ops-mason/workplans
tegwick 84c36a6c26 feat(mason): build the state-hub forge read lane (MASON-WP-0003-T02)
Policy workload-kv-read-state-hub-forge-derivation and Kubernetes auth
role state-hub-forge-derivation, verified both directions through a
2-minute test token that was revoked after use: read on its own path;
deny on forgejo-admin, on the shared llm-connect provider secrets, and
on the parent metadata path.

Kubernetes auth replaces the approved AppRole. The plan's §2 survey was
written from disk with no OpenBao session and could not see that
kubernetes/ auth is enabled on this cluster; the plan's own phase-4
instruction to re-verify against live state is what surfaced it. Ruled
by the founder at phase 4. No static credential is created, so nothing
has to be delivered into the cluster or rotated.

The live survey also re-checked reuse: workload-kv-read-agent-harness-
forgejo grants one repository deploy key, not organisation-wide read, so
§2's rejection of reuse stands.

ops-mason handled no secret value. The KV path does not exist until
paste_once_provision writes the token.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3377672@bnt-lap001
Assistant-Session: 15463ccf-238f-4e13-b163-93aa25c6d166
2026-08-27 22:49:13 +02:00
..
MASON-0001-statehub-bootstrap.md Mark MASON-0001 bootstrap workplan finished 2026-07-27 02:03:45 +02:00
MASON-WP-0001-foundation.md fix(workplans): declare type: workplan on records the hub already holds 2026-08-26 20:56:05 +02:00
MASON-WP-0002-whitehat-foundational-plane.md close: finish MASON-WP-0002 with governed residual 2026-08-22 11:36:13 +02:00
MASON-WP-0003-state-hub-forge-read-lane.md feat(mason): build the state-hub forge read lane (MASON-WP-0003-T02) 2026-08-27 22:49:13 +02:00