secrets-engine/workplans/SECRETS-WP-0001-statehub-bootstrap.md
tegwick a852d3f1ff feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane
Implements SECRETS-WP-0002 end to end as a uv-managed Python package:

- catalog: non-secret lane registry + strict validator (build/test/prod)
- stage roles + OpenBao ACL policies; guards refuse wildcards, sys/, identity/,
  admin names, and cross-stage paths before any backend call
- plan/apply: dry-run-first, idempotent policy + approle apply, decision-gated
- decisions: State Hub lookup with local-fixture fallback; non-secret evidence
  to JSONL + hub progress, scrubbed of any value
- provision/verify: mode-0600 file import + generated test values; positive/
  negative checks that never print the value
- exec delivery: `exec --catalog ... -- npm publish` injects the token via a
  temp .npmrc for the child only, cleaned up on exit/failure/interrupt
- ops-warden routing contract + hardening backlog docs
- 34 tests incl. live OpenBao integration; scripts/demo-e2e.sh runs the full
  chain against a throwaway bao dev server

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 12:28:45 +02:00

1.5 KiB

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
SECRETS-WP-0001 workplan Bootstrap State Hub integration infotech secrets-engine ready codex custodian 2026-06-28 2026-06-28 53f0c7b7-2899-4e91-a18e-67186775e2e2

Bootstrap State Hub integration

secrets-engine is a headless, multi-application, multi-tenant secrets workflow and automation layer that orchestrates approved secret custody, delivery, and lifecycle work across build, test, and production stages, with OpenBao as the initial enforcement backend.

Review Generated Integration Files

id: SECRETS-WP-0001-T01
status: todo
priority: high
state_hub_task_id: "e93ea995-8c3b-4892-ab09-70cf7e0a0346"

Review INTENT.md, SCOPE.md, AGENTS.md, and .custodian-brief.md. Replace generated placeholders with repo-specific facts where needed.

Verify Local Developer Workflow

id: SECRETS-WP-0001-T02
status: todo
priority: high
state_hub_task_id: "3269b817-6e10-4e9f-804f-73a8b1ded920"

Identify the repo's install, test, lint, build, and run commands. Add or refine those commands in the agent instructions so future coding sessions can verify changes confidently.

Seed First Real Workplan

id: SECRETS-WP-0001-T03
status: todo
priority: medium
state_hub_task_id: "62de7242-1a4c-4ed0-a4e4-ebe17bcc06b6"

Create the first implementation workplan for the repository's most important next change. After workplan file updates, run from ~/state-hub:

make fix-consistency REPO=secrets-engine