feat: adopt security zones and explicit workload refs
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
tegwick 2026-08-22 15:36:37 +02:00
parent 12c637cbf2
commit 7ce58ae638
52 changed files with 1547 additions and 658 deletions

View file

@ -47,10 +47,10 @@ Config (host/port/env names only):
2. Fetch via sanctioned transport (never paste into chat):
```bash
warden access binky-company-email-imap --all --no-policy --out /tmp/imap.user
warden access binky-company-email-imap --all --out /tmp/imap.user
# primary field is IMAP_USERNAME; for password use --field after template support
# or:
warden access binky-company-email-imap --all --no-policy --exec -- \
warden access binky-company-email-imap --all --exec -- \
env IMAP_USERNAME=… # prefer secrets-engine / dual-field exec when wired
```