CCR-2026-0029/0030: policy applied live (attended, guarded)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 150322@bnt-lap001 Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
This commit is contained in:
parent
263605d00a
commit
fe1665d1d0
4 changed files with 59 additions and 3 deletions
|
|
@ -155,7 +155,22 @@ verification:
|
|||
Policy and role applied under attended authority
|
||||
(openbao-platform-admin-login, founder_required) with metadata-only receipts.
|
||||
- Positive and negative results recorded with non-secret request ids.
|
||||
evidence: []
|
||||
evidence:
|
||||
- at: '2026-09-23T18:06:29+00:00'
|
||||
actor: bernd.worsch
|
||||
kind: attended_policy_apply
|
||||
result: passed
|
||||
details:
|
||||
- scripts/openbao-policy-sync.sh through the openbao-platform-admin-login
|
||||
attended lane. The live policy went from sha256 41f4278c... (the prior
|
||||
declared version) to f324ef3b..., which equals the repo file on
|
||||
readback.
|
||||
- The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json.
|
||||
No secret values were read, written or printed.
|
||||
- Store openbao-activity-core stayed Valid. The existing ExternalSecret
|
||||
actcore-forgejo-admin force-synced at 18:06:45Z.
|
||||
- Positive and negative verification waits for activity-core to apply
|
||||
actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04).
|
||||
lifecycle:
|
||||
deactivate: >-
|
||||
Detach the policy from the eventual role and disable the ops-warden catalog
|
||||
|
|
|
|||
|
|
@ -94,7 +94,22 @@ verification:
|
|||
scripts/openbao-policy-sync.sh, guarded by the prior declared digest
|
||||
41f4278c3f62ff879575e62ef52071feaeb794fabd05868cb3ee40608cfd4785.
|
||||
- Values provisioned directly in OpenBao (done, ACTIVITY-WP-0039-T03).
|
||||
evidence: []
|
||||
evidence:
|
||||
- at: '2026-09-23T18:06:29+00:00'
|
||||
actor: bernd.worsch
|
||||
kind: attended_policy_apply
|
||||
result: passed
|
||||
details:
|
||||
- scripts/openbao-policy-sync.sh through the openbao-platform-admin-login
|
||||
attended lane. The live policy went from sha256 41f4278c... (the prior
|
||||
declared version) to f324ef3b..., which equals the repo file on
|
||||
readback.
|
||||
- The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json.
|
||||
No secret values were read, written or printed.
|
||||
- Store openbao-activity-core stayed Valid. The existing ExternalSecret
|
||||
actcore-forgejo-admin force-synced at 18:06:45Z.
|
||||
- Positive and negative verification waits for activity-core to apply
|
||||
actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04).
|
||||
lifecycle:
|
||||
deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso
|
||||
and re-apply it.
|
||||
|
|
|
|||
|
|
@ -94,7 +94,22 @@ verification:
|
|||
scripts/openbao-policy-sync.sh, guarded by the prior declared digest
|
||||
41f4278c3f62ff879575e62ef52071feaeb794fabd05868cb3ee40608cfd4785.
|
||||
- Values provisioned directly in OpenBao (done, ACTIVITY-WP-0039-T03).
|
||||
evidence: []
|
||||
evidence:
|
||||
- at: '2026-09-23T18:06:29+00:00'
|
||||
actor: bernd.worsch
|
||||
kind: attended_policy_apply
|
||||
result: passed
|
||||
details:
|
||||
- scripts/openbao-policy-sync.sh through the openbao-platform-admin-login
|
||||
attended lane. The live policy went from sha256 41f4278c... (the prior
|
||||
declared version) to f324ef3b..., which equals the repo file on
|
||||
readback.
|
||||
- The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json.
|
||||
No secret values were read, written or printed.
|
||||
- Store openbao-activity-core stayed Valid. The existing ExternalSecret
|
||||
actcore-forgejo-admin force-synced at 18:06:45Z.
|
||||
- Positive and negative verification waits for activity-core to apply
|
||||
actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04).
|
||||
lifecycle:
|
||||
deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso
|
||||
and re-apply it.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue