basquetWi + New ticket
pluto PLUTO-168

Cleanup: Pluto operator/alert recipients hardcode elazarpimentel@gmail.com (poll-security-alerts RECIPIENT, error-digest ELAZAR_RECIPIENT) -> move to env-driven work email pensanta.com per bs-mqn8ogqjpze #5

Done low unassigned

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • wi-cli-venus created · 2026-06-21
  • wi-cli-venus commented · 2026-06-21
    CONCRETE per fleet send-as LOCK (Elazar, pm-llmmsgsrv mqn9t3bm0pgd): Pluto LEG-1 email FROM=alerts@pensanta.com (Elazar-verified send-as in elazar.pimentel@pensanta.com, fleet-shared sender), TO=elazar.pimentel@pensanta.com (work, NOT gmail). Per-app branding in SUBJECT line. Supersedes the prior soporte-evolutiva-pluto@ FROM + gmail TO. Assess env-only (ALERT_FROM/OPERATOR_EMAIL Vercel vars) vs code. Confirm Pluto SMTP creds can send-as alerts@pensanta.com. Dispatch AFTER 1eeb893 PTD/FINISHED to avoid colliding with in-flight push.
  • wi-cli-venus commented · 2026-06-21
    REVERT FROM-lock per Elazar DIRECT correction (mqna74eh9au0, 2026-06-21): apps KEEP their own per-app FROM; alerts@ is ONLY for non-app-specific/infra mail. So Pluto's error-alert FROM STAYS soporte-evolutiva-pluto@pensanta.com (already verified + live, PLUTO-131) — the FROM→alerts@ migration is CANCELED, zero code change. This WI reduces to: TO recipient cleanup ONLY (ensure leg-1/operator-alert recipient = elazar.pimentel@pensanta.com work, not gmail) IF Pluto still points at gmail; verify + fix only if needed. Supersedes my 04:13 concretization (which wrongly locked FROM=alerts@ from the fleet announce mqn9t3bm0pgd, since reverted fleet-wide).
  • wi-cli-venus commented · 2026-06-21
    Email-recipient sweep (Elazar gmail->pensanta directive) outcome: code-side default clean (soporte-evolutiva-pluto@). OPERATOR_EMAIL Vercel prod env = type=SENSITIVE -> reads back '' (unverifiable). Routed to db-pluto: confirm TO-vs-FROM semantics + SET elazar.pimentel@pensanta.com as type=ENCRYPTED (future-verifiable via single-env GET). Applies next deploy (coder's recipient --patch triggers it). 168 recipient arm closes on db-pluto verify-reply. Separately: 2 live code recipient mis-routes (poll-security-alerts, error-digest gmail->pensanta) authorized as a dedicated --patch (not waiting on dormant 169).
  • wi-cli-venus commented · 2026-06-21
    ENV ARM DONE (db-pluto): OPERATOR_EMAIL is TO-only (sendOperatorAlert email.ts L549/L722 + email-outbox.ts L38; never FROM; fallback soporte-evolutiva-pluto@). Deleted old type=sensitive (unreadable id g46kRTkzIrgysSE5), recreated type=ENCRYPTED (id tZWdxHdADVlPkd34, production), verified via single-env decrypt GET = elazar.pimentel@pensanta.com. Code-recipient arm = coder 187904d/v1.74.2 (poll-security-alerts RECIPIENT + error-digest ELAZAR_RECIPIENT gmail->pensanta), PTD pending audit PASS:187904d. 168 closes on PASS:187904d + live-version verify.
  • wi-cli-venus completed · 2026-06-21
    Operator-alert recipient fix DONE. v1.74.2/187904d (audit PASS:187904d + live-version 1.74.2 verified). Code: poll-security-alerts RECIPIENT + error-digest ELAZAR_RECIPIENT gmail->elazar.pimentel@pensanta.com. Env: OPERATOR_EMAIL (TO-only, sendOperatorAlert + email-outbox) re-set to elazar.pimentel@pensanta.com, type sensitive->encrypted (future-verifiable via decrypt GET). FROM untouched (soporte-evolutiva-pluto@). Migrations 012/033 gmail = login identity, correctly left. whey backup-notify + pluto-db.md doc line -> bin-whey-cc. Delivery confirms out-of-band on next genuine fire (mechanically-sound swap).
task
2026-06-21 by wi-cli-venus
6w ago
2026-06-21 04:45