Establish attended telemetry Grafana custody and record private activation
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-06 22:36:09 +02:00
parent 4c320cf053
commit 92a0f5ed59
7 changed files with 263 additions and 0 deletions

View file

@ -0,0 +1,35 @@
# Telemetry private activation — 2026-09-06
User supplied telemetry.coulomb.social and authorized continuing on railiance01.
The separately owned rapp-telemetry package is now installed privately (Helm
revision 4, pinned kube-prometheus-stack 89.2.3). All five workloads are ready,
12/12 configured targets are up, and three PVCs are bound. DNS resolves to the
node and cert-manager issued the hostname certificate. Public ingress is staged,
not applied; Master ADR-0006/0008 admission remains incomplete.
Platform established platform/workloads/telemetry/grafana-admin with CAS-zero
protected generation and dedicated ESO identity telemetry/telemetry-grafana-eso.
The exact role/policy is telemetry-grafana-eso / telemetry-grafana-admin-eso;
audience openbao, 15-minute maximum, no default policy. Native credential values
were compared with ESO delivery only inside the attended envelope. The coding
agent boundary denies both data and metadata, preserving existing live policy.
Positive read, sibling/write denial, wrong SA/namespace/audience rejection and
deny-over-read policy union checks passed. Attended sessions self-revoked.
Grafana native admin authentication works; anonymous and forged proxy headers
return 401. Grafana retained its PVC through an update and still has 20 provisioned
dashboards plus its Prometheus datasource. Same-namespace service/pod access
works; an unrelated namespace is rejected. A chart default route referenced an
undefined Alertmanager receiver; explicit route replacement fixed it and a
rendered-config check now guards against recurrence. Grafana uses Recreate
updates to keep one SQLite writer.
Custody details and lifecycle limitations: docs/credential-lane-designs/telemetry-grafana.md.
Deployment evidence: ../rapp-telemetry/evidence/live/2026-09-06-railiance01.json.
Detailed handoff: ../rapp-telemetry/docs/activation-2026-09-06.md.
RAPP-TELEMETRY-WP-0001-T03 remains progress for isolated restore and independent
custody. T04 still waits for operator OIDC, actual S3 signal delivery/receipt,
an outside-node watchdog and public admission. RPF-WP-0036 is not closed by this
installation. Primary backup remains Scaleway; do not fill the 10GB Nextcloud
Backup account with telemetry time series. It is for the agreed essential set.