diff --git a/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml b/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml index 1470fb1..64be775 100644 --- a/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml +++ b/credential-change-requests/CCR-2026-0020-approval-engine-operator-client-read.yaml @@ -155,7 +155,22 @@ verification: Policy and role applied under attended authority (openbao-platform-admin-login, founder_required) with metadata-only receipts. - Positive and negative results recorded with non-secret request ids. - evidence: [] + evidence: + - at: '2026-09-23T18:06:29+00:00' + actor: bernd.worsch + kind: attended_policy_apply + result: passed + details: + - scripts/openbao-policy-sync.sh through the openbao-platform-admin-login + attended lane. The live policy went from sha256 41f4278c... (the prior + declared version) to f324ef3b..., which equals the repo file on + readback. + - The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json. + No secret values were read, written or printed. + - Store openbao-activity-core stayed Valid. The existing ExternalSecret + actcore-forgejo-admin force-synced at 18:06:45Z. + - Positive and negative verification waits for activity-core to apply + actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). lifecycle: deactivate: >- Detach the policy from the eventual role and disable the ops-warden catalog diff --git a/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml b/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml index 3b83dff..88dd040 100644 --- a/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml +++ b/credential-change-requests/CCR-2026-0029-activity-core-ops-run-worker-rein-aharness-railiance01.yaml @@ -94,7 +94,22 @@ verification: scripts/openbao-policy-sync.sh, guarded by the prior declared digest 41f4278c3f62ff879575e62ef52071feaeb794fabd05868cb3ee40608cfd4785. - Values provisioned directly in OpenBao (done, ACTIVITY-WP-0039-T03). - evidence: [] + evidence: + - at: '2026-09-23T18:06:29+00:00' + actor: bernd.worsch + kind: attended_policy_apply + result: passed + details: + - scripts/openbao-policy-sync.sh through the openbao-platform-admin-login + attended lane. The live policy went from sha256 41f4278c... (the prior + declared version) to f324ef3b..., which equals the repo file on + readback. + - The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json. + No secret values were read, written or printed. + - Store openbao-activity-core stayed Valid. The existing ExternalSecret + actcore-forgejo-admin force-synced at 18:06:45Z. + - Positive and negative verification waits for activity-core to apply + actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). lifecycle: deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso and re-apply it. diff --git a/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml b/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml index 768eece..2d427b9 100644 --- a/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml +++ b/credential-change-requests/CCR-2026-0030-activity-core-ops-run-worker-rein-aharness-metered-railiance01.yaml @@ -94,7 +94,22 @@ verification: scripts/openbao-policy-sync.sh, guarded by the prior declared digest 41f4278c3f62ff879575e62ef52071feaeb794fabd05868cb3ee40608cfd4785. - Values provisioned directly in OpenBao (done, ACTIVITY-WP-0039-T03). - evidence: [] + evidence: + - at: '2026-09-23T18:06:29+00:00' + actor: bernd.worsch + kind: attended_policy_apply + result: passed + details: + - scripts/openbao-policy-sync.sh through the openbao-platform-admin-login + attended lane. The live policy went from sha256 41f4278c... (the prior + declared version) to f324ef3b..., which equals the repo file on + readback. + - The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json. + No secret values were read, written or printed. + - Store openbao-activity-core stayed Valid. The existing ExternalSecret + actcore-forgejo-admin force-synced at 18:06:45Z. + - Positive and negative verification waits for activity-core to apply + actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04). lifecycle: deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso and re-apply it. diff --git a/docs/evidence/2026-09-23-activity-core-eso-policy-sync.json b/docs/evidence/2026-09-23-activity-core-eso-policy-sync.json new file mode 100644 index 0000000..8ccd569 --- /dev/null +++ b/docs/evidence/2026-09-23-activity-core-eso-policy-sync.json @@ -0,0 +1,11 @@ +{ + "changed": true, + "credential_values_emitted": false, + "declared_sha256": "f324ef3b193fb8f825f3b4a1b71266e1bacce4d3b0735083005dbc7c85883f5c", + "live_sha256": "f324ef3b193fb8f825f3b4a1b71266e1bacce4d3b0735083005dbc7c85883f5c", + "observed_at": "2026-09-23T18:06:29.089806+00:00", + "policy_name": "workload-kv-read-activity-core-eso", + "previous_sha256": "41f4278c3f62ff879575e62ef52071feaeb794fabd05868cb3ee40608cfd4785", + "schema": "railiance-platform.openbao-policy-sync.v1", + "status": "applied" +}