Prove tenant-engine live accept and close AUDIT-WP-0010
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

A labeled Job in tenant-engine posted 202 then duplicate 200.
Chain intact (60 events). AUDIT-IN-0002 promoted. Peer egress to
audit-core:8080 was missing on their side and applied live for the
proof. No token values recorded.

Assistant: grok
Assistant-Session: 01a0a182-bab7-7f11-b32b-d06f3af52082
This commit is contained in:
tegwick 2026-09-15 22:21:22 +02:00
parent d68823ff06
commit a1f625a644
3 changed files with 269 additions and 6 deletions

View file

@ -4,7 +4,7 @@ type: workplan
title: "Admit tenant-engine as an attributive sender"
domain: infotech
repo: audit-core
status: active
status: finished
flavor: implementation
owner: claude
topic_slug: railiance
@ -165,14 +165,19 @@ so the §9.6 trade is documented here and not only in the emitter.
```task
id: AUDIT-WP-0010-T05
status: wait
status: done
priority: medium
state_hub_task_id: "777bb728-4a4d-5c5b-8b62-24fdb6ab31e3"
```
**Waiting**, re-statused 2026-09-10. Blocked on the T04 envelope correction in
tenant-engine, then on the T02 token. There is nothing to prove end to end
until an event can be accepted at all; running this now would only reproduce
the dead-letter path already covered by test.
Done 2026-09-15. Live Job in namespace `tenant-engine` (label
`app.kubernetes.io/name=tenant-engine`) posted `source=tenant-engine` for
`tenant:audit-core:t05-proof`: first **202**, duplicate **200**. Chain intact
at 60 events; head is the proof event. Applied peer egress
`tenant-engine-audit-core-egress` (their policy had no audit-core:8080).
`AUDIT-IN-0002` closed `promoted` to this workplan; replied to tenant-engine.
Ongoing drain still needs their manifest egress plus
`TENANT_ENGINE_AUDIT_CORE_TOKEN_FILE` / URL on the Deployment. Receipt:
`docs/evidence/2026-09-15-tenant-engine-accept.json`. No token values.
Prove it end to end against the production receiver: a real event from
`tenant-engine` accepted, attributed to the right tenant, redacted per policy,
and linked into the chain. Record the evidence under `docs/evidence/`. Then