S3 Platform Services — PostgreSQL HA, Valkey, object storage
Four owner threads are each blocked on a fact only an authenticated read can establish: whether the legacy whynot-design npm path still exists, which field backs the authoritative lane, whether the two KeyCape approval policies match repo source after an activation that recorded policy_applied false, which netkingdom bound group claims already exist as input to CCR-2026-0019, and which fields the governed backup lane carries. Adds scripts/openbao_open_questions_session.py, which contains no mutating bao verb and emits only a mode-0600 metadata receipt, plus the run-book in docs/openbao-open-questions-session.md. Field-name resolution is a data read, so the runner returns sorted key names and no value reaches argv, disk or the receipt; that caveat is stated rather than glossed. Not run. The rapp-qonto rotation and the RPF-WP-0029 provider invalidation are explicitly out of scope. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB Assistant: claude-code Assistant-Model: opus Assistant-Process: 1275505@bnt-lap001 Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5 |
||
|---|---|---|
| .claude/rules | ||
| .forgejo/workflows | ||
| argocd | ||
| assurance | ||
| credential-change-requests | ||
| credential-grants | ||
| data/consumption-mode | ||
| docs | ||
| helm | ||
| history | ||
| interfaces | ||
| lib | ||
| manifests | ||
| openbao | ||
| registry | ||
| reviews | ||
| schemas | ||
| scripts | ||
| tests | ||
| tools | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| .sops.yaml | ||
| AGENTS.md | ||
| ArchitectureBlueprint.md | ||
| CLAUDE.md | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| SCOPE.md | ||
| tenancy.yaml | ||
| WORK-RECORDS.md | ||