Document scope alignment and warden-sign readiness

This commit is contained in:
tegwick 2026-06-30 00:52:05 +02:00
parent d8aadaffe3
commit ae685f3a0a
10 changed files with 736 additions and 41 deletions

View file

@ -0,0 +1,19 @@
# Offline approval mirror for the canonical State Hub decision
# 4589dcb7-c0df-4073-9a0b-4f80a0fcdb93 (SECRETS-WP-0004).
#
# Build-mode short-circuit: the operator (Bernd) authorized the warden-sign prod
# apply and the canonical hub decision is recorded; this mirror lets
# `secrets-engine apply warden-sign --stage prod` resolve the lane's decision_ref
# (SECRETS-WP-0004) without waiting. The hub decision is the audit record; resolve
# it formally with "Approved:". NON-SECRET: contains no token value.
id: SECRETS-WP-0004
title: "warden-sign auth-capability lane — prod apply (FLEX-WP-0007 T4)"
status: resolved
superseded_by: null
decided_by: "human"
review_url: "http://127.0.0.1:8000/decisions/4589dcb7-c0df-4073-9a0b-4f80a0fcdb93"
rationale: >-
APPROVE: establish the warden-sign OpenBao policy + AppRole granting update on
ssh/sign/{agt,adm,atm}-role only, for the FLEX-WP-0007 T4 production policy-gate
smoke. Tightly scoped (denial probes confirm no token-create/sudo/root/admin).
No secret value exposed or stored. Operator-authorized in build mode.