ops-warden/wiki/playbooks/audit-core-senders.md
tegwick 56876ee456 Add draft routing entry audit-core-senders
Pointer-only. Database leases stay on database-dynamic-credentials.
Promote after the Mason AppRole build is verified.
2026-08-13 10:27:13 +02:00

822 B

audit-core sender registry

Worker checklist

This file is a pointer only. ops-warden does not issue sender tokens and does not duplicate the operating procedure.

  • Construction plan: ops-mason/plans/audit-core-openbao-runtime-custody.md
  • Package and operator runbook: audit-core/docs/operator-runbook.md
  • Database leases (separate lane): warden route show database-dynamic-credentials
  • Authoritative senders shape: audit-core/docs/senders.example.json (placeholders only)

First deploy mints sender tokens in-cluster into Secret audit-core/audit-core-senders. The OpenBao path platform/workloads/audit-core/senders is the later authority, filled by a Mason wrap-migrate — not by a founder bao kv put.

Never place a sender token, bearer, or senders.json value in Git, State Hub, logs, or chat.