Add OpenBao emergency lockdown runbook

This commit is contained in:
2026-05-25 18:31:48 +02:00
parent b9bad47a21
commit e2540529f0
2 changed files with 153 additions and 15 deletions

View File

@@ -257,6 +257,12 @@ the operator can still proceed deliberately on a tainted workpath.
in the bootstrap console. The initial config command can now be recorded as
applied while root-token revocation/escrow remains a separate gate.
**2026-05-25:** Added an Emergency lock-down runbook for sealing Railiance
OpenBao without placing tokens on the command line. Reordered the console into
Introduction & Actors, Subsystems & Scopes, Roles & Responsibilities,
Integration & Tests, Artefacts & Locations, Usecases & Runbooks, and
Terminology & Patterns.
**2026-05-24:** Stepped back from ad hoc secret rollout and added the
custodian age-key bootstrap model to the control surface. The UI now records
the custodian public age recipient, a derived fingerprint, and a non-secret