Pin signing-lane writes to the verified primary cluster
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
parent
5d288938f7
commit
80793afe4f
5 changed files with 59 additions and 1 deletions
|
|
@ -24,6 +24,12 @@ cross-namespace store references. Coding-agent data AND metadata are denied.
|
|||
State Hub chart diff together. Confirm the dedicated SA binding and record
|
||||
CCR approval from the user's task authorization. Keep the lane non-resolvable.
|
||||
2. Commit/push the reviewed source in both repositories before live apply.
|
||||
Verify the selected kubeconfig reaches kube-system UID
|
||||
`a553c742-0115-43d4-99a4-a5ca56fe0786` using a metadata-only namespace GET.
|
||||
The writer enforces this identity before OpenBao access. The workstation's
|
||||
default config uses a local port forward; if that listener is unavailable,
|
||||
establish the approved cluster access path before starting attended login.
|
||||
Do not substitute another cluster's context to make the command succeed.
|
||||
3. Run the silent writer through the contained attended login envelope:
|
||||
|
||||
```sh
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue