feat: prepare scoped State Hub preflight signing custody and rotation
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
This commit is contained in:
codex 2026-09-05 16:38:26 +02:00
parent a46a6d8213
commit 5d288938f7
4 changed files with 117 additions and 8 deletions

View file

@ -3,7 +3,7 @@ kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: State Hub repository-rename preflight signing read lane
status: proposed
status: approved
created: '2026-09-05'
updated: '2026-09-05'
requester:
@ -23,6 +23,19 @@ review:
comment: 'Live primary/railiance01: namespace/release/deployment state-hub, API
SA state-hub, one replica; ESO CRD supports serviceAccountRef.audiences. New
dedicated delivery identity requires live acceptance.'
- at: '2026-09-05T14:37:03+00:00'
reviewer: codex
decision: binding_confirmed
comment: Live dedicated state-hub/state-hub-preflight-eso ServiceAccount observed;
minted subject and audience openbao verified by TokenReview. API workload TokenRequest
and ExternalSecret create denied.
- at: '2026-09-05T14:37:03+00:00'
reviewer: user via RPF-WP-0035-T04 instruction
decision: approved
comment: User explicitly requested execution of RPF-WP-0035-T04 on 2026-09-05.
Scope is the reviewed transitional State Hub signing lane, exact data-only ESO
grant and protected CAS writer with controlled-outage rotation acceptance. No
repository rename authorized. Operator OIDC remains required.
target:
domain: infotech
tenant: state-hub
@ -47,7 +60,7 @@ openbao:
- state-hub-preflight-eso
service_account_namespaces:
- state-hub
bound_claims_confirmed: false
bound_claims_confirmed: true
policies:
- workload-kv-read-state-hub-rename-preflight
ttl: 15m