Record T03 readiness and the remaining upstream blocker
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-18 12:53:14 +02:00
parent e54f67c537
commit e858115210
2 changed files with 28 additions and 4 deletions

View file

@ -59,4 +59,25 @@ ServiceAccount token manifest. Prove a valid caller succeeds, no token returns
401, and user-engine cannot represent another protected system. This is a live
operator rollout and was not performed by the source change.
2026-08-18 readiness review: our half is done. The `rapp-user-engine` managed
package is now the apply home, and image `sha256:c501aeb2…` from `7604d31`
which contains the caller-token change — is live and passed `make verify-live`.
The projected ServiceAccount token manifest is in place: audience `flex-auth`,
mounted at `/var/run/secrets/flex-auth-caller/token`, with
`USER_ENGINE_FLEX_AUTH_TOKEN_FILE` pointing at it. flex-auth's deploy carries
the binding `user-engine=system:serviceaccount:user-engine:user-engine`.
The blocker is now precisely one upstream item. FLEX-WP-0015-T02 is `wait`:
ADR 0004's TokenReview choke point exists in flex-auth source, but the running
digest is unchanged, so production still accepts unauthenticated callers and
our Authorization header is sent and ignored. Running the probe today would
pass steps 1 and 3 and silently fail step 2 — a false pass on the only
assertion that proves enforcement. The probe is therefore written down rather
than run: see `docs/flex-auth-caller-identity.md`, which carries all three
checks as commands plus the digests to record.
This task stays `wait` on FLEX-WP-0015-T02 promotion through FLEX-WP-0011,
and on an operator shell with cluster credentials, which agent sessions in
this repo do not hold.
Contract: `docs/flex-auth-caller-identity.md`.