secrets-engine/.decisions/SECRETS-WP-0004.yaml

19 lines
1 KiB
YAML

# Offline approval mirror for the canonical State Hub decision
# 4589dcb7-c0df-4073-9a0b-4f80a0fcdb93 (SECRETS-WP-0004).
#
# Build-mode short-circuit: the operator (Bernd) authorized the warden-sign prod
# apply and the canonical hub decision is recorded; this mirror lets
# `secrets-engine apply warden-sign --stage prod` resolve the lane's decision_ref
# (SECRETS-WP-0004) without waiting. The hub decision is the audit record; resolve
# it formally with "Approved:". NON-SECRET: contains no token value.
id: SECRETS-WP-0004
title: "warden-sign auth-capability lane — prod apply (FLEX-WP-0007 T4)"
status: resolved
superseded_by: null
decided_by: "human"
review_url: "http://127.0.0.1:8000/decisions/4589dcb7-c0df-4073-9a0b-4f80a0fcdb93"
rationale: >-
APPROVE: establish the warden-sign OpenBao policy + AppRole granting update on
ssh/sign/{agt,adm,atm}-role only, for the FLEX-WP-0007 T4 production policy-gate
smoke. Tightly scoped (denial probes confirm no token-create/sudo/root/admin).
No secret value exposed or stored. Operator-authorized in build mode.