad7a85ea
4 changed files with 41 additions and 13 deletions

View file

@ -113,10 +113,9 @@ identity activation and product accounts are retained in RAPPS-WP-0014-T02.
```task
id: NK-WP-0036-T04
status: wait
status: done
priority: high
needs_human: true
intervention_note: "LLDAP rejects the provisioner's current admin login with 401 after reload. Prepared consumer-only reconciliation requires explicit operator acceptance and the current working LLDAP admin credential via hidden terminal input; never send it in chat."
needs_human: false
state_hub_task_id: "3497d77a-1dc2-5fe6-8784-33949321f556"
```
@ -130,8 +129,13 @@ The non-printing, field-only attended repair and seven synthetic tests are
prepared at sso-mfa/k8s/lldap/identity-provisioner-reconcile.py. See
docs/identity-provisioner-bind-repair.md for exact scope, operator input,
metadata guard, candidate authentication, apply, reload and verification.
Live metadata inspect succeeds; live check/apply is pending current operator
custody and acceptance. The unresolved warden route is a pointer, not authority
The operator completed the hidden-input apply on 2026-09-11. Its sanitized
receipt confirms provider_login and consumer_login true, provider_password_changed
false, and the existing Secret resourceVersion advanced from 51345775 to
60026132. Independent consumer login plus directory-read verification returns
reloaded-check-passed; the deployment is ready 1/1 at its unchanged image.
The existing native user can now retry Create login; successful identity linkage
and password setup remain the pilot onboarding task. The unresolved warden route is a pointer, not authority
to export another live Secret. Retain NK-WP-0033's separate incident residuals.
## Make dependency failure visible before another human onboarding attempt