Prepare password-free telemetry SMTP entry for attended custody
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
codex 2026-09-28 11:11:34 +02:00
parent c3607fffea
commit 3d43a9b1a3
3 changed files with 117 additions and 0 deletions

View file

@ -0,0 +1,30 @@
# Telemetry SMTP entry
Existing RTEL-WP-0002-T04; no new task/workplan. Founder requested entry creation
on 2026-09-28 after creating platform@coulomb.social, and will add the password.
KV v2 mount: platform. Entry: workloads/railiance-telemetry/smtp.
Full CLI path: platform/workloads/railiance-telemetry/smtp.
Initial fields: SMTP_HOST=smtp.ionos.de, SMTP_PORT=587,
SMTP_USERNAME=platform@coulomb.social, SMTP_FROM=platform@coulomb.social,
SMTP_STARTTLS=true. SMTP_PASSWORD is deliberately absent until founder update.
Preserve the existing fields when saving that new version.
Attended founder command (requires existing local OpenBao forwarding):
```sh
BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 warden access openbao-platform-admin-login --exec -- python3 /home/worsch/railiance-platform/scripts/telemetry_smtp_entry.py
```
The helper is silent. CAS=0 never overwrites any existing path/version. Existing
version returns without reading values or writing. Four tests cover first
creation, existing version preservation, permission errors and CAS conflict.
Exit 20 invalid metadata; 21 metadata access failure; 22 creation failure;
23 unexpected write version; 24 verification failure; 25 contained failure.
A successful rerun on an existing path only proves presence, not its contents.
Read Warden's printed completion line: login-failed means no child ran;
completed-but-revocation-unconfirmed means creation ran but session revocation
requires attention. Native creation is pending until that attended result.
This helper does not grant ESO access, copy another mailbox's credential, or
activate SMTP. Scoped workload delivery remains the existing telemetry task.