diff --git a/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml b/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml index 64be775..630dbf0 100644 --- a/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml +++ b/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml @@ -171,6 +171,17 @@ verification: actcore-forgejo-admin force-synced at 18:06:45Z. - Positive and negative verification waits for activity-core to apply actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). + - at: '2026-09-23T20:35:35+00:00' + actor: railiance-platform + kind: positive_verification + result: passed + details: + - ExternalSecret activity-core/actcore-ops-run-worker-tokens (store + openbao-activity-core) reached SecretSynced at 20:35:35Z. It was + observed read-only by status only. No Secret data or metadata was read. + - The negative check (sibling path and list denied for role + activity-core-eso) is still to run. It follows from the exact-path + policy but has not been exercised live. lifecycle: deactivate: >- Detach the policy from the eventual role and disable the ops-warden catalog diff --git a/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml b/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml index 88dd040..056fd8e 100644 --- a/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml +++ b/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml @@ -110,6 +110,17 @@ verification: actcore-forgejo-admin force-synced at 18:06:45Z. - Positive and negative verification waits for activity-core to apply actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). + - at: '2026-09-23T20:35:35+00:00' + actor: railiance-platform + kind: positive_verification + result: passed + details: + - ExternalSecret activity-core/actcore-ops-run-worker-tokens (store + openbao-activity-core) reached SecretSynced at 20:35:35Z. It was + observed read-only by status only. No Secret data or metadata was read. + - The negative check (sibling path and list denied for role + activity-core-eso) is still to run. It follows from the exact-path + policy but has not been exercised live. lifecycle: deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso and re-apply it. diff --git a/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml b/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml index 2d427b9..9d9ff43 100644 --- a/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml +++ b/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml @@ -110,6 +110,17 @@ verification: actcore-forgejo-admin force-synced at 18:06:45Z. - Positive and negative verification waits for activity-core to apply actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). + - at: '2026-09-23T20:35:35+00:00' + actor: railiance-platform + kind: positive_verification + result: passed + details: + - ExternalSecret activity-core/actcore-ops-run-worker-tokens (store + openbao-activity-core) reached SecretSynced at 20:35:35Z. It was + observed read-only by status only. No Secret data or metadata was read. + - The negative check (sibling path and list denied for role + activity-core-eso) is still to run. It follows from the exact-path + policy but has not been exercised live. lifecycle: deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso and re-apply it.