Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Updated by fix-consistency on 2026-09-23:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
- WP-0045-T06 done: both dead static-token Secrets deleted after a no-reference recheck.
- Renewer Application moved from drafts to railiance01 applications; inert until
the AppProject carries batch/CronJob and the root is synced by hand.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
ACTIVITY-WP-0039-T02. Add read on the two exact worker-token paths to
workload-kv-read-activity-core-eso, one CCR per worker identity. Adds
scripts/openbao-policy-sync.sh, a silent attended policy writer that refuses
undeclared live drift and verifies on readback. Not applied; CCRs await
platform-operator and activity-core-owner approval.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Updated by fix-consistency on 2026-09-23:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
The five dynamic-database ClusterSecretStores use 768h static tokens that
nothing renews; expiry revoked their DB leases on 2026-09-23 and recurs
around 2026-10-25. Kubernetes auth is not a drop-in fix: ESO v0.16.1 revokes
its login token after each reconcile, which revokes the leases it created.
- eso-token-renewer CronJob (ArgoCD draft, no RBAC, mounted Secrets).
- Attended periodic mint script for all five lanes.
- CronJob added to the platform-addons AppProject in git (not yet applied).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Updated by fix-consistency on 2026-09-23:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Answers the-custodian 641673a4. An attended read-only check (receipt
docs/evidence/2026-09-23-openbao-platform-admin-check.json) found:
- live platform-admin policy = repo file + reins/* (ops-mason, 2026-07-27);
repo now matches live (sha256 0ca5b821...). No live write.
- role also attaches operator-custody (undeclared); declared here.
- role declared as openbao/auth/netkingdom-platform-admin-role.json.
- default policy is attached and grants revoke-self/lookup-self, so the
suspected missing grant is not the cause of warden's unconfirmed revocation.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Updated by fix-consistency on 2026-09-22:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
- WP-0025-T03 done: public listener retracted 2026-09-15; bao.coulomb.social
is retired, tunnel is the operator path; DNS withdrawal handed to S1.
- WP-0043-T01 done: ArgoCD Core reconciles railiance01 at main (evidence).
- WP-0043-T05 done: direct-apply gap inventory and founder proposal.
- WP-0045-T05 cancelled (no rollback needed); T06 preconditions recorded.
- Operator scripts default BAO_ADDR to the openbao-ui-railiance01 tunnel.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 150322@bnt-lap001
Assistant-Session: 16a7b788-374e-4915-a1df-fc87ffd9a5e4
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- workplan status: ready → active
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Declares target store specs, two exact-path policies and two ESO
ServiceAccounts. Nothing applied; live steps wait on the founder.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Founder go-ahead 2026-09-21. Client-side diff at f1109d5 rc=0 for all
non-hook objects; adoption sync uses the apply strategy, which skips the
two Sync-hook Jobs against the production database.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Founder go-ahead 2026-09-21. Child Application without automated sync or
finalizer, pinned to d2dbc19; synced by hand with prune off.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- workplan status: ready → active
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- update .custodian-brief.md for railiance-platform
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Updated by fix-consistency on 2026-09-21:
- workplan status: ready → active
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Records the founder's 2026-09-21 decision, read-only diff evidence for the
four Applications, and RPF-WP-0044 (one founder go-ahead per app). Nothing
applied.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
Founder decision 2026-09-21 (the-custodian/docs/kubernetes-change-gate-decision.md).
RPF-WP-0043 plans, and does not perform, the policy-nexus adoption; it waits on
the founder's go-ahead. Records that this repository cannot show ArgoCD
reconciling on railiance01.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
INTENT.md frontmatter governs; layer.yaml is marked derived (derived: true,
derived_from: INTENT.md) per amendment A11. standard_version removed from both
forms per A12. Layer values are not re-spelled: INTENT.md 'Staff' and
layer.yaml 'staff' agree after ASCII case-fold. This repository has no
conformance checker yet (gaps.conformance-check-script), so no checker change
was needed. pep-stance.yaml does not exist here and is untouched.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
The reader login succeeded; the child died at preflight. Use bao for the
KV read, accept parent/sibling deny shapes, and record a failure class.
Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
Reader lane login, sibling-path denial, and KeyCape exchange checks.
No sitting POST. Attended wrapper selects the exact OIDC reader role.
Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a
Attended helper returned applied, KV version 1, ESO synced, KeyCape
ready. No sitting POST. CCRs 0026/0027 are applied metadata only.
Assistant: grok
Assistant-Session: 01a0a23b-3bf0-7341-b4e5-9dc05f72573a