Ship secret-use snapshot surface for kings-guard
Add secrets-engine secret-use snapshot: catalog plus local evidence only, contracted non-secret fields, declared 1d heartbeat cadence. Never contacts OpenBao. Completeness is not claimed. owner_status stays proposed until kings-guard admits the snapshot as an observation input. Assistant: grok Assistant-Session: 01a05f07-ae72-7781-9fcb-19efd61add00
This commit is contained in:
parent
3abee434df
commit
2278cefbb3
8 changed files with 374 additions and 13 deletions
|
|
@ -65,6 +65,7 @@ SECRETS_ENGINE_HUB_URL="" bash scripts/demo-e2e.sh
|
|||
- KeyCape service-auth consumer boundary: [docs/service-auth.md](docs/service-auth.md)
|
||||
- Approval consume-before-OpenBao (GH-DEC-2026-003): [docs/approval-consumption.md](docs/approval-consumption.md)
|
||||
- OpenBao JWT login contract (engine consumer): [docs/openbao-jwt-login.md](docs/openbao-jwt-login.md)
|
||||
- Secret-use evidence surface: [docs/secret-use-evidence-contract.md](docs/secret-use-evidence-contract.md)
|
||||
|
||||
The implementation is a Python package (`src/secrets_engine/`). OpenBao is
|
||||
reached only through the `bao` CLI adapter (`openbao.py`); the rest of the code
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue