19 lines
1 KiB
YAML
19 lines
1 KiB
YAML
# Offline approval mirror for the canonical State Hub decision
|
|
# 4589dcb7-c0df-4073-9a0b-4f80a0fcdb93 (SECRETS-WP-0004).
|
|
#
|
|
# Build-mode short-circuit: the operator (Bernd) authorized the warden-sign prod
|
|
# apply and the canonical hub decision is recorded; this mirror lets
|
|
# `secrets-engine apply warden-sign --stage prod` resolve the lane's decision_ref
|
|
# (SECRETS-WP-0004) without waiting. The hub decision is the audit record; resolve
|
|
# it formally with "Approved:". NON-SECRET: contains no token value.
|
|
id: SECRETS-WP-0004
|
|
title: "warden-sign auth-capability lane — prod apply (FLEX-WP-0007 T4)"
|
|
status: resolved
|
|
superseded_by: null
|
|
decided_by: "human"
|
|
review_url: "http://127.0.0.1:8000/decisions/4589dcb7-c0df-4073-9a0b-4f80a0fcdb93"
|
|
rationale: >-
|
|
APPROVE: establish the warden-sign OpenBao policy + AppRole granting update on
|
|
ssh/sign/{agt,adm,atm}-role only, for the FLEX-WP-0007 T4 production policy-gate
|
|
smoke. Tightly scoped (denial probes confirm no token-create/sudo/root/admin).
|
|
No secret value exposed or stored. Operator-authorized in build mode.
|