net-kingdom/workplans/archived/260702-ADHOC-2026-06-14.md
repo-manager d9baa06f7e
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3377672@bnt-lap001
Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166
2026-08-28 11:56:08 +02:00

1.2 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
NK-WP-ADHOC-2026-06-14 workplan Ad hoc NetKingdom operator usability fixes netkingdom net-kingdom finished codex netkingdom 2026-06-14 2026-06-14 3ad3848e-00be-55a7-99e2-bc31047ea847

Terminology note: Historical text in this archived workplan may use the legacy term "workstream". The fleet term is workplan (canon/standards/workplan-terminology-fleet_v0.1.md).

Ad hoc NetKingdom operator usability fixes

SOPS Custody Unlock Helper

id: NK-WP-ADHOC-2026-06-14-T01
status: done
priority: medium

Added a custody unlock helper for SOPS/age operations so drills and incident commands can use the password-safe/offline custody age private key without installing it permanently on a workstation.

The helper validates the supplied private key against the expected public age recipient, writes a temporary 0600 SOPS_AGE_KEY_FILE, runs the requested command or opens an incident shell, and removes the temporary key on exit.

Documented the inter-hub recovery-drill path:

make sops-custody-run COMMAND='make -C /home/worsch/inter-hub recovery-drill'