CCR-2026-0029/0030: policy applied live (attended, guarded)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
This commit is contained in:
codex 2026-09-23 20:07:09 +02:00
parent 263605d00a
commit fe1665d1d0
4 changed files with 59 additions and 3 deletions

View file

@ -155,7 +155,22 @@ verification:
Policy and role applied under attended authority
(openbao-platform-admin-login, founder_required) with metadata-only receipts.
- Positive and negative results recorded with non-secret request ids.
evidence: []
evidence:
- at: '2026-09-23T18:06:29+00:00'
actor: bernd.worsch
kind: attended_policy_apply
result: passed
details:
- scripts/openbao-policy-sync.sh through the openbao-platform-admin-login
attended lane. The live policy went from sha256 41f4278c... (the prior
declared version) to f324ef3b..., which equals the repo file on
readback.
- The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json.
No secret values were read, written or printed.
- Store openbao-activity-core stayed Valid. The existing ExternalSecret
actcore-forgejo-admin force-synced at 18:06:45Z.
- Positive and negative verification waits for activity-core to apply
actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04).
lifecycle:
deactivate: >-
Detach the policy from the eventual role and disable the ops-warden catalog

View file

@ -94,7 +94,22 @@ verification:
scripts/openbao-policy-sync.sh, guarded by the prior declared digest
41f4278c3f62ff879575e62ef52071feaeb794fabd05868cb3ee40608cfd4785.
- Values provisioned directly in OpenBao (done, ACTIVITY-WP-0039-T03).
evidence: []
evidence:
- at: '2026-09-23T18:06:29+00:00'
actor: bernd.worsch
kind: attended_policy_apply
result: passed
details:
- scripts/openbao-policy-sync.sh through the openbao-platform-admin-login
attended lane. The live policy went from sha256 41f4278c... (the prior
declared version) to f324ef3b..., which equals the repo file on
readback.
- The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json.
No secret values were read, written or printed.
- Store openbao-activity-core stayed Valid. The existing ExternalSecret
actcore-forgejo-admin force-synced at 18:06:45Z.
- Positive and negative verification waits for activity-core to apply
actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04).
lifecycle:
deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso
and re-apply it.

View file

@ -94,7 +94,22 @@ verification:
scripts/openbao-policy-sync.sh, guarded by the prior declared digest
41f4278c3f62ff879575e62ef52071feaeb794fabd05868cb3ee40608cfd4785.
- Values provisioned directly in OpenBao (done, ACTIVITY-WP-0039-T03).
evidence: []
evidence:
- at: '2026-09-23T18:06:29+00:00'
actor: bernd.worsch
kind: attended_policy_apply
result: passed
details:
- scripts/openbao-policy-sync.sh through the openbao-platform-admin-login
attended lane. The live policy went from sha256 41f4278c... (the prior
declared version) to f324ef3b..., which equals the repo file on
readback.
- The receipt is docs/evidence/2026-09-23-activity-core-eso-policy-sync.json.
No secret values were read, written or printed.
- Store openbao-activity-core stayed Valid. The existing ExternalSecret
actcore-forgejo-admin force-synced at 18:06:45Z.
- Positive and negative verification waits for activity-core to apply
actcore-ops-run-worker-tokens (ACTIVITY-WP-0039-T04).
lifecycle:
deactivate: Remove the two path blocks from workload-kv-read-activity-core-eso
and re-apply it.

View file

@ -0,0 +1,11 @@
{
"changed": true,
"credential_values_emitted": false,
"declared_sha256": "f324ef3b193fb8f825f3b4a1b71266e1bacce4d3b0735083005dbc7c85883f5c",
"live_sha256": "f324ef3b193fb8f825f3b4a1b71266e1bacce4d3b0735083005dbc7c85883f5c",
"observed_at": "2026-09-23T18:06:29.089806+00:00",
"policy_name": "workload-kv-read-activity-core-eso",
"previous_sha256": "41f4278c3f62ff879575e62ef52071feaeb794fabd05868cb3ee40608cfd4785",
"schema": "railiance-platform.openbao-policy-sync.v1",
"status": "applied"
}