Start Qonto workload identity gate
This commit is contained in:
parent
269d922631
commit
0a4f4b9de6
2 changed files with 7 additions and 2 deletions
|
|
@ -18,7 +18,7 @@ state_hub_workstream_id: "c3f9fbfd-3db1-4387-8b65-7d53ba57138d"
|
|||
|
||||
```task
|
||||
id: REEF-RAILIANCE-WP-0003-T01
|
||||
status: todo
|
||||
status: progress
|
||||
priority: high
|
||||
state_hub_task_id: "de8a8e05-93f9-4082-bbb0-5b522179421d"
|
||||
```
|
||||
|
|
@ -26,6 +26,11 @@ state_hub_task_id: "de8a8e05-93f9-4082-bbb0-5b522179421d"
|
|||
Establish the `rapp-qonto` identity and OpenBao-backed ExternalSecret lane
|
||||
without exposing credential values.
|
||||
|
||||
2026-07-27: ops-mason surveyed live OpenBao state and produced reviewed plan
|
||||
`rapp-qonto-openbao-kubernetes-lane`. It reuses the existing exact-scope Qonto
|
||||
policy, replaces the draft static-token store with Kubernetes authentication,
|
||||
and awaits the mandatory structural-access approval before build.
|
||||
|
||||
## T02 - Enforce restricted Qonto egress
|
||||
|
||||
```task
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue