Record built user-engine custody plan
This commit is contained in:
parent
8578a0074d
commit
ecba442fe6
1 changed files with 27 additions and 1 deletions
|
|
@ -3,7 +3,9 @@ id: user-engine-openbao-runtime-custody
|
|||
demand_source: net-kingdom/workplans/NK-WP-0023-T05
|
||||
consumer_repo: net-kingdom
|
||||
credential_type: openbao-approle-kv
|
||||
status: proposed
|
||||
status: built
|
||||
approved_by: "Bernd Worsch"
|
||||
approved_at: "2026-07-30"
|
||||
created: "2026-07-30"
|
||||
updated: "2026-07-30"
|
||||
---
|
||||
|
|
@ -97,3 +99,27 @@ changes.
|
|||
**Decision needed:** approve as proposed, reject, or return with changes.
|
||||
Approval authorizes custody migration and bounded rotation rehearsal, never
|
||||
printing or otherwise disclosing either value.
|
||||
|
||||
## 6. Build result
|
||||
|
||||
Built on 2026-07-30 exactly as approved:
|
||||
|
||||
- created KV path `platform/workloads/user-engine/runtime`;
|
||||
- created policy `workload-kv-read-user-engine-runtime`;
|
||||
- created AppRoles `external-secrets-user-engine` and
|
||||
`external-secrets-sso-user-engine`;
|
||||
- delivered each bootstrap identity directly into its Kubernetes Secret;
|
||||
- created two namespace-restricted ClusterSecretStores and three
|
||||
ExternalSecrets while preserving existing application Secret names;
|
||||
- migrated the two existing values in a wrapped process without printing or
|
||||
staging them;
|
||||
- rehearsed coordinated rotation, waited for all three derived Secrets, and
|
||||
returned both dependent Deployments to Ready;
|
||||
- verified exact-path `read`, sibling-path `deny`, matching derived
|
||||
provisioner tokens, and a live post-rotation identity reconciliation.
|
||||
|
||||
No new secret value requires founder paste-once provisioning. No credential
|
||||
value was written to Git, logs, State Hub, or chat. The two executor audit
|
||||
records are in `audit/build-log.jsonl`; no ops-warden catalog entry is needed
|
||||
because this is an OpenBao/External Secrets runtime lane rather than an SSH
|
||||
certificate route.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue