rein-aharness/workplans/ADHOC-2026-09-04.md
tegwick aedfadda0b fix(runtime): restore Binky OpenBao discovery
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a06bfe-2a55-7ed3-bacd-879977b099bf
2026-09-04 17:46:10 +02:00

1.5 KiB

id type title domain repo status owner topic_slug created updated
HARNESS-WP-ADHOC-2026-09-04 workplan Restore Binky mail-scan OpenBao runtime discovery infotech rein-aharness finished codex activity-core 2026-09-04 2026-09-04

Restore Binky mail-scan OpenBao runtime discovery

Repair and verify the claim-loop runtime

id: HARNESS-WP-ADHOC-2026-09-04-T01
status: done
priority: high

Make the railiance01 claim-loop discover the existing host-installed OpenBao client and the already-provisioned Binky mail AppRole directory. Preserve explicit environment overrides, install the corrected launcher/unit, and prove an AppRole login plus allowlisted IMAP field presence without exposing values.

Completed 2026-09-04. The launcher now supplies non-secret defaults for BAO_ADDR, VAULT_ADDR, and EXECUTOR_APPROLE_DIR, and ensures ~/.local/bin is present in PATH; explicit overrides remain authoritative. The corrected wrapper and unit were installed on railiance01 and the claim loop restarted cleanly. Its child environment resolves OpenBao v2.5.4 at the expected address and the existing mode-0600 AppRole files. A capabilities-safe smoke proved read on tenants/data/binky/company-email/imap, deny on the sibling Qonto path, and field presence for IMAP_USERNAME and IMAP_PASSWORD without printing either value. Focused launcher and mail-scan tests passed 5 tests. Pre-change live launcher and unit backups carry suffix .pre-bao-fix-20260904.