WARDEN-WP-0028: promote binky-company-email-imap active
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Founder provisioned IMAP on tenants/ (KV v2); capabilities-safe verify
pass. Catalog resolvable; workplan finished.
This commit is contained in:
tegwick 2026-07-17 00:33:20 +02:00
parent 6b5432229f
commit 053a1d7cee
5 changed files with 24 additions and 8 deletions

View file

@ -401,11 +401,11 @@ entries:
wiki_ref: wiki/playbooks/binky-company-email-imap.md#worker-checklist
canon_ref: railiance-platform/docs/workload-kv-access-lanes.md
reviewed: "2026-07-17"
status: draft
status: active
risk: high
# CCR-2026-0007: tenants/ mount + policy + OIDC role applied 2026-07-17.
# Values: founder Red provision pending. Promote to active after provision +
# capabilities-safe verify. Sibling non-secret host/port in email-connect config.
# CCR-2026-0007: tenants/ mount + policy + OIDC role applied; founder provisioned
# values via UI (version ≥2, not placeholder). Capabilities-safe verify 2026-07-17:
# lane-policy read; default deny. Host: imap.ionos.de:993 (binky-control config).
auth_method: "caller's own OpenBao token (OIDC netkingdom role binky-company-email-imap-workload-kv-read)"
path_template: "tenants/binky/company-email/imap"
fetch_command: "bao kv get -field=IMAP_PASSWORD tenants/binky/company-email/imap"