Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2.2 KiB
RPF-WP-0035-T04 completed — 2026-09-05
The user explicitly assigned this session to lead activation. The approved CCR-2026-0015 lane was provisioned through the attended Warden/OpenBao envelope. The dedicated kubeconfig reached the pinned primary cluster. Warden exited successfully after each contained operation and its session cleanup.
Initial CAS-zero generation produced version 1. Exact path read, wrong service account/namespace/audience, sibling and metadata denial, and coding-agent deny precedence passed. ESO initially failed token lookup-self with 403. Inspection of deployed ESO v0.16.1 source confirmed token lookup-self and revoke-self calls. The policy was narrowly amended to permit these self-token operations; no KV access was broadened. A drift-checked repair passed all custody checks and ESO became Ready.
State Hub production source commit 49e3182 enabled its reviewed API-only
reference. Deployment used a fresh Forge clone of that exact revision, retained
the running image main-cdff3b7 and existing release values, and server dry-run
showed only Deployment/state-hub changed. Helm revision 59 deployed successfully.
The single API replica matched the delivered key, returned healthy primary
identity, and produced a valid signed preflight with zero blockers for the
approved flex-auth to access-engine fixture. MCP had no key reference; the
shared environment Secret had no competing signing key.
The API deployment was scaled to zero, every matching pod terminated, and no HPA was present. The guarded attended writer rotated with CAS 1 to version 2. ESO refreshed; the API was restored to one replica. Forward recovery passed: delivered key equality, health, valid new preflight, and predecessor rejection specifically for invalid signature, not expiry. The protected predecessor fixture was removed after verification. No repository rename was executed.
Evidence: docs/evidence/RPF-WP-0035-T04-signing-activation-2026-09-05.json.
CCR is active and T04 is done; other credential lanes retain their own gates.
Validation: 183 platform unit tests, 15 State Hub signing/rename API tests, credential request validation and Helm lint passed. Live acceptance receipts provide the operational evidence beyond these source tests.