Record Policy Nexus metadata apply and diagnose bootstrap
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
This commit is contained in:
codex 2026-09-01 00:18:15 +02:00
parent 1d5f35539d
commit a6d47c51cc
3 changed files with 46 additions and 2 deletions

View file

@ -3,7 +3,7 @@ kind: credential-change-request
schema_version: 1
request_type: workload-kv-read
title: Policy Nexus Forgejo private-source read token lane
status: approved
status: applied
created: '2026-08-31'
updated: '2026-08-31'
requester:
@ -137,6 +137,16 @@ verification:
and its public health endpoint returns 200; the KeyCape openbao-admin authorize
path returns 302. No Forgejo identity, PAT, OpenBao secret value, Actions secret,
or workflow run was created.
- at: '2026-08-31T22:15:50+00:00'
actor: attended operator via governed platform-admin lane
kind: delegated_metadata_apply
result: passed
details:
- Delegated metadata applier ran as attended operator via governed platform-admin
lane using local bao CLI ambient authority.
- 'Policy metadata write: sys/policies/acl/workload-kv-read-policy-nexus-forgejo-source'
- 'Auth role metadata write: auth/netkingdom/role/policy-nexus-forgejo-source-workload-kv-read'
- No secret values were read, written, printed, or accepted in argv.
lifecycle:
deactivate: Remove the repository Actions secret, revoke the Forgejo PAT, disable
the OpenBao access path, and leave scheduled publication failing closed.