docs(questions): C4-C8 agent-stack + credentials-policy rulings [#767]

Detail: https://projects.knownelement.com/issues/767
This commit is contained in:
2026-09-03 17:13:29 -05:00
parent a2a45ea9d8
commit 994959d4ad
+24
View File
@@ -92,3 +92,27 @@ to-glpi.sh is idempotent by name. Recommend folding "refresh #307 →
regenerate → import → report diff" into the daily 09:00 C2 housekeeping.
Related data-quality: #307 §5 has `pfvsvrki.knel.net` typo; 14
stale-dns-record CIs need reconcile-or-delete ruling.
## Agent-stack rulings needed (#767 — after TSGCOO tree discovery 2026-09-03)
### C4. Credentials policy — one statement, please
Three coexisting models: Bitwarden (TSGCOO's bw-run.sh design — replaces ~/.creds for
agent/system creds), ~/.creds 0600 (current house rules), Vaultwarden (your app-secrets
ruling). Proposed: Bitwarden = agent + system API credentials going forward (~/.creds
deprecated as #478 ingests them), Vaultwarden stays for app-internal secrets. Confirm?
### C5. #767 scope split
This chat owns the CR escalation ladder + GLPI Changes wiring + mechanical gates
(ticket-gate CR check, X-Consumer attribution); TSGCOO's lane owns identity provisioning
execution (#442/#478). Confirm the seam?
### C6. Resume TSGCOO's blockers?
Q1-Q6 in org-buildout/questions-v1.md + #478 stage-2 re-gate. I can clear Q1 (docker
group for TSGCOO) now — say the word. Invite links (Q3) + Gitea token (Q4) are yours.
### C7. Leaked vptechops Gitea token
Listed in a KNELSecretsManager remote URL — rotate at your convenience (your console,
not my lane).
### C8. GLPI Changes vs Tickets (was C1)
Still the blocking ruling for the whole CR wiring — see C1 above (recommend Changes).