Pin signing-lane writes to the verified primary cluster
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 16:41:46 +02:00
parent 5d288938f7
commit 80793afe4f
5 changed files with 59 additions and 1 deletions

View file

@ -24,6 +24,12 @@ cross-namespace store references. Coding-agent data AND metadata are denied.
State Hub chart diff together. Confirm the dedicated SA binding and record
CCR approval from the user's task authorization. Keep the lane non-resolvable.
2. Commit/push the reviewed source in both repositories before live apply.
Verify the selected kubeconfig reaches kube-system UID
`a553c742-0115-43d4-99a4-a5ca56fe0786` using a metadata-only namespace GET.
The writer enforces this identity before OpenBao access. The workstation's
default config uses a local port forward; if that listener is unavailable,
establish the approved cluster access path before starting attended login.
Do not substitute another cluster's context to make the command succeed.
3. Run the silent writer through the contained attended login envelope:
```sh