From 8d878cc4c2daab615738afd89af82df04effb389 Mon Sep 17 00:00:00 2001 From: codex Date: Wed, 23 Sep 2026 22:36:41 +0200 Subject: [PATCH] CCR-2026-0029/0030: record positive verification (ExternalSecret synced) Co-Authored-By: Claude Opus 5.5 Assistant: claude-code Assistant-Model: opus Assistant-Process: 150322@bnt-lap001 Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4 --- ...026-0020-approval-engine-operator-client-read.yaml | 11 +++++++++++ ...core-ops-run-worker-rein-aharness-railiance01.yaml | 11 +++++++++++ ...-run-worker-rein-aharness-metered-railiance01.yaml | 11 +++++++++++ 3 files changed, 33 insertions(+) diff --git a/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml b/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml index 64be775..630dbf0 100644 --- a/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml +++ b/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml @@ -171,6 +171,17 @@ verification: actcore-forgejo-admin force-synced at 18:06:45Z. - Positive and negative verification waits for activity-core to apply actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). + - at: '2026-09-23T20:35:35+00:00' + actor: railiance-platform + kind: positive_verification + result: passed + details: + - ExternalSecret activity-core/actcore-ops-run-worker-tokens (store + openbao-activity-core) reached SecretSynced at 20:35:35Z. It was + observed read-only by status only. No Secret data or metadata was read. + - The negative check (sibling path and list denied for role + activity-core-eso) is still to run. It follows from the exact-path + policy but has not been exercised live. lifecycle: deactivate: >- Detach the policy from the eventual role and disable the ops-warden catalog diff --git a/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml b/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml index 88dd040..056fd8e 100644 --- a/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml +++ b/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml @@ -110,6 +110,17 @@ verification: actcore-forgejo-admin force-synced at 18:06:45Z. - Positive and negative verification waits for activity-core to apply actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). + - at: '2026-09-23T20:35:35+00:00' + actor: railiance-platform + kind: positive_verification + result: passed + details: + - ExternalSecret activity-core/actcore-ops-run-worker-tokens (store + openbao-activity-core) reached SecretSynced at 20:35:35Z. It was + observed read-only by status only. No Secret data or metadata was read. + - The negative check (sibling path and list denied for role + activity-core-eso) is still to run. It follows from the exact-path + policy but has not been exercised live. lifecycle: deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso and re-apply it. diff --git a/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml b/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml index 2d427b9..9d9ff43 100644 --- a/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml +++ b/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml @@ -110,6 +110,17 @@ verification: actcore-forgejo-admin force-synced at 18:06:45Z. - Positive and negative verification waits for activity-core to apply actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). + - at: '2026-09-23T20:35:35+00:00' + actor: railiance-platform + kind: positive_verification + result: passed + details: + - ExternalSecret activity-core/actcore-ops-run-worker-tokens (store + openbao-activity-core) reached SecretSynced at 20:35:35Z. It was + observed read-only by status only. No Secret data or metadata was read. + - The negative check (sibling path and list denied for role + activity-core-eso) is still to run. It follows from the exact-path + policy but has not been exercised live. lifecycle: deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso and re-apply it.