fix(workplans): adopt ADR-007 derived identifiers for unregistered records
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

These workplans exist only in the retired local hub. Their random pre-ADR-007
identifiers are refused by C-06 as stale references, so they cannot be
registered. Deriving from the canonical record id takes no identity from
anything: central does not hold them and the old ids die with the cache.

Records central already holds were deliberately left untouched.

Refs CUST-WP-0068-T06

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
This commit is contained in:
codex 2026-08-25 20:10:35 +02:00
parent 75c587d932
commit 1d90aac30f
9 changed files with 43 additions and 43 deletions

View file

@ -16,7 +16,7 @@ related_workplans:
- KEY-WP-0005
created: "2026-07-23"
updated: "2026-07-23"
state_hub_workstream_id: "6341d238-fffc-4428-9265-0b6db5714e9b"
state_hub_workstream_id: "1358db95-967c-5a03-8b8c-4816dc106594"
---
# FLEX-WP-0008: tenant-engine Consumer Integration
@ -52,7 +52,7 @@ and action vocabulary is small and doesn't need CARING descriptor mapping.
id: FLEX-WP-0008-T01
status: done
priority: high
state_hub_task_id: "d78361e6-eb8e-4623-bed2-917538c403ca"
state_hub_task_id: "5606408f-f94c-5d79-ba41-ed23fadac480"
```
Resource types: `tenant`, `role-grant`, `plan-assignment`. Actions:
@ -84,7 +84,7 @@ types match exactly, not just by convention.
id: FLEX-WP-0008-T02
status: done
priority: high
state_hub_task_id: "8a07e83b-27a2-4390-a169-51065bcf3bd6"
state_hub_task_id: "bbe1a8f4-dcd9-58bb-8d82-386ee0c11a51"
```
Policy: writes require an `aal2`+ assurance actor holding an appropriate
@ -140,7 +140,7 @@ HTTP, real Rego evaluation. `go test ./...` still green across the whole
id: FLEX-WP-0008-T03
status: done
priority: medium
state_hub_task_id: "20c005a4-48b7-4ac4-a345-aeaa0de06d80"
state_hub_task_id: "e27d24b3-0aef-5bd4-b7e3-81532cd7aa9c"
```
A context-enrichment adapter (mirrors `internal/adapters/{relationship,rule,topaz}`'s
@ -201,7 +201,7 @@ this task exists to guarantee, proven end-to-end across Go → Python → Go
id: FLEX-WP-0008-T04
status: done
priority: low
state_hub_task_id: "0c59ada6-c61b-41a3-8baa-a98e936c5690"
state_hub_task_id: "0f319a2f-e4bb-5ba8-92de-b693ae9a2aa3"
```
Confirm T01T03 done; run flex-auth's existing test suite plus the new

View file

@ -11,7 +11,7 @@ created: "2026-08-08"
updated: "2026-08-16"
depends_on:
- NK-WP-0024
state_hub_workstream_id: "45756b89-feba-45f5-a24a-63a1119254bf"
state_hub_workstream_id: "390da58d-3c58-5102-bd3c-7133956c810e"
---
# FLEX-WP-0009 - user-engine production authorization
@ -26,7 +26,7 @@ net-kingdom/docs/user-engine-platform-expansion-contract.md.
id: FLEX-WP-0009-T01
status: done
priority: high
state_hub_task_id: "e940c5a3-ecb4-43d3-9554-2bfb422ec56d"
state_hub_task_id: "4607222e-3407-59c4-b388-aa7c88f7e3ef"
```
Add a user-engine protected-system manifest, resource manifests, subject
@ -48,7 +48,7 @@ self-service, cross-tenant, missing-role, and wrong-system cases.
id: FLEX-WP-0009-T02
status: done
priority: high
state_hub_task_id: "6e0fe708-d7ff-411f-a64d-84a1692a6e11"
state_hub_task_id: "7ae9de35-4f71-54d8-aabb-858c1202c833"
```
Implement policy-as-code for self-only mutations, tenant-admin authority
@ -68,7 +68,7 @@ the package validates under CARING 0.4.0-rc2 and the registry loads cleanly.
id: FLEX-WP-0009-T03
status: done
priority: high
state_hub_task_id: "f8293230-136d-4f2d-8d3f-bb9840ea7e63"
state_hub_task_id: "9a1ea146-0735-5d6f-bd75-96eb78e9bd2b"
```
Publish an immutable flex-auth image and deploy a namespaced Service at
@ -89,7 +89,7 @@ behind ingress restricted to the user-engine workload and with no egress.
id: FLEX-WP-0009-T04
status: done
priority: high
state_hub_task_id: "97b931e9-ac5b-46c7-a462-e23c0c18c4f4"
state_hub_task_id: "9639adbe-4392-5f6c-a924-3771f71ab94c"
```
Run live allow, deny, service-unavailable, and cross-tenant probes from the

View file

@ -16,7 +16,7 @@ related_workplans:
- USER-WP-0021
created: "2026-08-10"
updated: "2026-08-10"
state_hub_workstream_id: "c159fe8b-d35b-4a74-8a15-c1263f7f6392"
state_hub_workstream_id: "fdabae84-dc9e-5ccd-81df-8ae7e66b90b8"
---
# FLEX-WP-0010 - Authorize tenant-engine lifecycle actions
@ -71,7 +71,7 @@ yet, and here is why".
id: FLEX-WP-0010-T01
status: done
priority: high
state_hub_task_id: "e92e45b9-724a-4fbd-8302-75558cf4b6c1"
state_hub_task_id: "8deb9564-658e-5eff-8ef7-94838bee05cc"
```
Add `tenant.update`, `tenant.retire`, and `tenant.reactivate` to
@ -112,7 +112,7 @@ retire a tenant, not what a *retired tenant* may do.
id: FLEX-WP-0010-T02
status: done
priority: medium
state_hub_task_id: "5aa9e104-a4b3-40cd-b5ad-4ff56421ce69"
state_hub_task_id: "82d13a89-a344-5797-b10f-390d17b11b73"
```
`tenant.retire` is the highest-consequence action in the set: it suspends a
@ -151,7 +151,7 @@ identity, or when a second `tenant-engine` operator subject is registered.
id: FLEX-WP-0010-T03
status: done
priority: high
state_hub_task_id: "59856c87-a1b4-4fce-b554-9b13181bb8fd"
state_hub_task_id: "2fbceaf5-514b-5ded-adb1-f4e63ce96160"
```
Add `allow`/`deny` fixture pairs to
@ -207,7 +207,7 @@ clean. Evidence table mirrored into `examples/tenant-engine/README.md`.
id: FLEX-WP-0010-T04
status: done
priority: low
state_hub_task_id: "04141e54-a250-424e-8dfd-4148875e67da"
state_hub_task_id: "eb2579cb-b54f-5834-abcc-81954ac34889"
```
Confirm T01T03. Run `statehub fix-consistency`. Notify `tenant-engine` that

View file

@ -15,7 +15,7 @@ related_workplans:
- RAIL-BS-WP-0006
created: "2026-08-11"
updated: "2026-08-16"
state_hub_workstream_id: "b17c3296-f8ae-4f61-bcf7-41ac80bacd47"
state_hub_workstream_id: "deda35b4-f41d-559e-954e-a75f29237f68"
---
# FLEX-WP-0011 - Bring flex-auth under the railiance staged-promotion contract
@ -63,7 +63,7 @@ policy rollouts.
id: FLEX-WP-0011-T01
status: done
priority: medium
state_hub_task_id: "edc7fee5-b78d-4a5c-a773-42c5b39d0019"
state_hub_task_id: "75748946-68c0-5f33-abe1-810fcd55e93f"
```
Write `railiance/app.toml` against schema `railiance.app.v1`, using
@ -110,7 +110,7 @@ re-promote that image.
id: FLEX-WP-0011-T02
status: done
priority: medium
state_hub_task_id: "5283bc1f-88c3-431b-a9ea-4a900a3e5885"
state_hub_task_id: "4becc09f-2331-5487-a794-643c748dd1bd"
```
Prove `stage deploy`, `stage observe`, `stage promote`, and `stage rollback`
@ -147,7 +147,7 @@ Candidate image: `sha256:1f5290376dc5fcf456dc7a785e394d8b90949dabecd1d3e856f3855
id: FLEX-WP-0011-T03
status: done
priority: low
state_hub_task_id: "bebd6ed9-9145-4fc0-bdc8-cac669643c62"
state_hub_task_id: "abb788fe-22a5-5226-9f08-a43e20a47ce9"
```
`the-custodian/docs/coulombcore-drain-placement-plan.md` row 23 lists

View file

@ -13,7 +13,7 @@ related_workplans:
- RAILIANCE-WP-0005
created: "2026-08-11"
updated: "2026-08-23"
state_hub_workstream_id: "89ecdb1f-ceb0-4a50-b72d-c3dfd5fa7c73"
state_hub_workstream_id: "2a6b5764-1831-5305-b46e-0991d02675df"
---
# FLEX-WP-0012 - Authorize railiance-platform credential-grant requests
@ -86,7 +86,7 @@ What is *actually* missing is narrower and worth stating precisely:
id: FLEX-WP-0012-T01
status: done
priority: medium
state_hub_task_id: "a1c9ba0c-3413-4823-9f9e-ccee09cf5d74"
state_hub_task_id: "f8491771-be1a-5c70-a4aa-059e48536630"
```
Two honest options, and the choice is a charter question rather than a
@ -142,7 +142,7 @@ one generic flex-auth decision surface.
id: FLEX-WP-0012-T02
status: done
priority: medium
state_hub_task_id: "7e9c4e59-e59c-4617-a87f-99142952fe78"
state_hub_task_id: "685f3d70-7c50-5664-95ae-1e8c93b14073"
```
Add `examples/railiance-platform/` with a protected-system manifest, subject
@ -188,7 +188,7 @@ returned `credential_grant_allowed` for the registered runtime grant and
id: FLEX-WP-0012-T03
status: done
priority: medium
state_hub_task_id: "3335b2b7-cf1a-411d-95b3-03c4b4c35659"
state_hub_task_id: "045ec743-4411-5b42-b9e8-df25b0c07984"
```
Implement whichever shape T01 chose. If B, the adapter must reuse the
@ -240,7 +240,7 @@ over real HTTP, `go test ./...` is green, and `gofmt`/`go vet` are clean.
id: FLEX-WP-0012-T04
status: done
priority: low
state_hub_task_id: "40015a87-040c-4d48-b360-fd5566dbc552"
state_hub_task_id: "0dcf2e1f-baa2-5fea-9e3e-9a73795af11f"
```
Reply to capability request `893ff109` — it has been open since 2026-07-02

View file

@ -17,7 +17,7 @@ related_workplans:
- TEN-WP-0006
created: "2026-08-16"
updated: "2026-08-16"
state_hub_workstream_id: "41df7845-a144-420d-9852-adabde0949b3"
state_hub_workstream_id: "6f22ded6-a69c-531b-bfa6-2f8d5c886979"
---
# FLEX-WP-0013 - Restore the seven-action tenant-engine policy pin
@ -70,7 +70,7 @@ Do not move `flex-auth-user-engine`.
id: FLEX-WP-0013-T01
status: done
priority: high
state_hub_task_id: "22db4198-b9c3-4ebf-975a-5c44c6a75928"
state_hub_task_id: "f84b0f20-f374-5d61-aa43-d1f886ea86c3"
```
Set the tenant-engine digest to `9320df39` in:
@ -96,7 +96,7 @@ that digest as live and `c25fc34a` as rollback.
id: FLEX-WP-0013-T02
status: done
priority: high
state_hub_task_id: "e5e76f15-369a-4573-8095-46ba05cd6b14"
state_hub_task_id: "a77ff4bb-8927-5317-a0eb-903cfeef0de5"
```
`kubectl apply -f deploy/flex-auth-tenant-engine.yaml` against railiance01,
@ -145,7 +145,7 @@ deploy/flex-auth-tenant-engine.yaml` reused ReplicaSet
id: FLEX-WP-0013-T03
status: done
priority: medium
state_hub_task_id: "df616e44-cfea-4811-a986-90ea0f72b68b"
state_hub_task_id: "832ba42f-4247-58a9-bc1b-f99648c2c188"
```
Notify `tenant-engine` that TEN-WP-0005-T05 authority is restored, naming

View file

@ -16,7 +16,7 @@ related_workplans:
- TEN-WP-0006
created: "2026-08-16"
updated: "2026-08-16"
state_hub_workstream_id: "dd6d4e09-3664-4698-8c14-8cf1efc2d142"
state_hub_workstream_id: "7de17bd2-5e7c-5355-ba1d-40a051a67746"
---
# FLEX-WP-0014 - Authorize tenant-engine guardrail actions
@ -60,7 +60,7 @@ is verified locally. Image + pin is a follow-on, named in T04.
id: FLEX-WP-0014-T01
status: done
priority: high
state_hub_task_id: "4f4e9fdb-ca21-40a9-b6af-ef0384cd230a"
state_hub_task_id: "34fb239a-7f06-5e96-9f10-a6bbb85bf4c3"
```
Add `tenant.guardrail.read` and `tenant.guardrail.set` to
@ -94,7 +94,7 @@ read-only subject. Registry snapshot rebuilt (2 subjects, 2 groups).
id: FLEX-WP-0014-T02
status: done
priority: medium
state_hub_task_id: "ec0d2d80-4052-48b1-8d31-ca8e8eac3066"
state_hub_task_id: "8ea87d5f-883a-5d63-89bb-33a3d0963472"
```
tenant-engine split the actions so a PDP can read ceilings without being
@ -120,7 +120,7 @@ subject.
id: FLEX-WP-0014-T03
status: done
priority: high
state_hub_task_id: "a744472b-59cb-45a3-b3b7-1cf734b04855"
state_hub_task_id: "1029d2ce-bb37-530e-91ef-ded86f6f5be8"
```
Add fixture pairs for: authorized `tenant-engine` read and set → allow;
@ -165,7 +165,7 @@ Live `flex-auth serve` on `127.0.0.1:9098` + real `tenant-engine` on
id: FLEX-WP-0014-T04
status: done
priority: low
state_hub_task_id: "3516be81-825b-4c83-ae61-89ac914efd7a"
state_hub_task_id: "b2b44215-ef08-5c50-b466-190156a88ef3"
```
Confirm T01T03. Notify `tenant-engine` naming the policy revision. State

View file

@ -15,7 +15,7 @@ related_workplans:
- FLEX-WP-0011
created: "2026-08-17"
updated: "2026-08-19"
state_hub_workstream_id: "31846b19-c2a3-428e-950b-5985bc9146eb"
state_hub_workstream_id: "43fe348c-02b9-5d5d-af37-a2d80cfc6e1d"
---
# FLEX-WP-0015 - Tenancy posture declaration and inbound caller authentication
@ -57,7 +57,7 @@ per FLEX-WP-0007).
id: FLEX-WP-0015-T01
status: done
priority: high
state_hub_task_id: "0a32500d-511a-4bd7-972e-de4cd3e62dd9"
state_hub_task_id: "ee587988-d29c-5dd8-9417-8af73f627817"
```
**Publish posture and answer the review.** Write `tenancy.yaml` and
@ -69,7 +69,7 @@ corrections. Done 2026-08-17.
id: FLEX-WP-0015-T02
status: done
priority: high
state_hub_task_id: "b2e87a81-b63d-4be4-ad44-01426b7e6f74"
state_hub_task_id: "7c906ab5-0b3f-5a73-8561-b29d94f4e634"
```
**Close the A0 — authenticate callers of `/v1/check`.** Decide first, build
@ -192,7 +192,7 @@ said so was corrected to them.
id: FLEX-WP-0015-T03
status: done
priority: medium
state_hub_task_id: "64eb7652-3b67-4bfb-879b-8588deeec8b5"
state_hub_task_id: "4f885922-56c9-5d89-b7ab-e61c8d69d67a"
```
**Wire or delete `internal/adapters/tenantengine`.** The adapter is complete
@ -219,7 +219,7 @@ live-role policy must introduce the dependency explicitly.
id: FLEX-WP-0015-T04
status: cancel
priority: low
state_hub_task_id: "06432560-c28c-4de2-a672-87e74be54a6a"
state_hub_task_id: "1c05032a-bcae-5a4c-8f4a-c51b30a48807"
```
**AuthZEN evaluation endpoint (framework `A4`).** Deliberately deferred, not
@ -244,7 +244,7 @@ this task and may be worth doing first.
id: FLEX-WP-0015-T05
status: done
priority: medium
state_hub_task_id: "9195ba20-ab0f-4d75-b293-86978073beb1"
state_hub_task_id: "702e55bf-b87a-547d-9a2d-bc2ccfee9341"
```
**Guard the declaration.** Framework §12 requires verifying the declared

View file

@ -16,7 +16,7 @@ related_workplans:
- WARDEN-WP-0009
created: "2026-08-19"
updated: "2026-08-19"
state_hub_workstream_id: "5c0fac68-284d-4672-9824-8686a902d33f"
state_hub_workstream_id: "f29f159c-c79e-5c78-b1e8-569a5b63d231"
---
# FLEX-WP-0016 - In-cluster ops-warden policy pin so policy.enabled can flip
@ -60,7 +60,7 @@ flip wait on that calling side.
id: FLEX-WP-0016-T01
status: done
priority: high
state_hub_task_id: "3d7fde8e-00b1-4bc3-be28-00afd37997ac"
state_hub_task_id: "b2f8052e-3686-593f-9359-dfd08d530a26"
```
**Overlay pin.** Add `values/ops-warden.yaml`: same digest as the A2 pins,
@ -77,7 +77,7 @@ warn, isolated, production registry. `tests/stage1.sh` renders it.
id: FLEX-WP-0016-T02
status: done
priority: high
state_hub_task_id: "9f30410f-e2b3-4b0a-9d70-6f6a12d2822e"
state_hub_task_id: "aa65f534-7401-5231-ae82-ea6e3d09b40c"
```
**Deploy warn.** `helm upgrade --install flex-auth-ops-warden` from the
@ -97,7 +97,7 @@ user-engine and tenant-engine pins were not moved.
id: FLEX-WP-0016-T03
status: done
priority: medium
state_hub_task_id: "65df7141-58f0-4be8-bc62-07f29cb96856"
state_hub_task_id: "351f502f-f0cf-5a70-86da-10b1fbe39dae"
```
**Handoff for the flip.** Tell ops-warden the Service DNS, digest, warn mode,