Add attended SMTP verification and exact reader admission
All checks were successful
CI Smoke / host-smoke (push) Successful in 2s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
codex 2026-09-28 11:21:57 +02:00
parent 3d43a9b1a3
commit 56fcc4c921
3 changed files with 183 additions and 0 deletions

View file

@ -28,3 +28,28 @@ completed-but-revocation-unconfirmed means creation ran but session revocation
requires attention. Native creation is pending until that attended result.
This helper does not grant ESO access, copy another mailbox's credential, or
activate SMTP. Scoped workload delivery remains the existing telemetry task.
## Password supplied; scoped delivery admission
The founder reports SMTP_PASSWORD added. This is not yet native verification.
The dedicated telemetry-smtp-eso ServiceAccount and package-owned
acknowledgment/smtp-custody.yaml are installed after dry-run and diff.
They project only SMTP_PASSWORD to telemetry/telemetry-alert-smtp:password.
The next attended command validates the exact public settings and password,
performs certificate-verified IONOS STARTTLS authentication without sending mail,
and admits the exact read-only policy and Kubernetes role (telemetry namespace,
telemetry-smtp-eso ServiceAccount, openbao audience, maximum 15 minutes).
Existing different policy/role values fail closed. Mailbox versions are untouched.
Coding-agent deny boundary is extended for data and metadata and tested.
```sh
BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 warden access openbao-platform-admin-login --exec -- python3 /home/worsch/railiance-platform/scripts/telemetry_smtp_delivery.py --receipt /tmp/telemetry-smtp-delivery.json
```
Use a new receipt filename on retry; existing evidence is never overwritten.
The helper is silent and writes only fixed status fields/KV version in its
0600 receipt. It never reads Kubernetes Secret values. Ten custody tests pass.
After successful attended completion, check ClusterSecretStore/ExternalSecret
Ready and record the receipt. Actual scoped Kubernetes auth and ESO delivery
remain unproved until that reconciliation. The alert route is still disabled.