railiance-platform/docs/telemetry-smtp-custody.md
codex 56fcc4c921
All checks were successful
CI Smoke / host-smoke (push) Successful in 2s
CI Smoke / container-smoke (push) Successful in 4s
Add attended SMTP verification and exact reader admission
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
2026-09-28 11:21:57 +02:00

55 lines
3.1 KiB
Markdown

# Telemetry SMTP entry
Existing RTEL-WP-0002-T04; no new task/workplan. Founder requested entry creation
on 2026-09-28 after creating platform@coulomb.social, and will add the password.
KV v2 mount: platform. Entry: workloads/railiance-telemetry/smtp.
Full CLI path: platform/workloads/railiance-telemetry/smtp.
Initial fields: SMTP_HOST=smtp.ionos.de, SMTP_PORT=587,
SMTP_USERNAME=platform@coulomb.social, SMTP_FROM=platform@coulomb.social,
SMTP_STARTTLS=true. SMTP_PASSWORD is deliberately absent until founder update.
Preserve the existing fields when saving that new version.
Attended founder command (requires existing local OpenBao forwarding):
```sh
BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 warden access openbao-platform-admin-login --exec -- python3 /home/worsch/railiance-platform/scripts/telemetry_smtp_entry.py
```
The helper is silent. CAS=0 never overwrites any existing path/version. Existing
version returns without reading values or writing. Four tests cover first
creation, existing version preservation, permission errors and CAS conflict.
Exit 20 invalid metadata; 21 metadata access failure; 22 creation failure;
23 unexpected write version; 24 verification failure; 25 contained failure.
A successful rerun on an existing path only proves presence, not its contents.
Read Warden's printed completion line: login-failed means no child ran;
completed-but-revocation-unconfirmed means creation ran but session revocation
requires attention. Native creation is pending until that attended result.
This helper does not grant ESO access, copy another mailbox's credential, or
activate SMTP. Scoped workload delivery remains the existing telemetry task.
## Password supplied; scoped delivery admission
The founder reports SMTP_PASSWORD added. This is not yet native verification.
The dedicated telemetry-smtp-eso ServiceAccount and package-owned
acknowledgment/smtp-custody.yaml are installed after dry-run and diff.
They project only SMTP_PASSWORD to telemetry/telemetry-alert-smtp:password.
The next attended command validates the exact public settings and password,
performs certificate-verified IONOS STARTTLS authentication without sending mail,
and admits the exact read-only policy and Kubernetes role (telemetry namespace,
telemetry-smtp-eso ServiceAccount, openbao audience, maximum 15 minutes).
Existing different policy/role values fail closed. Mailbox versions are untouched.
Coding-agent deny boundary is extended for data and metadata and tested.
```sh
BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 warden access openbao-platform-admin-login --exec -- python3 /home/worsch/railiance-platform/scripts/telemetry_smtp_delivery.py --receipt /tmp/telemetry-smtp-delivery.json
```
Use a new receipt filename on retry; existing evidence is never overwritten.
The helper is silent and writes only fixed status fields/KV version in its
0600 receipt. It never reads Kubernetes Secret values. Ten custody tests pass.
After successful attended completion, check ClusterSecretStore/ExternalSecret
Ready and record the receipt. Actual scoped Kubernetes auth and ESO delivery
remain unproved until that reconciliation. The alert route is still disabled.