ops-warden/workplans/WARDEN-WP-0036-attended-login-openbao-output.md
repo-manager 529feeac49
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 00:51:59 +02:00

1.2 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
WARDEN-WP-0036 workplan Accept contained OpenBao login output only after helper persistence infotech ops-warden finished codex attended-login-openbao-output 2026-09-01 2026-09-01 d844c96e-152d-53fa-bff6-e072125ef66c

Repair attended-login handoff

id: WARDEN-WP-0036-T01
status: done
priority: high
state_hub_task_id: "7eb8b9c9-1285-5ada-a17b-1d5bfbb8ba59"

Allow a successful OpenBao login to proceed when its output is fully contained and the private mode-0600 token helper is populated. Continue failing closed on non-zero login, missing persistence, child output, revocation failure, or cleanup failure.

Verify live contained operation

id: WARDEN-WP-0036-T02
status: done
priority: high
state_hub_task_id: "d22bab05-c38b-561f-95de-6c146ce7c6cf"

Run the proxy regression suite, reinstall the CLI, and complete one governed OpenBao platform-admin operation with deterministic self-revocation.

Completed 2026-09-01. The installed CLI completed the governed Policy Nexus Forgejo source bootstrap with all child output contained, then revoked and removed its isolated helper session.