diff --git a/intakes/intakes.md b/intakes/intakes.md index 23af1f5..47fb80b 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -45,3 +45,34 @@ created: '2026-08-28T21:02:14.320087Z' updated: '2026-08-28T21:02:14.320087Z' state_hub_intake_id: "01a04cf6-dcd7-7bd4-82e4-ef434b15fe46" ``` + +## SECRETS-IN-0002 — flex-auth → access-engine repository-coordinate rename (consumer surface) + +```yaml +id: SECRETS-IN-0002 +kind: intake +title: 'flex-auth to access-engine repository-coordinate rename: consumer-surface confirmation' +status: open +origin: cross-repo +origin_ref: FLEX-WP-0020 (hub message 15cf351a-bad8-4259-9b6f-b21d183a20ab) +priority: low +owner: secrets-engine +requested_by: flex-auth +resolution: '' +description: >- + flex-auth is preparing a repository-coordinate rename to access-engine. + Repository UUID fda8ad85-a7d7-4055-8f21-902a533e59df and Forge ID 42 are + unchanged; runtime and product names stay flex-auth per FLEX-DEC-2026-013. + secrets-engine is a consumer surface and is asked to confirm no live + repository URL or path remains. Survey 2026-09-21 found exactly one: + docs/approval-service-auth.md line 56 passes + `--flex-auth-source /home/worsch/flex-auth`, a local checkout path. Every + other flex-auth string in this repository is a runtime or contract name that + FLEX-DEC-2026-013 keeps: the Kubernetes namespace and service + flex-auth-secrets-engine.flex-auth.svc.cluster.local, the token audience + flex-auth, the contract version flex-auth.decision-record.v1, and prose + citations of flex-auth decisions and documents. Those must not be renamed. + Held open rather than edited, because the rename is preparing and not + complete, and changing a documented local checkout path ahead of the move + would document a path that does not exist yet. Close by updating that one + line when flex-auth confirms the rename has landed.