Pin signing-lane writes to the verified primary cluster
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 16:41:46 +02:00
parent 5d288938f7
commit 80793afe4f
5 changed files with 59 additions and 1 deletions

View file

@ -122,3 +122,11 @@ access checks and a non-mutating signed preflight pass; every API replica uses
the accepted version; rotation/invalidation and recovery are evidenced. No
repository rename is part of S3 lane acceptance. If demand is withdrawn, record
the owning decision and cancel this task explicitly rather than provision it.
2026-09-05 continuation: verified the live primary cluster identity and healthy
single API replica; the signing ExternalSecret is still absent. Added a writer
guard against wrong-cluster kubeconfigs before any OpenBao access. The default
workstation kubeconfig's local port-forward listener was unavailable. Activation
still needs the contained attended OIDC/MFA login and the acceptance evidence
above; source preparation is not live completion. See
`history/2026-09-05-preflight-signing-activation-readiness.md`.