From 9d958f8e09a057d6ad688dc77001368b5feea029 Mon Sep 17 00:00:00 2001 From: repo-manager Date: Sat, 5 Sep 2026 10:42:02 +0200 Subject: [PATCH] repo.work.assign_missing_identifiers source: repo-manager reason: deterministic projection registration Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883 --- workplans/RPF-WP-0032-secrets-engine-service-jwt-design.md | 3 +++ workplans/RPF-WP-0033-fluid-telegram-operator-kv-design.md | 3 +++ workplans/RPF-WP-0034-state-hub-preflight-signing-design.md | 3 +++ 3 files changed, 9 insertions(+) diff --git a/workplans/RPF-WP-0032-secrets-engine-service-jwt-design.md b/workplans/RPF-WP-0032-secrets-engine-service-jwt-design.md index e493516..f9ffbfa 100644 --- a/workplans/RPF-WP-0032-secrets-engine-service-jwt-design.md +++ b/workplans/RPF-WP-0032-secrets-engine-service-jwt-design.md @@ -8,6 +8,7 @@ status: blocked owner: codex created: "2026-09-05" updated: "2026-09-05" +state_hub_workstream_id: "bd036850-e1bf-5b70-bbc3-683dfa4b125c" --- # Design secrets-engine service JWT login @@ -18,6 +19,7 @@ updated: "2026-09-05" id: RPF-WP-0032-T01 status: done priority: high +state_hub_task_id: "166ece0b-840b-54b8-b10c-45f96eda0429" ``` Reviewed owner source and the current platform CCR contract. Delivered @@ -32,6 +34,7 @@ production objects changed or owner messages sent. id: RPF-WP-0032-T02 status: wait priority: high +state_hub_task_id: "d1f4a9f6-4ea5-5daa-97bb-039856855bc2" ``` Confirm issuer, verification endpoint, actual KeyCape registration and live auth mount survey. Approve the login-only role/self policy, implement reviewed declarative support and prove effective-policy, wrong-claim, expiry and cleanup checks. Native lane execution still requires its separate exact authorization and scoped authority. diff --git a/workplans/RPF-WP-0033-fluid-telegram-operator-kv-design.md b/workplans/RPF-WP-0033-fluid-telegram-operator-kv-design.md index eaec2cf..d8e85bb 100644 --- a/workplans/RPF-WP-0033-fluid-telegram-operator-kv-design.md +++ b/workplans/RPF-WP-0033-fluid-telegram-operator-kv-design.md @@ -8,6 +8,7 @@ status: blocked owner: codex created: "2026-09-05" updated: "2026-09-05" +state_hub_workstream_id: "957d49b9-6b84-5fde-89d0-4c2efef70067" --- # Design fluid-telegram attended operator KV lane @@ -18,6 +19,7 @@ updated: "2026-09-05" id: RPF-WP-0033-T01 status: done priority: high +state_hub_task_id: "6d305189-61f3-5750-8e4f-5cd97b92f324" ``` Reviewed owner source and the current platform CCR contract. Delivered @@ -32,6 +34,7 @@ production objects changed or owner messages sent. id: RPF-WP-0033-T02 status: wait priority: high +state_hub_task_id: "a542697f-adf8-59ac-9704-0bcde1d9fd0f" ``` Obtain tenant/group/MFA decisions; extend the CCR schema, validator, renderer and ops-mason executor for the exact four-entry matrix; correct the consumer tenant default, atomic salt creation and preflight output. Complete an attended installed-engine probe and boundary checks before any routing activation. diff --git a/workplans/RPF-WP-0034-state-hub-preflight-signing-design.md b/workplans/RPF-WP-0034-state-hub-preflight-signing-design.md index dbde8e6..74f3d73 100644 --- a/workplans/RPF-WP-0034-state-hub-preflight-signing-design.md +++ b/workplans/RPF-WP-0034-state-hub-preflight-signing-design.md @@ -8,6 +8,7 @@ status: blocked owner: codex created: "2026-09-05" updated: "2026-09-05" +state_hub_workstream_id: "5233ef7d-200e-5ca7-8b8c-897b12de4377" --- # Design State Hub preflight signing custody @@ -18,6 +19,7 @@ updated: "2026-09-05" id: RPF-WP-0034-T01 status: done priority: high +state_hub_task_id: "bb9e53a9-63b1-5500-8b30-96c5252b8d61" ``` Reviewed owner source and the current platform CCR contract. Delivered @@ -32,6 +34,7 @@ production objects changed or owner messages sent. id: RPF-WP-0034-T02 status: wait priority: high +state_hub_task_id: "96e4864a-fd17-529b-a72f-69ffd885a962" ``` Confirm exact primary deployment and delivery identity; approve the writer and read CCR; implement dedicated ESO/API-only delivery and a concrete rotation fence. Provision only in an approved window, prove preflight signing without executing a rename, and record API/ESO health and negative access evidence.