feat(RAILIANCE-WP-0027): add contained callback role update
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b90-83bf-75c2-81c8-aa705414e4d4
This commit is contained in:
codex 2026-08-23 14:37:01 +02:00
parent c89187c064
commit d18649fc6e
4 changed files with 164 additions and 0 deletions

View file

@ -69,5 +69,12 @@ lifecycle-healthy and reaches the expected overlay. Then execute the guarded
retraction, coordinate public DNS withdrawal with railiance-infra, and return
non-secret acceptance evidence to Railiance Master.
Net Kingdom revision `61aeafe` additionally applied the exact KeyCape callback
live and proved the public authorization endpoint accepts it. Railiance
Platform now carries the silent, narrowly scoped
`scripts/openbao-apply-operator-loopback-callback.sh` owner command for the
governed `openbao-platform-admin-login` lane. The remaining hold is one
attended OIDC/MFA execution of that command followed by one loopback UI login.
This workplan authorizes no OpenBao seal/unseal, policy broadening, PVC or
Secret mutation, reboot, restore, or RMASTER-WP-0020-T08 cleanup.