Harden secret provisioning and lifecycle controls
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0217e-8c4c-7383-be6b-f50a6e485306
This commit is contained in:
parent
0617923ff1
commit
3a1bd4f1c8
23 changed files with 1369 additions and 162 deletions
|
|
@ -15,7 +15,7 @@
|
|||
# Apply approved production lane values (provisioning) and metadata.
|
||||
# Owner-scoped prod lanes (e.g. whynot-design/...) — NOT under build/ or test/.
|
||||
path "secret/data/+/*" {
|
||||
capabilities = ["create", "update"]
|
||||
capabilities = ["create", "update", "patch"]
|
||||
}
|
||||
path "secret/metadata/+/*" {
|
||||
capabilities = ["create", "read", "update", "list"]
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue