Close CCR drift and high-risk policy gaps
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
codex 2026-08-21 01:29:28 +02:00
parent 852a8ab661
commit 382f04412a
12 changed files with 577 additions and 68 deletions

View file

@ -5,7 +5,7 @@ request_type: workload-kv-read
title: email-connect transactional SMTP and ingest token lane
status: active
created: '2026-08-12'
updated: '2026-08-12'
updated: '2026-08-21'
requester:
agent: grok
reason: >-
@ -117,6 +117,15 @@ verification:
railiance01, namespace-scoped to email-connect.
- Secret value provisioned directly in OpenBao through approved operator custody.
- Positive and negative verification recorded with non-secret audit ids or timestamps.
evidence:
- at: '2026-08-20T22:56:00+00:00'
actor: codex
kind: auth_path_reconciliation
result: passed
details:
- Live ClusterSecretStore openbao-email-connect uses tokenSecretRef external-secrets/openbao-email-connect-eso-token,
is namespace-limited to email-connect, and reports Valid.
- ExternalSecret email-connect-runtime reports SecretSynced. No Secret value was read.
lifecycle:
deactivate: Disable ops-warden catalog entry and detach ESO role policy.
rotate: >-