docs: establish attended recovery drill scenario
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0290b-3241-74c3-b868-6049545af836
This commit is contained in:
parent
2c1fc25e43
commit
5ac47520b1
2 changed files with 82 additions and 0 deletions
|
|
@ -160,6 +160,16 @@ the generic `openbao-api-key` template and proposed paste-once provisioning.
|
|||
ceremony from secret retrieval. It is a non-value-bearing pointer and can never
|
||||
offer `--fetch`, `--exec`, `--out`, `--wrap`, or paste-once share transport.
|
||||
|
||||
**Scenario established 2026-08-22.** The operator delegated preparation to the
|
||||
agent and reserved their involvement for the final GO/NO-GO. The bounded,
|
||||
non-secret scenario is
|
||||
`docs/evidence/WARDEN-WP-0027-T02-drill-scenario-2026-08-22.md`: ops-warden
|
||||
coordinates and enforces the hold point; railiance-platform is the proposed
|
||||
OpenBao driver; railiance-infra is the proposed independent console/abort owner;
|
||||
and railiance-master is asked only for a metadata-only 2-of-3 availability
|
||||
attestation. All three owner receipts and a green fully parameterized preflight
|
||||
are required before the final operator question.
|
||||
|
||||
## Task: Tamper-evident policy governance + reconcile
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue