Refresh SMTP completion and remaining acknowledgment gates

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
tegwick 2026-09-28 11:29:52 +02:00
parent 2a7368c37a
commit 820f0ff7b5
2 changed files with 14 additions and 8 deletions

View file

@ -144,13 +144,17 @@ The optional receiver test uses actual audit-core ingestion and SQLite with
synthetic credentials: first accepted, lost reply, then duplicate after restart.
It is not production custody proof. The template follows the upstream
[notification data contract](https://prometheus.io/docs/alerting/latest/notifications/).
The founder created `platform@coulomb.social`. The reviewed platform helper
creates `platform/workloads/railiance-telemetry/smtp` without a password through
attended OpenBao login. The founder then adds `SMTP_PASSWORD` as a new version,
preserving existing public SMTP fields.
Live activation remains blocked on password provisioning, dedicated credential custody,
client/caller admission, runtime rollout and recipient/readback drills.
No email or production acknowledgment is claimed.
The founder created `platform@coulomb.social` and supplied `SMTP_PASSWORD` in
OpenBao at `platform/workloads/railiance-telemetry/smtp`. Version 2 passed native
IONOS authentication. The dedicated ESO reader and credential projection are
Ready; the password was preserved. After adding scoped SMTP egress, the native
transport test succeeded and Bernd confirmed inbox receipt. See
`history/2026-09-28-alert-acknowledgment.md` for the evidence sequence.
Live acknowledgment activation remains blocked on webhook/audit sender custody,
OIDC client and enforced PDP caller admission, runtime rollout and actual alert
confirmation with independent audit readback. The successful transport-test
email does not establish those remaining facts.
Runtime validation (hash-pinned dependencies in requirements-runtime.lock):