Triage the older secrets-engine inbox: record platform waits and railiance-clock
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 3s

railiance-platform e82bb289 recorded against SECRETS-WP-0006-T05 (explicit wait
on T04 serving; CCR-2026-0003 is provenance only). 29cccf8a recorded against
SECRETS-WP-0008-T06, including the open tenant:coulomb vs tenant:platform
question for the service JWT, left for an owner session. railiance-clock's
review request opened as SECRETS-IN-0003. The intelligence-radar messages are
superseded by SECRETS-WP-0010-T03 (done 2026-09-16) and answered by pointer.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
This commit is contained in:
tegwick 2026-09-21 07:37:53 +02:00
parent 8a48cb05df
commit 377ec06d69
3 changed files with 54 additions and 1 deletions

View file

@ -339,7 +339,22 @@ does not read `BAO_TOKEN` on failure. `--bootstrap-token-file` is a named
break-glass provider with `auth_break_glass` evidence.
The platform-owned OpenBao JWT mount/role is still unpublished, so auto keeps
bootstrap/env and this task remains `wait`. Companion §7 / statute §3.4: an
bootstrap/env and this task remains `wait`.
Inbox triage 2026-09-21. railiance-platform `29cccf8a` (2026-09-09): status,
not a contract. Their side is RPF-WP-0035-T02 (design
`docs/credential-lane-designs/secrets-engine-service-jwt.md`), still `wait`.
Designed: role/audience `secrets-engine-openbao`, subject
`service:secrets-engine`, token policy `secrets-engine-login-self`, five-minute
budget, login-only. KeyCape issuer `https://kc.coulomb.social` and its JWKS are
now confirmed live, so the remaining blocker is this registration's issued
claims, consumer readiness, an approved source and attended apply authority.
**Open question for secrets-engine, not answered in the triage session:** the
JWT design says `tenant:coulomb`, while the approval chain resolved to
`tenant:platform` (decision `5ed3fb35`) and approval-engine compares tenant by
exact string. Which tenant the OpenBao service identity carries is a design
decision for an owner session; platform will correct its design before the
role exists once told. A service login grants no lane mutation authority. Companion §7 / statute §3.4: an
agent holds no long-lived credential of its own. Authority is per task,
time-bounded, and attributable to the principal it acts for.