railiance-platform/argocd/platform-addons/openbao-secretstore
codex f3ba7ca882
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Admit KeyCape approval-engine client custody paths and delivery
Answers KEY-WP-0013-T02. Both proposed KV paths are confirmed unchanged; the
field name is corrected to CLIENT_SECRET for the platform uppercase convention
and the CCR validator. Kubernetes delivery references are confirmed against the
live sso namespace. Attended authority is the governed openbao-platform-admin-login
lane, and the rollout is one attended window ordered after the Authelia issuer
precondition.

Adds CCR-2026-0017/0018, two exact-path read policies, two namespace-limited
ClusterSecretStores with Kubernetes auth, two ExternalSecrets, and RPF-WP-0035-T05.
Nothing is applied and no value exists: both CCRs remain proposed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275505@bnt-lap001
Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5
2026-09-08 14:53:32 +02:00
..
core-hub.externalsecrets.yaml feat: add hub-core database lease projections 2026-08-21 17:30:44 +02:00
keycape-approval-clients.externalsecrets.yaml Admit KeyCape approval-engine client custody paths and delivery 2026-09-08 14:53:32 +02:00
kustomization.yaml Fix openbao-secretstore ArgoCD health: coulombcore scope only 2026-07-08 15:41:04 +02:00
openbao-activity-core.clustersecretstore.yaml Move platform secret stores to local OpenBao 2026-08-03 21:36:52 +02:00
openbao-audit-core.clustersecretstore.yaml Point openbao-audit-core store at the Mason AppRole 2026-08-13 10:42:59 +02:00
openbao-backup-object-storage.clustersecretstore.yaml feat: vend platform-pg-backup-s3 via AppRole ESO 2026-08-14 20:00:15 +02:00
openbao-core-hub-database.clustersecretstore.yaml Advance RPF-WP-0021 platform onboarding 2026-08-20 23:31:47 +02:00
openbao-core-hub-runtime.clustersecretstore.yaml feat: prepare core hub platform onboarding 2026-08-20 11:18:30 +02:00
openbao-email-connect.clustersecretstore.yaml Add email-connect transactional SMTP and ingest custody lane. 2026-08-12 13:32:11 +02:00
openbao-forgejo.clustersecretstore.yaml Prepare bounded Kubernetes authentication recovery for three ESO lanes 2026-09-05 18:38:19 +02:00
openbao-keycape-approval-clients.clustersecretstore.yaml Admit KeyCape approval-engine client custody paths and delivery 2026-09-08 14:53:32 +02:00
openbao-rapp-qonto.clustersecretstore.yaml Move platform secret stores to local OpenBao 2026-08-03 21:36:52 +02:00
openbao-reuse.clustersecretstore.yaml Prepare bounded Kubernetes authentication recovery for three ESO lanes 2026-09-05 18:38:19 +02:00
openbao-target-revenue.clustersecretstore.yaml Prepare bounded Kubernetes authentication recovery for three ESO lanes 2026-09-05 18:38:19 +02:00
openbao.clustersecretstore.yaml Add ESO OpenBao GitOps add-ons 2026-06-25 20:08:36 +02:00