diff --git a/workplans/SECRETS-WP-0004-warden-sign-token-lane.md b/workplans/SECRETS-WP-0004-warden-sign-token-lane.md index 8418a71..27a3236 100644 --- a/workplans/SECRETS-WP-0004-warden-sign-token-lane.md +++ b/workplans/SECRETS-WP-0004-warden-sign-token-lane.md @@ -148,6 +148,15 @@ single-use `secret_id` to caller-chosen mode-0600 files outside Git worktrees an records only non-secret file paths/TTL metadata. Execution is waiting on live apply and attended out-of-band operator delivery. +2026-06-29: ops-warden follow-up message `f5b276a3-b90f-454f-b883-83eee7c69616` +asked for the OIDC login pointer instead of AppRole handoff because Bernd can +mint the scoped token on his workstation. Added the non-secret pointer: +`bao login -method=oidc -path=netkingdom role=warden-sign`, role path +`auth/netkingdom/role/warden-sign`, bound to `groups=["net-kingdom-admins"]` +and attaching only policy `warden-sign`. Replied to ops-warden in State Hub +message `0bce1e08-58c2-4db4-b06c-f86cf8142273`; no token value, role_id, +secret_id, or token accessor was included. + Define and execute the handoff: mint a fresh `secret_id`, deliver it (with the `role_id`) to the operator out-of-band; warden does `approle login` to obtain a `VAULT_TOKEN`. Post the non-secret pointers on the ops-warden thread (policy name,