Wire supervised startup and publish corrected Secret guidance
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s

This commit is contained in:
codex 2026-09-28 18:25:30 +02:00
parent 416dbf961c
commit ca4c174467
5 changed files with 90 additions and 88 deletions

View file

@ -75,10 +75,9 @@ refreshes of all 39 ExternalSecrets. The platform owner's pinned revision
`7daf7e9` is authoritative; the original proposal file is retained for history.
Reference: [ValidatingAdmissionPolicy](https://kubernetes.io/docs/reference/access-authn-authz/validating-admission-policy/).
Before any retry, fix and verify the 31 ESO declarations described in the rollout
receipt, then in one attended railiance-platform window: remove existing last-applied
annotations without logging values; persist the manifest in that owner's
deployment path; dry-run and diff; install policy and binding. Use only a
For future changes, preserve the explicit ESO target metadata already deployed.
Use the owner's source and deployment path, dry-run and diff, and the safe
maintenance helper for any required annotation cleanup. Use only a
synthetic, non-credential Secret in a scratch namespace to verify clean create
and update succeed, annotated create/update (including empty annotation) fail,
and client-side apply fails. Verify the policy type-check status, then remove
@ -92,8 +91,8 @@ not revoke any credential or stop other ways of reading secrets.
## Guidance and deferred rotation (T04/T05)
The September 24 standing notice exists. The raw presence template is now
withdrawn: absent annotations can trigger a dump of the full Secret. Use only
The September 28 standing notice supersedes September 24 and explicitly
withdraws the raw presence template: absent annotations can trigger a dump of the full Secret. Use only
the maintenance helper, which captures and suppresses kubectl output on errors. Claude's recorded guard remains a
stopgap. No equivalent Codex/Grok read-denial hook has been established by this
work; this session has broad kubectl/SSH permissions, so instructions are the