net-kingdom/workplans/ADHOC-2026-07-02.md
repo-manager d4d61b722e
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a05e30-2884-71b0-98d7-7edd16ae737b
2026-09-04 00:26:59 +02:00

1.7 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
NK-WP-ADHOC-2026-07-02 workplan Ad Hoc Tasks — 2026-07-02 infotech net-kingdom finished codex net-kingdom 2026-07-02 2026-07-02 a9177c57-3f48-5d32-aa04-d1822fb86d47

Ad Hoc Tasks — 2026-07-02

Fix creds-bootstrap-agent Phase 0 dry-run on machines without the age key

id: NK-WP-ADHOC-2026-07-02-T01
status: done
priority: low
state_hub_task_id: "16053545-ed7f-576f-81e0-7095b62a0a1e"

--dry-run previously aborted silently in Phase 0 on any machine without ~/.config/sops/age/keys.txt: key generation is correctly skipped in dry-run, but the subsequent public-key read (grep on the missing file) killed the script under set -e, so no later phase could be exercised.

Fix: when the key file is absent in dry-run, continue with a placeholder recipient and a clear notice instead of dying; live runs without a key still fail hard. Verified: full --dry-run now traverses Phase 0 through Phase 10 including the new Phase 7b OpenBao hook (NET-WP-0020-T02) on a machine with no age key.

Fix broken check-secrets Make target (unescaped $)

id: NK-WP-ADHOC-2026-07-02-T02
status: done
priority: medium
state_hub_task_id: "d86d474c-d6ff-57ed-a111-d10f674cb9e4"

make check-secrets failed with a bash parse error ("unexpected EOF while looking for matching '"): the trailing grep -v '/$' used a single $, which make expanded before bash saw it. Escaped to $$. Verified: make check-secrets passes again ("All secrets/ files appear SOPS-encrypted"). Pre-existing bug, unrelated to NET-WP-0020; found while running the final checks for that workplan.