Record native receiver rollout and live attestation follow-up
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
0e421fd52f
commit
8b3bceea7f
4 changed files with 206 additions and 2 deletions
|
|
@ -497,5 +497,35 @@ write and returns duplicate on restart/retry. Both synthetic senders pass exact
|
|||
scope, redaction, independent readback and seven read-route denials.
|
||||
|
||||
[Rehearsal evidence](../docs/evidence/2026-09-11-factory-receiver-release.json).
|
||||
Publish and native rollout are the next steps; T09/T11 remain progress until
|
||||
real sender custody, delivery and owner acceptance are evidenced.
|
||||
The receiver is now published and live at c82e0442de0f, source cb23dc82. Its
|
||||
synthetic native contract probe passes, the 32-event chain/head is unchanged,
|
||||
and no schema migration ran. Current scope and exact producer ingress are
|
||||
applied; Approval Engine's owner namespace now exists.
|
||||
|
||||
The approved custody operation stopped at attended OIDC, before the owner
|
||||
procedure ran; remote session revocation could not be confirmed by Warden.
|
||||
No sender custody receipt exists. T09/T11 remain progress for the attended
|
||||
retry, delivery and owner acceptance.
|
||||
[Native release receipt](../docs/evidence/2026-09-11-factory-receiver-live.json).
|
||||
|
||||
## Operate the scheduled attestation and independent offsite return
|
||||
|
||||
```task
|
||||
id: AUDIT-WP-0009-T12
|
||||
status: todo
|
||||
priority: high
|
||||
```
|
||||
|
||||
Residual from the source-complete T02: the 2026-09-11 receiver rollout found
|
||||
no native attest CronJob or audit-core-chain-head ConfigMap. The new receiver
|
||||
correctly reports tamper_evidence=false while its 32-event chain is intact.
|
||||
Apply the reviewed separate attestor identity, exact-ConfigMap RBAC, component
|
||||
egress and scheduled job; bootstrap an empty ConfigMap only if absent, never
|
||||
overwrite a live attestation with the manifest placeholder. Prove one successful
|
||||
run, fresh mounted readback and receiver denial of ConfigMap writes.
|
||||
|
||||
Coordinate the existing RESOURCE-WP-0002-T06 logical-offsite custody path for
|
||||
a copy independent of the cluster and Barman data. Record the operating owner,
|
||||
cadence and failure handling there; no Nextcloud credential belongs in the
|
||||
receiver. Until that return exists, describe an in-cluster attestation as a
|
||||
database-owner boundary only. Do not relabel the source-complete T02 as undone.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue