Refresh SMTP completion and remaining acknowledgment gates

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
tegwick 2026-09-28 11:29:52 +02:00
parent 2a7368c37a
commit 820f0ff7b5
2 changed files with 14 additions and 8 deletions

View file

@ -48,4 +48,6 @@ exporter and failure/absence rules for package integration.
The [email acknowledgment component](docs/alert-acknowledgment.md) records an The [email acknowledgment component](docs/alert-acknowledgment.md) records an
explicit Railiance admin confirmation with a durable audit-core outbox. It is explicit Railiance admin confirmation with a durable audit-core outbox. It is
not activated. Identity/policy adapters are implemented; native package admission, not activated. Identity/policy adapters are implemented; native package admission,
SMTP password custody and recipient proof remain under T04. webhook/audit custody and audited alert confirmation remain under T04. SMTP
custody and delivery are verified, including Bernd’s confirmed inbox receipt
of the transport-test email.

View file

@ -144,13 +144,17 @@ The optional receiver test uses actual audit-core ingestion and SQLite with
synthetic credentials: first accepted, lost reply, then duplicate after restart. synthetic credentials: first accepted, lost reply, then duplicate after restart.
It is not production custody proof. The template follows the upstream It is not production custody proof. The template follows the upstream
[notification data contract](https://prometheus.io/docs/alerting/latest/notifications/). [notification data contract](https://prometheus.io/docs/alerting/latest/notifications/).
The founder created `platform@coulomb.social`. The reviewed platform helper The founder created `platform@coulomb.social` and supplied `SMTP_PASSWORD` in
creates `platform/workloads/railiance-telemetry/smtp` without a password through OpenBao at `platform/workloads/railiance-telemetry/smtp`. Version 2 passed native
attended OpenBao login. The founder then adds `SMTP_PASSWORD` as a new version, IONOS authentication. The dedicated ESO reader and credential projection are
preserving existing public SMTP fields. Ready; the password was preserved. After adding scoped SMTP egress, the native
Live activation remains blocked on password provisioning, dedicated credential custody, transport test succeeded and Bernd confirmed inbox receipt. See
client/caller admission, runtime rollout and recipient/readback drills. `history/2026-09-28-alert-acknowledgment.md` for the evidence sequence.
No email or production acknowledgment is claimed.
Live acknowledgment activation remains blocked on webhook/audit sender custody,
OIDC client and enforced PDP caller admission, runtime rollout and actual alert
confirmation with independent audit readback. The successful transport-test
email does not establish those remaining facts.
Runtime validation (hash-pinned dependencies in requirements-runtime.lock): Runtime validation (hash-pinned dependencies in requirements-runtime.lock):