Catalog id email-connect-transactional (active) with OpenBao pointer playbook for CCR-2026-0010 / EMAIL-WP-0004 custody.
2.8 KiB
email-connect transactional SMTP + ingest token
Date: 2026-08-12
Workplan: EMAIL-WP-0004-T03 · CCR-2026-0010
Catalog: email-connect-transactional (active — OpenBao path live, ESO delivering on railiance01)
Pointer playbook for the IONOS STARTTLS credentials and shared caller bearer
used by the email-connect transactional invitation/verification receiver on
railiance01. ops-warden issues SSH certs only — SMTP passwords and API tokens
are OpenBao → Kubernetes Secret actions owned by railiance-platform and the
email-connect package.
Owners
| Concern | Owner repo | Authoritative doc |
|---|---|---|
| OpenBao path, ESO policy/role, ClusterSecretStore | railiance-platform |
docs/workload-kv-access-lanes.md — email-connect section |
| K8s package, NetworkPolicy, probes, rollback | email-connect |
deploy/k8s/railiance/README.md |
| user-engine caller wiring (same ingest token) | net-kingdom / user-engine |
NK-WP-0024 |
Do not ask ops-warden
warden route show openbao-api-key --json
warden route show email-connect-transactional --json
EMAIL_CONNECT_SMTP_PASSWORD and EMAIL_CONNECT_INGEST_TOKEN must not appear
in Git, State Hub, workplans, logs, or chat.
Custody shape (proposed)
platform/workloads/email-connect/transactional
Properties:
EMAIL_CONNECT_INGEST_TOKENEMAIL_CONNECT_SMTP_USERNAMEEMAIL_CONNECT_SMTP_PASSWORD
Delivery: ExternalSecret email-connect/email-connect-runtime
(ClusterSecretStore openbao-email-connect, ESO policy
external-secrets-email-connect) → Secret email-connect-runtime.
Non-secret host/port/sender/portal URL: ConfigMap email-connect-config.
Worker checklist
1. Confirm need
- Consumer is the transactional receiver in namespace
email-connect - Need is SMTP send or shared ingest token — not Binky IMAP mailbox scan
(
binky-company-email-imapis a different lane) - CCR-2026-0010 is approved before live provision
2. Platform path
- Path provisioned under
platform/workloads/email-connect/transactional - ESO role
external-secrets-email-connectapplied - ClusterSecretStore
openbao-email-connectnamespace-limited
3. Deployment wiring
kubectl apply -k deploy/k8s/railiance(email-connect repo)- ExternalSecret SecretSynced; Deployment Ready
- user-engine holds the same ingest token; no SMTP fields there
4. Smoke
/healthzfrom a user-engine pod succeeds- A pod outside user-engine cannot reach TCP 8080
- Record non-secret evidence only (timestamps, request ids, Ready status)
Related lanes
| Catalog id | Relationship |
|---|---|
binky-company-email-imap |
Mailbox read for evidence scans — not this send path |
openbao-api-key |
Generic pointer when no concrete lane exists |