Advance supervised agent records and close verified Secret annotation guard
This commit is contained in:
parent
b2f6713721
commit
db91818e84
44 changed files with 6868 additions and 54 deletions
|
|
@ -1,7 +1,7 @@
|
|||
# Agent environment orientation
|
||||
|
||||
**Audience:** every coding agent working in this estate (Claude Code, Codex, Grok, custodian workers). It is tool-neutral.
|
||||
**Owner:** the-custodian. **Last verified:** 2026-09-24.
|
||||
**Owner:** the-custodian. **Last verified:** 2026-09-28 (§6); other sections retain their dated evidence.
|
||||
|
||||
These are facts about the *environment*: where things run, how to reach them, and the traps that cost real time. Each section names its owner. When a fact changes, fix it here and in the owner's record.
|
||||
|
||||
|
|
@ -76,9 +76,24 @@ Owner: railiance-platform (OpenBao) and ops-warden (the `warden access` lane).
|
|||
## 6. Secrets and credentials
|
||||
|
||||
- Run the credential-routing check (`warden route find "<need>"`) before requesting anything. See the "Credential and access routing" section in every repo's `AGENTS.md`.
|
||||
- **Never read a Secret with `-o yaml`, `-o json`, `describe`-style tools, or even `-o jsonpath='{.metadata}'`.** A Secret created with `kubectl apply` carries its full data in the `kubectl.kubernetes.io/last-applied-configuration` annotation, so a metadata read prints the secret. To test for the annotation without printing a value:
|
||||
`kubectl get secret <n> -o go-template='{{ if index .metadata.annotations "kubectl.kubernetes.io/last-applied-configuration" }}HAS-ANNOTATION{{ else }}clean{{ end }}'`
|
||||
- **Do not run any other go-template or jsonpath against a Secret.** On 2026-09-23 a template that only asked for `len .metadata.ownerReferences` failed because the field was absent, and kubectl printed the raw object, including `.data` and the last-applied annotation. A metadata-only template is not safe on that basis. The presence check above is the only template to use.
|
||||
- **Never print Secret objects, annotations, or raw kubectl error output.** A
|
||||
client-side apply annotation can contain a second copy of every value, and a
|
||||
failing template can dump the object. Metadata-only intent does not make a
|
||||
command safe.
|
||||
- **Use the output-suppressing maintenance helper for annotation checks:**
|
||||
`railiance-platform/scripts/secret_annotation_maintenance.py` (no arguments
|
||||
inspects; `--clean` is the supervised mutation). It uses only validated
|
||||
namespace/name fields and a presence template tested for absent, empty and
|
||||
populated annotation maps and empty annotation values. It captures and discards
|
||||
raw kubectl output/errors; receipts contain only names, counts and booleans.
|
||||
- **The September 24 inline presence template is withdrawn.** On September 28,
|
||||
`index .metadata.annotations` failed on an absent map. The wrapper suppressed
|
||||
the resulting object dump; no values reached the agent transcript. Do not run
|
||||
standalone go-template/jsonpath against real Secrets, including the old check.
|
||||
- Agent autonomy is per identified agent and scope: start supervised, record
|
||||
exact proposals and verified outcomes, promote explicitly only under bounded
|
||||
EUR cost and risk grants. See `docs/agent-autonomy-decision.md`. A mode label or
|
||||
approval rate does not isolate credentials or grant runtime permissions.
|
||||
- ExternalSecrets use ClusterSecretStores. The target pattern is **OpenBao Kubernetes auth**: one ServiceAccount per consumer, 15-minute tokens, and a policy scoped to exact paths. Five stores still use static `*-eso-token` Secrets, which expire. Do not re-run the old `*-eso-token-apply` scripts.
|
||||
|
||||
## 7. GitOps (ArgoCD) on railiance01
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue