session: June 20 session 2 — sandbox Vault mirror + auto-unseal deployed

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Backtalk6858
2026-06-20 15:16:06 -05:00
parent 4c47123270
commit 6a90c3bae5
+11 -3
View File
@@ -97,15 +97,23 @@ All 8 prereq checklist items verified live on server-01:
- claude-policy extended: AppRole management + sys/generate-root paths added - claude-policy extended: AppRole management + sys/generate-root paths added
### id=57 — REMAINING (next session): ### id=57 — REMAINING (next session):
- Sandbox Vault AppRole policy mirroring (audit production roles/policies → recreate in vault-sandbox) - Sandbox Vaultwarden population — bw CLI approach FAILED (version mismatch); use Vaultwarden REST API directly (id=70 tracks implementation); 53 infra items, dummy values, no production data
- Production Bitwarden audit (enumerate infra items, map field structure)
- Sandbox Bitwarden Bridge population (test credentials, dummy values, NO production data)
- N8N sandbox credentials (-sandbox suffix names) - N8N sandbox credentials (-sandbox suffix names)
- Sudo bridge deploy on server-01 (Phase 2) — then disable NOPASSWD:ALL in /etc/sudoers.d/administrator on server-01
### id=51 — NOT STARTED. Scope locked: ### id=51 — NOT STARTED. Scope locked:
- Option B zero-exposure proxy: agent sends "run X using secret Y", proxy executes + injects secret, returns result only - Option B zero-exposure proxy: agent sends "run X using secret Y", proxy executes + injects secret, returns result only
- Must be live before builder agents deploy - Must be live before builder agents deploy
## June 20 Session 2 (continuation)
- Sandbox Vault auto-unseal deployed: vault-sandbox-unseal.sh + vault-sandbox-watch-unseal.sh + 2 systemd services, unsealed and verified
- Sandbox Vault AppRole mirror: 9 policies + 5 roles recreated from production (claude-code, claude-policy, n8n, n8n-outreach-policy, n8n-policy, n8n-rotation-policy, n8n-scheduling-policy, n8n-server01-policy, nextcloud-init)
- Production Bitwarden audit: 294 items total, 53 infra items identified (all username/password, some with notes)
- Sandbox Vaultwarden population BLOCKED: bw CLI 2026.5.0 WASM crypto error on create — use Vaultwarden REST API next session (id=70)
- sudo bridge NOT on server-01: server-01 has NOPASSWD:ALL; plan = deploy bridge first (Phase 2), then disable NOPASSWD
- ids added: 69 (Vaultwarden Version Monitor, p16), 70 (Sandbox Vaultwarden Seeder, p17)
- feedback_bw_cli_vaultwarden_create.md added to docker MEMORY.md
## June 22 (Monday) — Builder Agents (extended session) ## June 22 (Monday) — Builder Agents (extended session)
Build, test, and push both builder agents to production. Work as long as it takes. Build, test, and push both builder agents to production. Work as long as it takes.
- id=24 Agent Builder Agent (claude_agent + script types) - id=24 Agent Builder Agent (claude_agent + script types)