Wire supervised startup and publish corrected Secret guidance
This commit is contained in:
parent
416dbf961c
commit
ca4c174467
5 changed files with 90 additions and 88 deletions
|
|
@ -75,10 +75,9 @@ refreshes of all 39 ExternalSecrets. The platform owner's pinned revision
|
|||
`7daf7e9` is authoritative; the original proposal file is retained for history.
|
||||
Reference: [ValidatingAdmissionPolicy](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/).
|
||||
|
||||
Before any retry, fix and verify the 31 ESO declarations described in the rollout
|
||||
receipt, then in one attended railiance-platform window: remove existing last-applied
|
||||
annotations without logging values; persist the manifest in that owner's
|
||||
deployment path; dry-run and diff; install policy and binding. Use only a
|
||||
For future changes, preserve the explicit ESO target metadata already deployed.
|
||||
Use the owner's source and deployment path, dry-run and diff, and the safe
|
||||
maintenance helper for any required annotation cleanup. Use only a
|
||||
synthetic, non-credential Secret in a scratch namespace to verify clean create
|
||||
and update succeed, annotated create/update (including empty annotation) fail,
|
||||
and client-side apply fails. Verify the policy type-check status, then remove
|
||||
|
|
@ -92,8 +91,8 @@ not revoke any credential or stop other ways of reading secrets.
|
|||
|
||||
## Guidance and deferred rotation (T04/T05)
|
||||
|
||||
The September 24 standing notice exists. The raw presence template is now
|
||||
withdrawn: absent annotations can trigger a dump of the full Secret. Use only
|
||||
The September 28 standing notice supersedes September 24 and explicitly
|
||||
withdraws the raw presence template: absent annotations can trigger a dump of the full Secret. Use only
|
||||
the maintenance helper, which captures and suppresses kubectl output on errors. Claude's recorded guard remains a
|
||||
stopgap. No equivalent Codex/Grok read-denial hook has been established by this
|
||||
work; this session has broad kubectl/SSH permissions, so instructions are the
|
||||
|
|
|
|||
9
docs/evidence/2026-09-28-secret-guidance-notice.json
Normal file
9
docs/evidence/2026-09-28-secret-guidance-notice.json
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
{
|
||||
"from_agent": "the-custodian",
|
||||
"to_agent": "broadcast",
|
||||
"kind": "standing",
|
||||
"supersedes_id": "9bf2dba7-7bf8-40b4-b100-f74db80e0dd8",
|
||||
"subject": "STANDING: Secret checks require the safe helper; inline template exception withdrawn (2026-09-28)",
|
||||
"body": "Read the-custodian/docs/agent-environment-orientation.md before production, credential or GitOps work. This supersedes the September 24 orientation notice.\n\nSection 6 withdraws the inline Secret presence-check exception. Even a metadata-only template can fail and dump the entire Secret when annotations are absent. Never run standalone go-template/jsonpath against real Secrets, including the old presence check, and never print raw kubectl error output or Secret annotations.\n\nUse railiance-platform/scripts/secret_annotation_maintenance.py through the authorized admin path. Default mode inspects; --clean removes only the duplicate last-applied annotation. The helper captures and suppresses subprocess output/errors and emits only identities, counts and booleans. Keep that output boundary intact.\n\nThe reject-secret-last-applied admission guard is now active on railiance01. Secret writers must avoid client-side apply annotations. ESO target metadata is explicit in all 31 corrected declarations; all 39 ExternalSecrets passed fresh refreshes under enforcement. Do not remove those metadata templates on a later deployment. Rollout evidence: the-custodian/docs/evidence/2026-09-28-secret-annotation-rollout.md.\n\nAgent autonomy is per agent and scope: supervised first; promotion requires an explicit grant and enforced EUR cost/risk limits. A record or acceptance rate does not isolate credentials or authorize autopilot. Actual interactive agent isolation remains unfinished under CUST-WP-0073-T02. Decision and startup procedure: the-custodian/docs/agent-autonomy-decision.md and the-custodian/AGENTS.md.",
|
||||
"published_id": "51e9eace-06d2-46d6-921a-4b92440df68f"
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue