Document scope alignment and warden-sign readiness
This commit is contained in:
parent
d8aadaffe3
commit
ae685f3a0a
10 changed files with 736 additions and 41 deletions
19
.decisions/SECRETS-WP-0004.yaml
Normal file
19
.decisions/SECRETS-WP-0004.yaml
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
# Offline approval mirror for the canonical State Hub decision
|
||||
# 4589dcb7-c0df-4073-9a0b-4f80a0fcdb93 (SECRETS-WP-0004).
|
||||
#
|
||||
# Build-mode short-circuit: the operator (Bernd) authorized the warden-sign prod
|
||||
# apply and the canonical hub decision is recorded; this mirror lets
|
||||
# `secrets-engine apply warden-sign --stage prod` resolve the lane's decision_ref
|
||||
# (SECRETS-WP-0004) without waiting. The hub decision is the audit record; resolve
|
||||
# it formally with "Approved:". NON-SECRET: contains no token value.
|
||||
id: SECRETS-WP-0004
|
||||
title: "warden-sign auth-capability lane — prod apply (FLEX-WP-0007 T4)"
|
||||
status: resolved
|
||||
superseded_by: null
|
||||
decided_by: "human"
|
||||
review_url: "http://127.0.0.1:8000/decisions/4589dcb7-c0df-4073-9a0b-4f80a0fcdb93"
|
||||
rationale: >-
|
||||
APPROVE: establish the warden-sign OpenBao policy + AppRole granting update on
|
||||
ssh/sign/{agt,adm,atm}-role only, for the FLEX-WP-0007 T4 production policy-gate
|
||||
smoke. Tightly scoped (denial probes confirm no token-create/sudo/root/admin).
|
||||
No secret value exposed or stored. Operator-authorized in build mode.
|
||||
Loading…
Add table
Add a link
Reference in a new issue