Close CCR drift and high-risk policy gaps
This commit is contained in:
parent
852a8ab661
commit
382f04412a
12 changed files with 577 additions and 68 deletions
|
|
@ -5,7 +5,7 @@ request_type: workload-kv-read
|
|||
title: email-connect transactional SMTP and ingest token lane
|
||||
status: active
|
||||
created: '2026-08-12'
|
||||
updated: '2026-08-12'
|
||||
updated: '2026-08-21'
|
||||
requester:
|
||||
agent: grok
|
||||
reason: >-
|
||||
|
|
@ -117,6 +117,15 @@ verification:
|
|||
railiance01, namespace-scoped to email-connect.
|
||||
- Secret value provisioned directly in OpenBao through approved operator custody.
|
||||
- Positive and negative verification recorded with non-secret audit ids or timestamps.
|
||||
evidence:
|
||||
- at: '2026-08-20T22:56:00+00:00'
|
||||
actor: codex
|
||||
kind: auth_path_reconciliation
|
||||
result: passed
|
||||
details:
|
||||
- Live ClusterSecretStore openbao-email-connect uses tokenSecretRef external-secrets/openbao-email-connect-eso-token,
|
||||
is namespace-limited to email-connect, and reports Valid.
|
||||
- ExternalSecret email-connect-runtime reports SecretSynced. No Secret value was read.
|
||||
lifecycle:
|
||||
deactivate: Disable ops-warden catalog entry and detach ESO role policy.
|
||||
rotate: >-
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue