Pin signing-lane writes to the verified primary cluster
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
parent
5d288938f7
commit
80793afe4f
5 changed files with 59 additions and 1 deletions
|
|
@ -122,3 +122,11 @@ access checks and a non-mutating signed preflight pass; every API replica uses
|
|||
the accepted version; rotation/invalidation and recovery are evidenced. No
|
||||
repository rename is part of S3 lane acceptance. If demand is withdrawn, record
|
||||
the owning decision and cancel this task explicitly rather than provision it.
|
||||
|
||||
2026-09-05 continuation: verified the live primary cluster identity and healthy
|
||||
single API replica; the signing ExternalSecret is still absent. Added a writer
|
||||
guard against wrong-cluster kubeconfigs before any OpenBao access. The default
|
||||
workstation kubeconfig's local port-forward listener was unavailable. Activation
|
||||
still needs the contained attended OIDC/MFA login and the acceptance evidence
|
||||
above; source preparation is not live completion. See
|
||||
`history/2026-09-05-preflight-signing-activation-readiness.md`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue