Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014535@bnt-lap001 Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
1.7 KiB
1.7 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | state_hub_workstream_id |
|---|---|---|---|---|---|---|---|---|---|---|
| WARDEN-WP-ADHOC-2026-06-29 | workplan | Ad Hoc Tasks — 2026-06-29 | infotech | ops-warden | finished | claude | custodian | 2026-06-29 | 2026-06-29 | 13fa845f-852e-55ec-a2a5-2296996e0216 |
Ad Hoc Tasks — 2026-06-29
T01 — Joint-smoke mode for the deployed flex-auth (assist FLEX-WP-0007 T4)
id: WARDEN-WP-ADHOC-2026-06-29-T01
status: done
priority: medium
flex-auth (msg ea00620b) asked ops-warden to help close FLEX-WP-0007 T4 (joint OpenBao
- policy-gate production smoke). Their deployed runtime is reachable on CoulombCore via
the flex-auth-coulombcore tunnel at
127.0.0.1:18090, butpolicy_gate_production_smoke.shspawned its own local flex-auth binary — so it never exercised the deployed runtime.
- Added
FLEX_AUTH_EXTERNAL=1mode toscripts/policy_gate_production_smoke.sh: skips the localserve/load-registryand runs the allow/deny/vault paths against the already-running deployed flex-auth, with a/healthzprecheck that fails fast with a "is the flex-auth-coulombcore tunnel up?" hint (verified: clean exit 2 when down). - Verified the committed
production_registry_snapshot.jsonis current (rebuilt from~/.config/warden/inventory.yaml, diff-clean; 4 actors). - Answered flex-auth's three questions and handed the operator the exact CoulombCore
runbook (see reply). Remaining T4 steps are operator-gated and cannot run from the
workstation: mint a scoped
VAULT_TOKEN(ops-warden holds no standing token by design), run the joint smoke on CoulombCore, then flippolicy.enabled: true.