RPF-WP-0046-T04: adopt eso-token-renewer Application (pinned b2ebe10); close RPF-WP-0045
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 1s

- WP-0045-T06 done: both dead static-token Secrets deleted after a no-reference recheck.
- Renewer Application moved from drafts to railiance01 applications; inert until
  the AppProject carries batch/CronJob and the root is synced by hand.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
This commit is contained in:
codex 2026-09-23 20:17:42 +02:00
parent fe1665d1d0
commit 7bf2df953d
4 changed files with 26 additions and 9 deletions

View file

@ -124,6 +124,15 @@ state_hub_task_id: "28726b1b-3777-5945-859b-9e563b12fee6"
`kubectl -n external-secrets create job --from=cronjob/eso-token-renewer eso-token-renewer-first`.
Every lane must print `ok: true` with a TTL of 604800.
T04 progress, 2026-09-23 (founder go-ahead):
- A `kubectl diff` of the AppProject showed only `+ batch/CronJob`. The
session's permission guard blocked the apply ("Shared Cluster Mutation"), so
the founder runs step 1.
- Step 2 is done in git. The Application was moved to
`argocd/railiance01/applications/` and pinned to `b2ebe10`. The root has no
automated sync, so nothing changes until the manual root sync.
## T05 Move consumers off leases from the old tokens before 2026-10-25
```task