Wire supervised startup and publish corrected Secret guidance
This commit is contained in:
parent
416dbf961c
commit
ca4c174467
5 changed files with 90 additions and 88 deletions
|
|
@ -75,10 +75,9 @@ refreshes of all 39 ExternalSecrets. The platform owner's pinned revision
|
|||
`7daf7e9` is authoritative; the original proposal file is retained for history.
|
||||
Reference: [ValidatingAdmissionPolicy](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/).
|
||||
|
||||
Before any retry, fix and verify the 31 ESO declarations described in the rollout
|
||||
receipt, then in one attended railiance-platform window: remove existing last-applied
|
||||
annotations without logging values; persist the manifest in that owner's
|
||||
deployment path; dry-run and diff; install policy and binding. Use only a
|
||||
For future changes, preserve the explicit ESO target metadata already deployed.
|
||||
Use the owner's source and deployment path, dry-run and diff, and the safe
|
||||
maintenance helper for any required annotation cleanup. Use only a
|
||||
synthetic, non-credential Secret in a scratch namespace to verify clean create
|
||||
and update succeed, annotated create/update (including empty annotation) fail,
|
||||
and client-side apply fails. Verify the policy type-check status, then remove
|
||||
|
|
@ -92,8 +91,8 @@ not revoke any credential or stop other ways of reading secrets.
|
|||
|
||||
## Guidance and deferred rotation (T04/T05)
|
||||
|
||||
The September 24 standing notice exists. The raw presence template is now
|
||||
withdrawn: absent annotations can trigger a dump of the full Secret. Use only
|
||||
The September 28 standing notice supersedes September 24 and explicitly
|
||||
withdraws the raw presence template: absent annotations can trigger a dump of the full Secret. Use only
|
||||
the maintenance helper, which captures and suppresses kubectl output on errors. Claude's recorded guard remains a
|
||||
stopgap. No equivalent Codex/Grok read-denial hook has been established by this
|
||||
work; this session has broad kubectl/SSH permissions, so instructions are the
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue