Clarify core hub staging credential route

This commit is contained in:
2026-06-30 10:20:23 +02:00
parent cb7fd7b19d
commit 1f9ef92a66
4 changed files with 37 additions and 9 deletions

View File

@@ -528,6 +528,23 @@ Progress 2026-06-27:
- Fin-hub/business tasks remain deliberately deferred until identity integration
and ops-hub extension evidence are proven.
Progress 2026-06-30 Core Hub T16 route refinement:
- Rechecked the Core Hub replacement lane after the daily-triage checkpoint.
Core Hub is clean and its remaining open gates are deployed evidence,
activity-core sink smoke, staging import, dual-run/cutover readiness, and
explicit Haskell retirement approval.
- `warden route find` for the Core Hub staging operator/runtime token
need resolves to OpenBao-owned `openbao-api-key`, with
`key-cape-oidc-login` for interactive auth and
`ops-bridge-tunnel` for private endpoint access when needed.
This is not an ops-warden secret request; ops-warden only routes or assists
eligible lanes as the caller.
- Next Core Hub proof requires `CORE_HUB_BASE_URL`, approved
operator/runtime token custody, activity-core widget mapping, then
deployed-smoke plus activity-core sink-smoke evidence with non-secret ids,
prefixes, counts, statuses, and containment booleans only.
Progress 2026-06-27 Core Hub reset:
- `CUST-WP-0052` completed the Phase 3 reset. `CUST-WP-0025-T13` through