diff --git a/workplans/SECRETS-WP-0006-catalog-lane-adoption.md b/workplans/SECRETS-WP-0006-catalog-lane-adoption.md index f6cd04c..62be5f4 100644 --- a/workplans/SECRETS-WP-0006-catalog-lane-adoption.md +++ b/workplans/SECRETS-WP-0006-catalog-lane-adoption.md @@ -191,6 +191,18 @@ status: wait priority: high ``` +Readiness update 2026-08-21: rendered non-mutating production dry-runs for all +five lanes. Every plan checks the externally managed `platform` mount without +mutation, writes one exact-path read policy, and proposes the reviewed bounded +AppRole (15-minute token TTL, 30-minute maximum TTL, 15-minute single-use +Secret ID, and eight token uses). OpenBao is reachable and unsealed, but route +status remains `ready: false`: the original CCR references approve the existing +workload lanes and are not resolvable State Hub approvals for the new native +AppRoles. This session also has no production OpenBao token or bootstrap file. +Requested per-lane approval references and scoped attended/apply authority from +railiance-platform in message `3db3da86-2f3f-4301-8be6-74b507ea66a0`. No value +was read and no OpenBao mutation was attempted. + For each lane, obtain the required decision/operator approval before any live OpenBao policy, auth-role, provisioning, rotation, or delivery change. Start with metadata/capability-safe checks and preserve the current ops-warden proxy