Complete live State Hub signing activation and rotation acceptance
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 18:12:37 +02:00
parent ae27a42b18
commit 5d6d8724b4
7 changed files with 167 additions and 9 deletions

View file

@ -98,7 +98,7 @@ The unattended adapter remains a separate demand and gets no operator session.
```task
id: RPF-WP-0035-T04
status: progress
status: done
priority: medium
state_hub_task_id: "35a85846-61d5-54ce-8b18-ede45733d53c"
```
@ -130,3 +130,13 @@ workstation kubeconfig's local port-forward listener was unavailable. Activation
still needs the contained attended OIDC/MFA login and the acceptance evidence
above; source preparation is not live completion. See
`history/2026-09-05-preflight-signing-activation-readiness.md`.
Completed 2026-09-05: user-led attended activation generated version 1 and
rotated to version 2 with every API replica stopped. Exact access and negative
identity checks passed; ESO delivery and API-only exposure passed; the recovered
single API replica accepts new signed preflight and rejects its predecessor by
signature, with healthy primary identity and no preflight blockers. State Hub
chart commit `49e3182`, Helm revision 59. No repository rename executed.
Evidence: `docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json`;
closure: `history/2026-09-05-preflight-signing-activation-complete.md`.