RPF-WP-0046-T06: eso.token-renewal assurance signal; plan finished
Some checks are pending
CI Smoke / container-smoke (push) Waiting to run
CI Smoke / host-smoke (push) Successful in 0s

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
This commit is contained in:
codex 2026-09-24 00:48:24 +02:00
parent 8f7aa1bb77
commit 52224b84f8
5 changed files with 60 additions and 2 deletions

View file

@ -54,6 +54,13 @@ lag guarantee. The fleet ESO aggregate is deliberately a conservative inventory
check; an obsolete resource must be explicitly classified by its owner before
it is excluded. One ESO failure cannot disappear inside an average.
`eso.token-renewal` (RPF-WP-0046) is the last successful run of the
`external-secrets/eso-token-renewer` CronJob. The CronJob keeps the periodic
parent tokens of the five dynamic-database stores alive. The signal reads
CronJob status timestamps only. It fails when a newer scheduled run has not
succeeded within an hour, and it goes stale after 36h. The tokens lapse after
7 days without renewal.
The following remain missing until a native value-safe adapter and acceptance
exist: validated isolated restore receipts,
OpenBao snapshot/restore proof, and offsite upload/restore receipts. Missing