Record native receiver rollout and live attestation follow-up

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-11 07:26:16 +02:00
parent 0e421fd52f
commit 8b3bceea7f
4 changed files with 206 additions and 2 deletions

View file

@ -76,3 +76,4 @@
| intake | AUDIT-IN-0001 | closed | — | intakes/intakes.md |
| intake | AUDIT-IN-0002 | open | — | intakes/intakes.md |
| intake | AUDIT-IN-0003 | closed | — | intakes/intakes.md |
| intake | AUDIT-IN-0004 | open | — | intakes/intakes.md |

View file

@ -0,0 +1,172 @@
{
"schema": "hfact.factory-audit-receiver-live.v1",
"observed_at": "2026-09-11",
"release": {
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c82e0442de0fd181342916ae9cd5d6de41d859e1efda637bd93936c67873afa5",
"source_commit": "cb23dc82fd5dbadfdfb84e99581068bd0aa667c0"
},
"native_contract": {
"schema": "platform.factory-audit-custody.v1",
"status": "receiver_contract_supported",
"credential_values_emitted": false,
"started_at": "2026-09-11T04:50:27.072575+00:00",
"lanes": [
{
"ccr": "CCR-2026-0021",
"name": "approval-engine",
"kv": "platform/data/workloads/approval-engine/audit-sender",
"store": "openbao-approval-engine-audit",
"secret": "approval-engine-audit",
"secret_key": "audit-token",
"source_sha256": "ba69ecc8227c5bf887c2cd0ac4c50518c019bebfdfb6d49628edee1ce570da7d"
},
{
"ccr": "CCR-2026-0022",
"name": "informed-decision",
"kv": "platform/data/workloads/informed-decision/audit-sender",
"store": "openbao-informed-decision-audit",
"secret": "informed-decision-audit",
"secret_key": "token",
"source_sha256": "2f7f7f214d1e21fd79275197edd03ee7e154ef451d62a182017926250515a6aa"
}
],
"receiver": {
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c82e0442de0fd181342916ae9cd5d6de41d859e1efda637bd93936c67873afa5",
"deployment_uid": "b85fe3d0-75c9-4e0d-8c34-c6f1df0881bb",
"deployment_resource_version": "59740687",
"pod_uid": "6642c414-a942-4b11-b048-267423e12da8",
"capabilities": {
"load_bearing": true,
"redact": true,
"write_only": true,
"source_exact": true,
"tenant_exact": true
},
"synthetic_probe_only": true,
"credential_reads": 0
}
},
"native_before": {
"ready": {
"status": "ok",
"custody_class": "operational",
"durable": true,
"tamper_evidence": true,
"recoverable_days": 30,
"recoverable_source": "resource-control/data/capability/platform-audit-storage.json#provisions[capability=data.backup]",
"recoverable_basis": "measured"
},
"chain": {
"intact": true,
"events": 32,
"head": "9fc0b4f25c562cec037a5077f00ee63380db8b5c4e85b6016fc40b301431e4fd",
"head_event_id": "whitehat-e2-event-b-20260822-03",
"head_accepted_at": "2026-08-22T22:09:37+00:00",
"first_break": null,
"attestation_match": null
},
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6",
"generation": 15,
"deployment_uid": "b85fe3d0-75c9-4e0d-8c34-c6f1df0881bb"
},
"native_after": {
"ready": {
"status": "ok",
"custody_class": "operational",
"durable": true,
"tamper_evidence": false,
"recoverable_days": 30,
"recoverable_source": "resource-control/data/capability/platform-audit-storage.json#provisions[capability=data.backup]",
"recoverable_basis": "measured"
},
"chain": {
"intact": true,
"events": 32,
"head": "9fc0b4f25c562cec037a5077f00ee63380db8b5c4e85b6016fc40b301431e4fd",
"head_event_id": "whitehat-e2-event-b-20260822-03",
"head_accepted_at": "2026-08-22T22:09:37+00:00",
"first_break": null,
"attestation_match": null
}
},
"release_container": {
"image": "forgejo.coulomb.social/coulomb/audit-core:cb23dc82fd5dbadfdfb84e99581068bd0aa667c0",
"native_credentials_used": false,
"checks": {
"operational_ready": true,
"nonroot_readonly": true,
"approval-engine": {
"accepted": 202,
"duplicate": 200,
"wrong_source": 400,
"wrong_tenant": 400,
"read_routes_denied": 7,
"independent_read": 200,
"redacted": true,
"stored_once": true
},
"informed-decision": {
"accepted": 202,
"duplicate": 200,
"wrong_source": 400,
"wrong_tenant": 400,
"read_routes_denied": 7,
"independent_read": 200,
"redacted": true,
"stored_once": true
},
"sigterm": {
"exit_code": 0,
"inflight_committed_once": true,
"restart_retry_duplicate": true,
"chain_intact": true
}
},
"started_at": "2026-09-11T04:47:21.436615+00:00",
"status": "passed",
"own_fixture_cleanup": true
},
"approvals": [
{
"ccr": "CCR-2026-0021",
"decision_id": "2c9fe9f0-034a-41d7-9d49-b99df488fdc8",
"status": "resolved",
"decided_by": "user (platform-operator, audit-core-owner, approval-engine-owner)",
"decided_at": "2026-09-11T04:36:46.312720Z"
},
{
"ccr": "CCR-2026-0022",
"decision_id": "ee4ff001-256a-4406-9cb8-51be2cd5d31b",
"status": "resolved",
"decided_by": "user (platform-operator, audit-core-owner, informed-decision-owner)",
"decided_at": "2026-09-11T04:36:46.480026Z"
}
],
"approval_engine_namespace": "created from owner manifest; no workload deployed",
"sender_ingress": "two exact source-declared namespace AND workload-label peers applied",
"sender_custody": {
"status": "attended_login_failed_before_command_handoff",
"credential_command_started": false,
"custody_receipt_exists": false,
"remote_session_revocation": "not_confirmed_by_warden",
"operator_browser_feedback": "requested"
},
"receiver_tests": {
"passed": 229,
"migration_exclusion": "AUDIT-IN-0004: five existing PostgreSQL failures in historical SQLite importer"
},
"platform_tests": {
"passed": 18
},
"schema_migration_executed": false,
"attestation_residual": "AUDIT-WP-0009-T12",
"factory_attempts": 0,
"paid_model_calls": 0,
"release_scan": {
"vulnerabilities": 0,
"sha256": "f2e6be3514040766bd29a4f8a5265989e8fab6802c935b86bad19aa3ae6c4824",
"scanner": "aquasec/trivy@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969",
"warning": "Alpine 3.24 not in scanner OS lifecycle list"
},
"receiver_selector": "app.kubernetes.io/name=audit-core,app.kubernetes.io/component=receiver"
}

View file

@ -204,4 +204,5 @@ description: >
an intact chain. Also evaluate repeated dead-letter/finding import counting.
Run the full PostgreSQL suite with no migration exclusions for closure.
No native import is authorized or attempted by this release.
state_hub_intake_id: "01a08ecc-c6f6-7162-a154-0ab51a2ff61d"
```

View file

@ -497,5 +497,35 @@ write and returns duplicate on restart/retry. Both synthetic senders pass exact
scope, redaction, independent readback and seven read-route denials.
[Rehearsal evidence](../docs/evidence/2026-09-11-factory-receiver-release.json).
Publish and native rollout are the next steps; T09/T11 remain progress until
real sender custody, delivery and owner acceptance are evidenced.
The receiver is now published and live at c82e0442de0f, source cb23dc82. Its
synthetic native contract probe passes, the 32-event chain/head is unchanged,
and no schema migration ran. Current scope and exact producer ingress are
applied; Approval Engine's owner namespace now exists.
The approved custody operation stopped at attended OIDC, before the owner
procedure ran; remote session revocation could not be confirmed by Warden.
No sender custody receipt exists. T09/T11 remain progress for the attended
retry, delivery and owner acceptance.
[Native release receipt](../docs/evidence/2026-09-11-factory-receiver-live.json).
## Operate the scheduled attestation and independent offsite return
```task
id: AUDIT-WP-0009-T12
status: todo
priority: high
```
Residual from the source-complete T02: the 2026-09-11 receiver rollout found
no native attest CronJob or audit-core-chain-head ConfigMap. The new receiver
correctly reports tamper_evidence=false while its 32-event chain is intact.
Apply the reviewed separate attestor identity, exact-ConfigMap RBAC, component
egress and scheduled job; bootstrap an empty ConfigMap only if absent, never
overwrite a live attestation with the manifest placeholder. Prove one successful
run, fresh mounted readback and receiver denial of ConfigMap writes.
Coordinate the existing RESOURCE-WP-0002-T06 logical-offsite custody path for
a copy independent of the cluster and Barman data. Record the operating owner,
cadence and failure handling there; no Nextcloud credential belongs in the
receiver. Until that return exists, describe an in-cluster attestation as a
database-owner boundary only. Do not relabel the source-complete T02 as undone.