Record T03 readiness and the remaining upstream blocker
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
e54f67c537
commit
e858115210
2 changed files with 28 additions and 4 deletions
|
|
@ -59,4 +59,25 @@ ServiceAccount token manifest. Prove a valid caller succeeds, no token returns
|
|||
401, and user-engine cannot represent another protected system. This is a live
|
||||
operator rollout and was not performed by the source change.
|
||||
|
||||
2026-08-18 readiness review: our half is done. The `rapp-user-engine` managed
|
||||
package is now the apply home, and image `sha256:c501aeb2…` from `7604d31` —
|
||||
which contains the caller-token change — is live and passed `make verify-live`.
|
||||
The projected ServiceAccount token manifest is in place: audience `flex-auth`,
|
||||
mounted at `/var/run/secrets/flex-auth-caller/token`, with
|
||||
`USER_ENGINE_FLEX_AUTH_TOKEN_FILE` pointing at it. flex-auth's deploy carries
|
||||
the binding `user-engine=system:serviceaccount:user-engine:user-engine`.
|
||||
|
||||
The blocker is now precisely one upstream item. FLEX-WP-0015-T02 is `wait`:
|
||||
ADR 0004's TokenReview choke point exists in flex-auth source, but the running
|
||||
digest is unchanged, so production still accepts unauthenticated callers and
|
||||
our Authorization header is sent and ignored. Running the probe today would
|
||||
pass steps 1 and 3 and silently fail step 2 — a false pass on the only
|
||||
assertion that proves enforcement. The probe is therefore written down rather
|
||||
than run: see `docs/flex-auth-caller-identity.md`, which carries all three
|
||||
checks as commands plus the digests to record.
|
||||
|
||||
This task stays `wait` on FLEX-WP-0015-T02 promotion through FLEX-WP-0011,
|
||||
and on an operator shell with cluster credentials, which agent sessions in
|
||||
this repo do not hold.
|
||||
|
||||
Contract: `docs/flex-auth-caller-identity.md`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue