Close RAILIANCE-WP-0015-T06 rapp credential-lane binding
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled

Document the one recipe a new rapp uses to acquire runtime secrets:
standing KV secrets bind through a CCR target.rapp, leases through
grant rapp_id. Stamp the existing postgres grants and the qonto
workload CCR. Gate, delivery, and revocation are unchanged.
This commit is contained in:
codex 2026-08-14 00:47:28 +02:00
parent 6ab882cc44
commit dfa6373985
10 changed files with 342 additions and 10 deletions

View file

@ -52,6 +52,11 @@ secret_markers_rejected:
- ghp_
- sk-
# Optional. Set when this CCR is the runtime bind for a rapp (RAILIANCE-WP-0015-T06).
# target.rapp is a rapp-* slug. It does not replace target.workload.
optional_target_fields:
- rapp
workload_kv_read:
required:
openbao: