Distills patterns from the Teleport access topology work: verified-data diagram
building, as-displayed HTML-to-PDF export via headless Chromium, and
container-scoped/host/database onboarding into an existing Teleport cluster.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01R3ZTfgQrkR3q8DSEoZAmvs
SessionStart hook that provisions a short-lived, policy-scoped OpenBao token
for each agent session. For Claude Code it writes export lines into
$CLAUDE_ENV_FILE; for hosts that cannot persist env from hooks (Codex) it
writes a mode-600 session env file and points the agent to it via context.
Failure degrades to a benign JSON so sessions still start. Registered in both
Claude and Codex marketplace manifests.
Co-Authored-By: Claude <noreply@anthropic.com>