railiance-platform/openbao
codex 32d5cf0211
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Prepare the two approval client-side reader admissions
RPF-WP-0035-T06. Adds CCR-2026-0019 (secrets-engine) and CCR-2026-0020
(approval-engine-operator) with their exact-path read policies, reusing the
existing version-1 custody from the verifier activation. No reseed, rotation,
shared reader or verifier Secret reuse; both requests are in_flight and nothing
is applied.

The two shapes were decided by read-only survey rather than assumed.
secrets-engine consumes its client secret through an operator-run CLI reading a
protected file, and its namespace holds no workload, so reader 1 is an attended
operator-workstation OIDC lane rather than an ESO lane; its one missing input is
the operator group claim, which NetKingdom and KeyCape own. approval-engine is
not deployed and no owner source names who presents the operator client, so
reader 2 records the undetermined actor instead of guessing one for the widest
approval scope in the pair. Both declare openbao.auth missing rather than
carrying a placeholder binding.

T06 moves to wait on those two owner inputs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WLUjpv3ssxNRAEPPgLFnEB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1275505@bnt-lap001
Assistant-Session: 97265baa-f08f-4032-b290-a1e2965a69c5
2026-09-09 14:41:01 +02:00
..
auth Finish coding-agent high-risk boundary coverage 2026-08-22 10:03:54 +02:00
eso-auth-recovery Prepare bounded Kubernetes authentication recovery for three ESO lanes 2026-09-05 18:38:19 +02:00
policies Prepare the two approval client-side reader admissions 2026-09-09 14:41:01 +02:00
ssh fix(openbao): complete SSH apply script for OpenBao 2.5.x issuers 2026-06-18 01:18:56 +02:00
state-hub-preflight fix: preserve unrelated live boundary rules during signing lane apply 2026-09-05 16:43:47 +02:00