railiance-platform/history/2026-09-05-preflight-signing-activation-readiness.md
codex 80793afe4f
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Pin signing-lane writes to the verified primary cluster
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
2026-09-05 16:41:46 +02:00

23 lines
1.3 KiB
Markdown

# Signing activation readiness — RPF-WP-0035-T04
The user requested completion of T04. Concurrent session work landed platform
commit `5d28893` and prepared State Hub chart wiring and STATE-WP-0088. Avoid
overlapping live activation with that session; no credential mutation or API
outage was performed during this review.
Read-only SSH checks confirmed kube-system UID
`a553c742-0115-43d4-99a4-a5ca56fe0786`, one ready State Hub API replica, image
`main-cdff3b7`, and absence of ExternalSecret `state-hub-rename-preflight`.
The default workstation kubeconfig used localhost port 16443, whose listener
refused connection. The activation runbook now requires verified cluster access
before login, and the writer refuses a different cluster before OpenBao access
or key generation. A regression test covers this refusal.
Credential routing selected `openbao-platform-admin-login`, verdict
`founder_required`, identity act `oidc_login`. This requires attended operator
OIDC/MFA through the contained Warden envelope. It cannot be substituted with
root or workload authority. No new login was initiated while the other session's
activation ownership remained unconfirmed.
T04 remains in progress: live custody, ESO delivery, signed preflight, and
fenced rotation/invalidation/recovery evidence remain outstanding.