Add attended SMTP verification and exact reader admission
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
parent
3d43a9b1a3
commit
56fcc4c921
3 changed files with 183 additions and 0 deletions
|
|
@ -28,3 +28,28 @@ completed-but-revocation-unconfirmed means creation ran but session revocation
|
|||
requires attention. Native creation is pending until that attended result.
|
||||
This helper does not grant ESO access, copy another mailbox's credential, or
|
||||
activate SMTP. Scoped workload delivery remains the existing telemetry task.
|
||||
|
||||
## Password supplied; scoped delivery admission
|
||||
|
||||
The founder reports SMTP_PASSWORD added. This is not yet native verification.
|
||||
The dedicated telemetry-smtp-eso ServiceAccount and package-owned
|
||||
acknowledgment/smtp-custody.yaml are installed after dry-run and diff.
|
||||
They project only SMTP_PASSWORD to telemetry/telemetry-alert-smtp:password.
|
||||
|
||||
The next attended command validates the exact public settings and password,
|
||||
performs certificate-verified IONOS STARTTLS authentication without sending mail,
|
||||
and admits the exact read-only policy and Kubernetes role (telemetry namespace,
|
||||
telemetry-smtp-eso ServiceAccount, openbao audience, maximum 15 minutes).
|
||||
Existing different policy/role values fail closed. Mailbox versions are untouched.
|
||||
Coding-agent deny boundary is extended for data and metadata and tested.
|
||||
|
||||
```sh
|
||||
BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 warden access openbao-platform-admin-login --exec -- python3 /home/worsch/railiance-platform/scripts/telemetry_smtp_delivery.py --receipt /tmp/telemetry-smtp-delivery.json
|
||||
```
|
||||
|
||||
Use a new receipt filename on retry; existing evidence is never overwritten.
|
||||
The helper is silent and writes only fixed status fields/KV version in its
|
||||
0600 receipt. It never reads Kubernetes Secret values. Ten custody tests pass.
|
||||
After successful attended completion, check ClusterSecretStore/ExternalSecret
|
||||
Ready and record the receipt. Actual scoped Kubernetes auth and ESO delivery
|
||||
remain unproved until that reconciliation. The alert route is still disabled.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue