docs: plan production lifecycle hardening
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0217e-8c4c-7383-be6b-f50a6e485306
This commit is contained in:
tegwick 2026-08-23 11:27:10 +02:00
parent 7799716c73
commit 0617923ff1
2 changed files with 339 additions and 0 deletions

View file

@ -203,6 +203,13 @@ Requested per-lane approval references and scoped attended/apply authority from
railiance-platform in message `3db3da86-2f3f-4301-8be6-74b507ea66a0`. No value
was read and no OpenBao mutation was attempted.
Hardening dependency 2026-08-23: `SECRETS-WP-0007` now owns the engine-level
provisioning, lifecycle, approval-binding, delivery-session, verification, and
evidence gaps found during scope assessment. T05 must not provision or revoke
the existing shared paths through the current commands. Native live adoption
resumes through `SECRETS-WP-0007-T07` after its T01-T06 safety gates; this task
continues to own the per-lane production evidence and acceptance outcome.
For each lane, obtain the required decision/operator approval before any live
OpenBao policy, auth-role, provisioning, rotation, or delivery change. Start
with metadata/capability-safe checks and preserve the current ops-warden proxy