feat: adopt security zones and explicit workload refs
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
parent
12c637cbf2
commit
7ce58ae638
52 changed files with 1547 additions and 658 deletions
|
|
@ -61,7 +61,7 @@ Never paste values into chat, State Hub, workplans, or Git.
|
|||
3. **Or proxy via warden access** (same `bao kv get`, audited metadata only):
|
||||
```bash
|
||||
warden route show reuse-surface-hub-write-token --json
|
||||
warden access reuse-surface-hub-write-token --no-policy --fetch
|
||||
warden access reuse-surface-hub-write-token --fetch
|
||||
```
|
||||
|
||||
4. **Webhook HMAC** (same path, second field — must match Forgejo org webhook):
|
||||
|
|
@ -87,4 +87,4 @@ Never paste values into chat, State Hub, workplans, or Git.
|
|||
Rotation: `railiance-platform/docs/reuse-surface-runtime-secrets-rotation-runbook.md`
|
||||
(OpenBao patch → ESO `force-sync` → hub rollout → `make reuse-forgejo-webhook` when
|
||||
the webhook HMAC changes → `make reuse-webhook-smoke`). Lifecycle:
|
||||
`railiance-platform/docs/credential-lane-lifecycle-runbook.md` (CCR-2026-0005).
|
||||
`railiance-platform/docs/credential-lane-lifecycle-runbook.md` (CCR-2026-0005).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue