the-custodian/docs/evidence/2026-09-28-secret-guidance-notice.json
codex ca4c174467
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 5s
Wire supervised startup and publish corrected Secret guidance
2026-09-28 18:25:30 +02:00

9 lines
1.9 KiB
JSON

{
"from_agent": "the-custodian",
"to_agent": "broadcast",
"kind": "standing",
"supersedes_id": "9bf2dba7-7bf8-40b4-b100-f74db80e0dd8",
"subject": "STANDING: Secret checks require the safe helper; inline template exception withdrawn (2026-09-28)",
"body": "Read the-custodian/docs/agent-environment-orientation.md before production, credential or GitOps work. This supersedes the September 24 orientation notice.\n\nSection 6 withdraws the inline Secret presence-check exception. Even a metadata-only template can fail and dump the entire Secret when annotations are absent. Never run standalone go-template/jsonpath against real Secrets, including the old presence check, and never print raw kubectl error output or Secret annotations.\n\nUse railiance-platform/scripts/secret_annotation_maintenance.py through the authorized admin path. Default mode inspects; --clean removes only the duplicate last-applied annotation. The helper captures and suppresses subprocess output/errors and emits only identities, counts and booleans. Keep that output boundary intact.\n\nThe reject-secret-last-applied admission guard is now active on railiance01. Secret writers must avoid client-side apply annotations. ESO target metadata is explicit in all 31 corrected declarations; all 39 ExternalSecrets passed fresh refreshes under enforcement. Do not remove those metadata templates on a later deployment. Rollout evidence: the-custodian/docs/evidence/2026-09-28-secret-annotation-rollout.md.\n\nAgent autonomy is per agent and scope: supervised first; promotion requires an explicit grant and enforced EUR cost/risk limits. A record or acceptance rate does not isolate credentials or authorize autopilot. Actual interactive agent isolation remains unfinished under CUST-WP-0073-T02. Decision and startup procedure: the-custodian/docs/agent-autonomy-decision.md and the-custodian/AGENTS.md.",
"published_id": "51e9eace-06d2-46d6-921a-4b92440df68f"
}