`ADHOC-YYYY-MM-DD` is unique per date but not per repository, so any two repos
opening an ad-hoc on the same day collide. The 2026-08-26 fleet projection
reset refused 9 records for exactly this reason.
Canon (work-record-types_v0.1, CUST-WP-0066) settled the form as
`{PREFIX}-WP-ADHOC-YYYY-MM-DD`, filename unchanged, and grandfathered existing
ids on the condition they are never *silently* re-derived. This is the explicit
migration that clause allows for.
The hub id is derived from the record id, so a changed id is a different
record: stale state_hub_*_id fields are dropped and fix-consistency re-derives.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2.2 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated |
|---|---|---|---|---|---|---|---|---|---|
| NK-WP-ADHOC-2026-08-14 | workplan | Close NK-WP-0025 residuals | infotech | net-kingdom | finished | codex | netkingdom | 2026-08-14 | 2026-08-14 |
NK-WP-ADHOC-2026-08-14 - NK-WP-0025 residual closeout
Reconcile Coulomb Social Case B residual records
id: NK-WP-ADHOC-2026-08-14-T01
status: done
priority: medium
Update the owning smoke evidence and close or narrow CSOC-IN-0001 and CSOC-IN-0002 now that NK-WP-0025 completed the public registration, OIDC/JIT, repeat-login, collision, redirect, and assurance evidence.
Protect the canonical LDAP-DN subject contract
id: NK-WP-ADHOC-2026-08-14-T02
status: done
priority: medium
Add focused regression coverage for the canonical LDAP-DN OIDC subject and the reverse normalization used by directory lifecycle and password setup.
Persist the audit-core multi-tenant sender scope
id: NK-WP-ADHOC-2026-08-14-T03
status: done
priority: high
Move the live user-engine sender registry from its manually minted Secret to
the authoritative OpenBao/ExternalSecret path with source-bound write-only
scope and tenants: ["*"], without reading or logging its token.
2026-08-14 probe: the live Secret has the correct redacted scope, but
platform/workloads/audit-core/senders does not exist. ClusterSecretStore
openbao-audit-core is present and can read only that exact path. The current
workstation OpenBao identity returns 403 and credential routing exposes no
resolvable write grant. Completion therefore waits for a short-lived
platform-admin OpenBao session to perform the documented wrapped migration;
the temporary probe ExternalSecret was removed.
Done 2026-08-14: after an attended KeyCape/MFA platform-admin login, the
existing registry was streamed directly from Kubernetes to OpenBao without
printing or staging it. OpenBao created version 1; ExternalSecret
audit-core-senders became SecretSynced and owns the derived Secret. Its
base64 checksum remained
dcf342e33fd326c536ee3ada443f294221836e226e5924ac1b2ec490631a3cdb, proving
the migration did not change the live document. The audit-core rollout
completed and /readyz returned durable archive custody.