Close SECRETS-WP-0003 whynot-design real publish pilot

Apply, provision, and verify the prod lane on live OpenBao, publish
@whynot/design@0.4.1 through native secrets-engine exec, and teach the
OpenBao client to tolerate stage-role mount/approle probes when sys/mounts
and sys/auth are denied.
This commit is contained in:
tegwick 2026-07-03 17:04:19 +02:00
parent 0bf33a9a96
commit 32dfd4c78b
3 changed files with 78 additions and 11 deletions

View file

@ -15,7 +15,7 @@ Every minted bootstrap token has a revocation task. Track each here:
| --- | --- | --- | --- | --- |
| `~/.secrets-engine/bootstrap/prod.token` | prod | (n/a — demo uses dev server) | 1h | n/a |
| `~/.secrets-engine/bootstrap/prod-warden-sign.token` | prod | SECRETS-WP-0004 live lane applied via attended operator flow; file use not recorded in repo | 1h | cleanup/revocation evidence not recorded |
| `~/.secrets-engine/bootstrap/prod-whynot-design.token` | prod | pending SECRETS-WP-0003 live apply/provision | 1h | pending |
| `~/.secrets-engine/bootstrap/prod-whynot-design.token` | prod | SECRETS-WP-0003 live apply/provision/publish 2026-07-03 | 1h | pending |
Revoke: `bao token revoke -accessor <accessor>` then `shred -u <file>`.
For SECRETS-WP-0004, the scoped `warden-sign` token used for the 2026-06-29
@ -27,7 +27,7 @@ contents in this repo.
| Credential | Custody path | Minted | Revocation task | Revoked? |
| --- | --- | --- | --- | --- |
| whynot-design Gitea bot npm/package token | OpenBao lane `whynot-design-npm-publish`, source handoff file `~/.secrets-engine/handoff/whynot-design-npm.token` | pending SECRETS-WP-0003 bot/token gate | Revoke or rotate the bot token in Gitea, delete the source handoff file with `shred -u`, and record non-secret package/version evidence after publish | pending |
| whynot-design Gitea bot npm/package token | OpenBao lanes `whynot-design-npm-publish` + `platform/workloads/coulomb/whynot-design/npm-publish`; handoff file shredded after provision | SECRETS-WP-0003 publish `@whynot/design@0.4.1` 2026-07-03 | Rotate in Gitea when TTL/policy requires; handoff source file deleted with `shred -u` after provision | handoff shredded; lane value remains in OpenBao |
## H1 — Replace bootstrap token files with OIDC / service auth