feat: adopt security zones and explicit workload refs
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
tegwick 2026-08-22 15:36:37 +02:00
parent 12c637cbf2
commit 7ce58ae638
52 changed files with 1547 additions and 658 deletions

View file

@ -61,7 +61,7 @@ Never paste values into chat, State Hub, workplans, or Git.
3. **Or proxy via warden access** (same `bao kv get`, audited metadata only):
```bash
warden route show reuse-surface-hub-write-token --json
warden access reuse-surface-hub-write-token --no-policy --fetch
warden access reuse-surface-hub-write-token --fetch
```
4. **Webhook HMAC** (same path, second field — must match Forgejo org webhook):
@ -87,4 +87,4 @@ Never paste values into chat, State Hub, workplans, or Git.
Rotation: `railiance-platform/docs/reuse-surface-runtime-secrets-rotation-runbook.md`
(OpenBao patch → ESO `force-sync` → hub rollout → `make reuse-forgejo-webhook` when
the webhook HMAC changes → `make reuse-webhook-smoke`). Lifecycle:
`railiance-platform/docs/credential-lane-lifecycle-runbook.md` (CCR-2026-0005).
`railiance-platform/docs/credential-lane-lifecycle-runbook.md` (CCR-2026-0005).