From 3ca0e63bed109a64774a5c8d94ca8953a815a766 Mon Sep 17 00:00:00 2001 From: tegwick Date: Fri, 21 Aug 2026 09:00:10 +0200 Subject: [PATCH] docs: record native lane readiness --- workplans/SECRETS-WP-0006-catalog-lane-adoption.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/workplans/SECRETS-WP-0006-catalog-lane-adoption.md b/workplans/SECRETS-WP-0006-catalog-lane-adoption.md index f6cd04c..62be5f4 100644 --- a/workplans/SECRETS-WP-0006-catalog-lane-adoption.md +++ b/workplans/SECRETS-WP-0006-catalog-lane-adoption.md @@ -191,6 +191,18 @@ status: wait priority: high ``` +Readiness update 2026-08-21: rendered non-mutating production dry-runs for all +five lanes. Every plan checks the externally managed `platform` mount without +mutation, writes one exact-path read policy, and proposes the reviewed bounded +AppRole (15-minute token TTL, 30-minute maximum TTL, 15-minute single-use +Secret ID, and eight token uses). OpenBao is reachable and unsealed, but route +status remains `ready: false`: the original CCR references approve the existing +workload lanes and are not resolvable State Hub approvals for the new native +AppRoles. This session also has no production OpenBao token or bootstrap file. +Requested per-lane approval references and scoped attended/apply authority from +railiance-platform in message `3db3da86-2f3f-4301-8be6-74b507ea66a0`. No value +was read and no OpenBao mutation was attempted. + For each lane, obtain the required decision/operator approval before any live OpenBao policy, auth-role, provisioning, rotation, or delivery change. Start with metadata/capability-safe checks and preserve the current ops-warden proxy