chore(wp-0004): write back State Hub workstream/task IDs
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
bcdfc78087
commit
9092ebb59b
1 changed files with 6 additions and 0 deletions
|
|
@ -9,6 +9,7 @@ owner: codex
|
|||
topic_slug: custodian
|
||||
created: "2026-06-29"
|
||||
updated: "2026-06-29"
|
||||
state_hub_workstream_id: "eb1bdff7-909c-4391-8b95-6baf1feb3a54"
|
||||
---
|
||||
|
||||
# SECRETS-WP-0004 - Provision a scoped warden-sign token lane
|
||||
|
|
@ -60,6 +61,7 @@ OpenBao, so it also exercises parts of the engine the npm pilot did not.
|
|||
id: SECRETS-WP-0004-T01
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "278e9a20-eaa6-47a8-9dd7-62952961d520"
|
||||
```
|
||||
|
||||
Add a lane kind that represents an OpenBao auth credential (AppRole + policy)
|
||||
|
|
@ -81,6 +83,7 @@ Acceptance:
|
|||
id: SECRETS-WP-0004-T02
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "f4b209e5-c900-4f5e-bb0c-f0c5b27b70c2"
|
||||
```
|
||||
|
||||
Author the `warden-sign` ACL policy and AppRole. Policy: `update` on
|
||||
|
|
@ -102,6 +105,7 @@ Acceptance:
|
|||
id: SECRETS-WP-0004-T03
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "4b414788-d670-496b-9c57-074464a012c4"
|
||||
```
|
||||
|
||||
Apply the policy + AppRole on `https://bao.coulomb.social` using a mode-0600
|
||||
|
|
@ -120,6 +124,7 @@ Acceptance:
|
|||
id: SECRETS-WP-0004-T04
|
||||
status: todo
|
||||
priority: high
|
||||
state_hub_task_id: "52b5cf88-029f-4f4b-8fe9-0a8dc30378b5"
|
||||
```
|
||||
|
||||
Define and execute the handoff: mint a fresh `secret_id`, deliver it (with the
|
||||
|
|
@ -140,6 +145,7 @@ Acceptance:
|
|||
id: SECRETS-WP-0004-T05
|
||||
status: todo
|
||||
priority: medium
|
||||
state_hub_task_id: "aa0f281e-976d-4fcd-b8a3-78582117f86f"
|
||||
```
|
||||
|
||||
Confirm the unblock end to end, then reply to ops-warden (msg 077ac90d) with the
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue