Record Core authorization boundary and pending GitOps tool projection
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e241-8285-7a63-8c0c-51c9cb824dc3
This commit is contained in:
parent
743def17be
commit
ff34d596f9
2 changed files with 22 additions and 3 deletions
|
|
@ -100,3 +100,17 @@ Credential routing inspection found no ready scoped unattended ArgoCD/Forgejo
|
|||
release lane. ACTIVITY-WP-0041-T03 remains the authority/admission owner; no broad
|
||||
operator token was copied or delegated. Its concrete executor contract is in
|
||||
`docs/activity-core-release-admission.md`.
|
||||
|
||||
The production worker currently mounts an older platform checkout's script
|
||||
(SHA256 0baacfd07b74ddd4317f79aa0de818c25186e15303a67c08d29edc73ad74a870).
|
||||
Deploy the new script as a pinned GitOps projection, verify worker readback and a
|
||||
non-destructive planner fixture, then close T03. Do not silently overwrite the
|
||||
host checkout: it is outside the newly adopted nine-resource projection. Current
|
||||
baseline aliases remain protected; no prune was executed during verification.
|
||||
|
||||
ArgoCD Core has no API-server token/role lane. T02 admission must prove a broker
|
||||
that restricts both the platform child revision update and Kubernetes Application
|
||||
sync operation; resource-name RBAC alone cannot restrict patch fields. This is
|
||||
concrete implementation work retained here and in ACTIVITY-WP-0041-T03, not a
|
||||
reason to ask the founder to approve each release. Tests in the owner checkout:
|
||||
20 passed across retention and additive inventory suites.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue