Implements SECRETS-WP-0002 end to end as a uv-managed Python package: - catalog: non-secret lane registry + strict validator (build/test/prod) - stage roles + OpenBao ACL policies; guards refuse wildcards, sys/, identity/, admin names, and cross-stage paths before any backend call - plan/apply: dry-run-first, idempotent policy + approle apply, decision-gated - decisions: State Hub lookup with local-fixture fallback; non-secret evidence to JSONL + hub progress, scrubbed of any value - provision/verify: mode-0600 file import + generated test values; positive/ negative checks that never print the value - exec delivery: `exec --catalog ... -- npm publish` injects the token via a temp .npmrc for the child only, cleaned up on exit/failure/interrupt - ops-warden routing contract + hardening backlog docs - 34 tests incl. live OpenBao integration; scripts/demo-e2e.sh runs the full chain against a throwaway bao dev server Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1.5 KiB
1.5 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | state_hub_workstream_id |
|---|---|---|---|---|---|---|---|---|---|---|
| SECRETS-WP-0001 | workplan | Bootstrap State Hub integration | infotech | secrets-engine | ready | codex | custodian | 2026-06-28 | 2026-06-28 | 53f0c7b7-2899-4e91-a18e-67186775e2e2 |
Bootstrap State Hub integration
secrets-engine is a headless, multi-application, multi-tenant secrets workflow and automation layer that orchestrates approved secret custody, delivery, and lifecycle work across build, test, and production stages, with OpenBao as the initial enforcement backend.
Review Generated Integration Files
id: SECRETS-WP-0001-T01
status: todo
priority: high
state_hub_task_id: "e93ea995-8c3b-4892-ab09-70cf7e0a0346"
Review INTENT.md, SCOPE.md, AGENTS.md, and .custodian-brief.md.
Replace generated placeholders with repo-specific facts where needed.
Verify Local Developer Workflow
id: SECRETS-WP-0001-T02
status: todo
priority: high
state_hub_task_id: "3269b817-6e10-4e9f-804f-73a8b1ded920"
Identify the repo's install, test, lint, build, and run commands. Add or refine those commands in the agent instructions so future coding sessions can verify changes confidently.
Seed First Real Workplan
id: SECRETS-WP-0001-T03
status: todo
priority: medium
state_hub_task_id: "62de7242-1a4c-4ed0-a4e4-ebe17bcc06b6"
Create the first implementation workplan for the repository's most important
next change. After workplan file updates, run from ~/state-hub:
make fix-consistency REPO=secrets-engine