docs: retain approval client consumer procedure return
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-10 12:48:38 +02:00
parent 67c5a7a508
commit d3a502b45c
2 changed files with 24 additions and 1 deletions

View file

@ -5,7 +5,7 @@ request_type: workload-kv-read
title: secrets-engine client-side read of its approval client secret
status: in_flight
created: '2026-09-09'
updated: '2026-09-09'
updated: '2026-09-10'
in_flight:
missing_fields:
- openbao.auth
@ -51,6 +51,21 @@ review:
makes this an attended operator-workstation lane on the OIDC mount, not an
External Secrets lane. The named operator group claim is the one input
neither this repo nor secrets-engine can supply; NetKingdom/KeyCape own it.
- at: '2026-09-10'
reviewer: codex (consumer source review)
decision: consumer_procedure_documented
comment: >-
Secrets Engine source 98d72ceb1dbcff2d2a80fb8c3058d76777a0ac93,
docs/approval-service-auth.md, supplies the requested workstation
procedure: operator-owned 0700 runtime session directory outside Git,
new 0600 file, path-only configuration across one claim/consume operation,
EXIT/INT/TERM cleanup, and explicit residual-file handling after a hard
interruption. The consumer checks file permissions/location/non-emptiness;
creation, parent custody and removal remain attended responsibilities.
No automatic cleanup or live read proof is claimed. This documents the
consumer return; it is not platform-operator/secrets-engine-owner approval,
group confirmation or authority to apply the role. Existing activation
conditions and in_flight status remain.
target:
domain: financials
tenant: platform