# Signing activation readiness — RPF-WP-0035-T04 The user requested completion of T04. Concurrent session work landed platform commit `5d28893` and prepared State Hub chart wiring and STATE-WP-0088. Avoid overlapping live activation with that session; no credential mutation or API outage was performed during this review. Read-only SSH checks confirmed kube-system UID `a553c742-0115-43d4-99a4-a5ca56fe0786`, one ready State Hub API replica, image `main-cdff3b7`, and absence of ExternalSecret `state-hub-rename-preflight`. The default workstation kubeconfig used localhost port 16443, whose listener refused connection. The activation runbook now requires verified cluster access before login, and the writer refuses a different cluster before OpenBao access or key generation. A regression test covers this refusal. Credential routing selected `openbao-platform-admin-login`, verdict `founder_required`, identity act `oidc_login`. This requires attended operator OIDC/MFA through the contained Warden envelope. It cannot be substituted with root or workload authority. No new login was initiated while the other session's activation ownership remained unconfirmed. T04 remains in progress: live custody, ESO delivery, signed preflight, and fenced rotation/invalidation/recovery evidence remain outstanding.