docs: record native lane readiness
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-08-21 09:00:10 +02:00
parent 398955295b
commit 3ca0e63bed

View file

@ -191,6 +191,18 @@ status: wait
priority: high priority: high
``` ```
Readiness update 2026-08-21: rendered non-mutating production dry-runs for all
five lanes. Every plan checks the externally managed `platform` mount without
mutation, writes one exact-path read policy, and proposes the reviewed bounded
AppRole (15-minute token TTL, 30-minute maximum TTL, 15-minute single-use
Secret ID, and eight token uses). OpenBao is reachable and unsealed, but route
status remains `ready: false`: the original CCR references approve the existing
workload lanes and are not resolvable State Hub approvals for the new native
AppRoles. This session also has no production OpenBao token or bootstrap file.
Requested per-lane approval references and scoped attended/apply authority from
railiance-platform in message `3db3da86-2f3f-4301-8be6-74b507ea66a0`. No value
was read and no OpenBao mutation was attempted.
For each lane, obtain the required decision/operator approval before any live For each lane, obtain the required decision/operator approval before any live
OpenBao policy, auth-role, provisioning, rotation, or delivery change. Start OpenBao policy, auth-role, provisioning, rotation, or delivery change. Start
with metadata/capability-safe checks and preserve the current ops-warden proxy with metadata/capability-safe checks and preserve the current ops-warden proxy