docs(questions): C4 credentials + C5 scope + C6 docker rulings recorded [#767]

Answers landed 2026-09-03: Bitwarden/Vault = cred SoR (.creds bootstrap-only);
this chat = COO/C2-only (PM/policy/enablement), agent stack lives here;
docker(988) verified on all 7 TSG*/COS* officer accounts.
This commit is contained in:
2026-09-03 17:27:54 -05:00
parent 994959d4ad
commit 041d311d1c
+17
View File
@@ -101,15 +101,32 @@ agent/system creds), ~/.creds 0600 (current house rules), Vaultwarden (your app-
ruling). Proposed: Bitwarden = agent + system API credentials going forward (~/.creds ruling). Proposed: Bitwarden = agent + system API credentials going forward (~/.creds
deprecated as #478 ingests them), Vaultwarden stays for app-internal secrets. Confirm? deprecated as #478 ingests them), Vaultwarden stays for app-internal secrets. Confirm?
> **ANSWERED 2026-09-03 (Charles):** Bitwarden/Vault is the SoR — "its the latter."
> ~/.creds is a bootstrap mechanism for convenience only (same as using the
> reachableceo linux/cloudron account as a bootstrap identity). Going forward: new
> agent/system credentials land in Bitwarden; ~/.creds materializes bootstrap copies.
### C5. #767 scope split ### C5. #767 scope split
This chat owns the CR escalation ladder + GLPI Changes wiring + mechanical gates This chat owns the CR escalation ladder + GLPI Changes wiring + mechanical gates
(ticket-gate CR check, X-Consumer attribution); TSGCOO's lane owns identity provisioning (ticket-gate CR check, X-Consumer attribution); TSGCOO's lane owns identity provisioning
execution (#442/#478). Confirm the seam? execution (#442/#478). Confirm the seam?
> **ANSWERED 2026-09-03 (Charles):** No split — **this chat is COO/C2 only going
> forward** (project management, policy making, enablement). The agent stack IS
> enablement → it lives HERE, end-to-end (design + provisioning execution). Dedicated
> chats get spun up for any work that isn't PM/policy/enablement. TSGCOO's existing
> tree is prior art feeding this chat, not a separate lane.
### C6. Resume TSGCOO's blockers? ### C6. Resume TSGCOO's blockers?
Q1-Q6 in org-buildout/questions-v1.md + #478 stage-2 re-gate. I can clear Q1 (docker Q1-Q6 in org-buildout/questions-v1.md + #478 stage-2 re-gate. I can clear Q1 (docker
group for TSGCOO) now — say the word. Invite links (Q3) + Gitea token (Q4) are yours. group for TSGCOO) now — say the word. Invite links (Q3) + Gitea token (Q4) are yours.
> **ANSWERED 2026-09-03 (Charles):** "yes give all of the TSG* and COS* accounts docker
> group access. that is super critical for all them to work." → VERIFIED ALREADY IN
> PLACE: docker(988) confirmed on all 7 officer accounts (TSGCOO, TSGCCO, TSGCTO,
> TSGBOD, COS-RCEO, COS-WFO, COS-TSG). Org-buildout Q1 closed. Q3 (Cloudron invite
> links ×9) + Q4 (Gitea push token) remain Charles's.
### C7. Leaked vptechops Gitea token ### C7. Leaked vptechops Gitea token
Listed in a KNELSecretsManager remote URL — rotate at your convenience (your console, Listed in a KNELSecretsManager remote URL — rotate at your convenience (your console,
not my lane). not my lane).