Record KeyCape loopback callback evidence
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02e56-e4ad-71a2-b3e2-b6193e0d8093
This commit is contained in:
parent
913c03d6ec
commit
8ae77ca006
1 changed files with 9 additions and 6 deletions
|
|
@ -59,12 +59,15 @@ priority: high
|
||||||
state_hub_task_id: "99f8b41f-e9db-579d-a6fb-b71337048afc"
|
state_hub_task_id: "99f8b41f-e9db-579d-a6fb-b71337048afc"
|
||||||
```
|
```
|
||||||
|
|
||||||
Blocked on two facts: KeyCape and the OpenBao role must accept the exact
|
KeyCape revision `d150be1` now admits exactly
|
||||||
loopback callback, and an attended MFA login must pass. The host-namespace
|
`http://127.0.0.1:18200/ui/vault/auth/netkingdom/oidc/callback` in the
|
||||||
preflight already proves `openbao-ui-railiance01` lifecycle-healthy and reaches
|
source-owned `openbao-admin` client and pins it in configuration tests. The
|
||||||
the expected overlay. Then execute the guarded retraction, coordinate public
|
OpenBao `auth/netkingdom/role/platform-admin` role must still independently
|
||||||
DNS withdrawal with railiance-infra, and return non-secret acceptance evidence
|
admit that exact callback, and an attended MFA login must pass. The
|
||||||
to Railiance Master.
|
host-namespace preflight already proves `openbao-ui-railiance01`
|
||||||
|
lifecycle-healthy and reaches the expected overlay. Then execute the guarded
|
||||||
|
retraction, coordinate public DNS withdrawal with railiance-infra, and return
|
||||||
|
non-secret acceptance evidence to Railiance Master.
|
||||||
|
|
||||||
This workplan authorizes no OpenBao seal/unseal, policy broadening, PVC or
|
This workplan authorizes no OpenBao seal/unseal, policy broadening, PVC or
|
||||||
Secret mutation, reboot, restore, or RMASTER-WP-0020-T08 cleanup.
|
Secret mutation, reboot, restore, or RMASTER-WP-0020-T08 cleanup.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue