railiance-platform answered the routing question (msg 7c7228ac): steps 1-2 are executed by the platform operator attended, through the governed openbao-platform-admin-login lane with a unique metadata receipt path, under founder_required attended OIDC via netkingdom role=platform-admin. Nothing else in that repo carries write authority against platform/workloads/. The blocker narrows again -- the AUTHORITY is answered, the ARTIFACT is not. A two-custodian CAS rotation with a service restart is a distinct version-guarded operation needing its own reviewed CCR, which is theirs to write once an owner asks for the rotation. That question is now with key-cape; ops-warden connected the two and did not ask on their behalf. Their executable precedent for the identical two-custodian shape is cited so a rapp-qonto rotation script is not built from a bare `bao kv patch` -- the provider/consumer consistency reason key-cape gave when declining to ship a wrapper, which railiance-platform endorsed unprompted. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C Assistant: claude-code Assistant-Model: opus Assistant-Process: 1276224@bnt-lap001 Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3 |
||
|---|---|---|
| .. | ||
| capabilities | ||
| flex-auth | ||
| generated | ||
| indexes | ||
| policy | ||
| routing | ||
| README.md | ||
Capability Registry
Markdown-first capability index for federation and reuse planning.
Authoring
- Copy a capability entry template (see reuse-surface
templates/capability-entry.template.md). - Add the row to
indexes/capabilities.yaml. - Run
reuse-surface validatefrom a checkout with the CLI installed. - Merge to
mainand verify publish withreuse-surface establish --publish-check.
Federation contract: reuse-surface docs/RegistryFederation.md.