audit-core/docs/evidence/AUDIT-WP-0008-T05-whitehat-e2-02-abort-2026-08-22.md
tegwick c221921142
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Record Whitehat E2 admission abort
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02991-be07-7bb3-8b6d-e9701b5621de
2026-08-22 21:26:38 +02:00

3.5 KiB
Raw Blame History

WH-ENG-20260822-AUDIT-E2-02 admission abort

Date: 2026-08-22
Workplan task: AUDIT-WP-0008-T05
Outcome: aborted before probe execution; zero target packets

Scope

The attended window was 19:15Z19:30Z. Custody projection was permitted only from 19:15Z through 19:18Z. The approved target image was sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6. The run used engagement-specific -02 identities, tenants, fixture IDs, KV paths, and projection resources. No credential value was printed or retained in this evidence.

Timeline and value-safe observations

  • Before the window, repeated preflight observed audit-core 1/1 Ready on the approved image, OpenBao initialized and unsealed, and no temporary identity, exact KV path, projection resource, mounted Secret, or runner pod.
  • At 19:15:32Z, preflight reported projection-window-open with the same clean baseline.
  • The first projection attempt stopped at its projected-key-name verification. SSH had allowed the remote shell to expand the Go-template $k variables. The procedure's automatic exact cleanup completed. At 19:16:49Z, independent preflight again found no temporary identity, KV path, projection resource, or runner; audit-core was 1/1 Ready.
  • The value-safe key-name check was shell-quoted and projection was retried inside the gate. Projection succeeded at 19:17:54Z with exactly two temporary identities, mounted keys token-a and token-b, expiry 19:30Z, and audit-core Ready. The ExternalSecret reached Ready and the named mounted Secret and ClusterSecretStore existed.
  • The approved pod contract was applied at 19:19Z and whitehat/whitehat-e2-audit became Ready.
  • Whitehat target validation passed, the engagement was authorized, and the kill switch was clear. admit-plane then failed closed with live custody broker is not connected; no credential was requested. The custody procedure had produced a valid value-safe projection receipt, but Whitehat has no adapter that consumes that receipt and issues a plane lease. The runner was not invoked and sent zero packets.
  • The runner pod was deleted at 19:21:07Z. Custody cleanup completed at 19:21:39Z: two temporary identities removed, both exact engagement KV paths deleted, mounted Secret absent, audit-core Ready, and no secret value observed.
  • The independent post-cleanup preflight found empty temporary-identity, exact-path, and projection-resource lists, projection-cutoff-passed, OpenBao unsealed, and audit-core 1/1 Ready. The runner pod was absent.

Result and follow-up

This is not E2 evidence and does not complete T05. The run proves the attended custody projection, expiry, runner creation, abort, and exact cleanup path. It also proves that manually coordinating those roles is insufficient: the live test-plane admission control cannot authenticate the custody projection.

Before another engagement is scheduled, implement and test a value-safe custody receipt contract and Whitehat broker adapter. The adapter must bind the receipt to the exact engagement, two projected handles, target revision, projection and expiry times, mounted Secret identity, and current cleanup authority without returning bearer values. A single driver must then sequence projection-ready, plane admission, runner invocation, report delivery, runner deletion, and custody cleanup while preserving the independent role approvals.

The SSH argument-quoting defect is fixed and pushed in railiance-platform commit d239ed3; its regression test and all 115 platform tests pass.