docs: record native lane readiness
This commit is contained in:
parent
398955295b
commit
3ca0e63bed
1 changed files with 12 additions and 0 deletions
|
|
@ -191,6 +191,18 @@ status: wait
|
|||
priority: high
|
||||
```
|
||||
|
||||
Readiness update 2026-08-21: rendered non-mutating production dry-runs for all
|
||||
five lanes. Every plan checks the externally managed `platform` mount without
|
||||
mutation, writes one exact-path read policy, and proposes the reviewed bounded
|
||||
AppRole (15-minute token TTL, 30-minute maximum TTL, 15-minute single-use
|
||||
Secret ID, and eight token uses). OpenBao is reachable and unsealed, but route
|
||||
status remains `ready: false`: the original CCR references approve the existing
|
||||
workload lanes and are not resolvable State Hub approvals for the new native
|
||||
AppRoles. This session also has no production OpenBao token or bootstrap file.
|
||||
Requested per-lane approval references and scoped attended/apply authority from
|
||||
railiance-platform in message `3db3da86-2f3f-4301-8be6-74b507ea66a0`. No value
|
||||
was read and no OpenBao mutation was attempted.
|
||||
|
||||
For each lane, obtain the required decision/operator approval before any live
|
||||
OpenBao policy, auth-role, provisioning, rotation, or delivery change. Start
|
||||
with metadata/capability-safe checks and preserve the current ops-warden proxy
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue