Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
55 lines
3.1 KiB
Markdown
55 lines
3.1 KiB
Markdown
# Telemetry SMTP entry
|
|
|
|
Existing RTEL-WP-0002-T04; no new task/workplan. Founder requested entry creation
|
|
on 2026-09-28 after creating platform@coulomb.social, and will add the password.
|
|
|
|
KV v2 mount: platform. Entry: workloads/railiance-telemetry/smtp.
|
|
Full CLI path: platform/workloads/railiance-telemetry/smtp.
|
|
Initial fields: SMTP_HOST=smtp.ionos.de, SMTP_PORT=587,
|
|
SMTP_USERNAME=platform@coulomb.social, SMTP_FROM=platform@coulomb.social,
|
|
SMTP_STARTTLS=true. SMTP_PASSWORD is deliberately absent until founder update.
|
|
Preserve the existing fields when saving that new version.
|
|
|
|
Attended founder command (requires existing local OpenBao forwarding):
|
|
|
|
```sh
|
|
BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 warden access openbao-platform-admin-login --exec -- python3 /home/worsch/railiance-platform/scripts/telemetry_smtp_entry.py
|
|
```
|
|
|
|
The helper is silent. CAS=0 never overwrites any existing path/version. Existing
|
|
version returns without reading values or writing. Four tests cover first
|
|
creation, existing version preservation, permission errors and CAS conflict.
|
|
Exit 20 invalid metadata; 21 metadata access failure; 22 creation failure;
|
|
23 unexpected write version; 24 verification failure; 25 contained failure.
|
|
A successful rerun on an existing path only proves presence, not its contents.
|
|
|
|
Read Warden's printed completion line: login-failed means no child ran;
|
|
completed-but-revocation-unconfirmed means creation ran but session revocation
|
|
requires attention. Native creation is pending until that attended result.
|
|
This helper does not grant ESO access, copy another mailbox's credential, or
|
|
activate SMTP. Scoped workload delivery remains the existing telemetry task.
|
|
|
|
## Password supplied; scoped delivery admission
|
|
|
|
The founder reports SMTP_PASSWORD added. This is not yet native verification.
|
|
The dedicated telemetry-smtp-eso ServiceAccount and package-owned
|
|
acknowledgment/smtp-custody.yaml are installed after dry-run and diff.
|
|
They project only SMTP_PASSWORD to telemetry/telemetry-alert-smtp:password.
|
|
|
|
The next attended command validates the exact public settings and password,
|
|
performs certificate-verified IONOS STARTTLS authentication without sending mail,
|
|
and admits the exact read-only policy and Kubernetes role (telemetry namespace,
|
|
telemetry-smtp-eso ServiceAccount, openbao audience, maximum 15 minutes).
|
|
Existing different policy/role values fail closed. Mailbox versions are untouched.
|
|
Coding-agent deny boundary is extended for data and metadata and tested.
|
|
|
|
```sh
|
|
BAO_ADDR=http://127.0.0.1:18200 VAULT_ADDR=http://127.0.0.1:18200 warden access openbao-platform-admin-login --exec -- python3 /home/worsch/railiance-platform/scripts/telemetry_smtp_delivery.py --receipt /tmp/telemetry-smtp-delivery.json
|
|
```
|
|
|
|
Use a new receipt filename on retry; existing evidence is never overwritten.
|
|
The helper is silent and writes only fixed status fields/KV version in its
|
|
0600 receipt. It never reads Kubernetes Secret values. Ten custody tests pass.
|
|
After successful attended completion, check ClusterSecretStore/ExternalSecret
|
|
Ready and record the receipt. Actual scoped Kubernetes auth and ESO delivery
|
|
remain unproved until that reconciliation. The alert route is still disabled.
|