Close FLEX-WP-0029 second edition; correct cadence.yaml; block human/external-gated workplans
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run

FLEX-WP-0029: publish the second stance-register edition across five rows
(a third scope axis, not a converging two — tenant-engine scopes on
engine-reachability, not security-zone), record Finding 1 as resolved by
gate-house doctrine rather than by either side, and note Finding 3 as still
open in secrets-engine's file. First edition marked superseded, not amended.
SCOPE.md's G3 gap closed accordingly.

FLEX-WP-0031: correct cadence.yaml to declare one heartbeat per rare
load-bearing class instead of a single combined class (tests pass unchanged).
Acknowledged audit-core's AUDIT-IN-0006 reply on T02 and recorded its
corrections; the remaining work (drain, reconciliation, PVC rollout, G2
closure) stays wait/blocked pending the founder's attended OpenBao mint and
gate-house's atomicity ruling, so the workplan moves to blocked.

FLEX-WP-0027: marked blocked — the sole remaining task needs the operator's
own signed-in account, an irreducible human action.

FLEX-WP-0020: recorded net-kingdom's T04 update (NK-WP-0039-T02 done,
runtime.yaml digests current) and replied with no objection to their
ADR-0015 values-pointer proposal for the drifted runtime.yaml reference.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: sonnet
Assistant-Process: 250108@bnt-lap001
Assistant-Session: bab3d5bd-b0bb-42d0-bf80-94ed6fc2b08a
This commit is contained in:
tegwick 2026-09-27 22:12:35 +02:00
parent f208c1da06
commit 92981698d8
8 changed files with 264 additions and 21 deletions

View file

@ -274,6 +274,22 @@ design and close on their side after T06; `flex-auth` owes each a
"rename landed" notice. Recorded in the evidence file. Seven owners remain
pending.
2026-09-27: `net-kingdom` confirmed `NK-WP-0039-T02` done (package coordinate
unchanged, pins stay, no other coordinate reference found) and `runtime.yaml`
now declares current tenant-engine/user-engine digests. `NK-WP-0039-T03` waits
only on flex-auth's announcement that `access-engine` resolves, i.e. it is
gated on T06 like the others. Separately, `net-kingdom` found
`sso-mfa/k8s/tenant-engine/runtime.yaml` live-ahead-of-file beyond digests
(missing `--caller-auth-mode enforce` and caller bindings) and proposed
replacing the flex-auth part of it with a pointer to `values/<consumer>.yaml`
per their `ADR-0015`; flex-auth replied with no objection, since that matches
the pattern flex-auth already uses for other consumers and points at a file
that actually tracks caller-auth state. Six owners now confirmed acknowledged
or resolved on their side; the remainder is still tracked in the evidence
file. This does not change T04's own gate — the external ownership ledger
still requires every discovered change to land its own owning-repository
handoff before T05/T06.
Reviewed inventory baseline:
| Owner | Required source/verification surface |

View file

@ -4,12 +4,12 @@ type: workplan
title: "Admit scoped human review for the three T03 actions"
domain: infotech
repo: flex-auth
status: active
status: blocked
flavor: implementation
owner: codex
topic_slug: netkingdom
created: "2026-09-14"
updated: "2026-09-14"
updated: "2026-09-27"
state_hub_workstream_id: "954635b2-8377-5227-ab4f-10607b2a02c6"
---
@ -52,3 +52,8 @@ state_hub_task_id: "9417d64a-308c-566f-af29-217c5c45d294"
Wait for the operator's exact signed-in account, then address the three memos
and verify actual human acknowledgements/entries. Synthetic policy checks are
not acceptance evidence. SECRETS-WP-0010-T03 retains live consume and execution.
2026-09-27: no operator sign-in has occurred yet. This is the only remaining
task and it is irreducibly a human action (the operator's own signed-in
account exercising the review), so the workplan is marked `blocked` rather
than `active` until that happens.

View file

@ -4,7 +4,7 @@ type: workplan
title: "The stance register outgrew the review that read it: five rows, and the divergence was ruled rather than resolved"
domain: infotech
repo: flex-auth
status: ready
status: finished
flavor: review
owner: claude
topic_slug: netkingdom
@ -13,7 +13,7 @@ planning_order: 290
related_workplans:
- FLEX-WP-0019
created: "2026-09-20"
updated: "2026-09-20"
updated: "2026-09-27"
state_hub_workstream_id: "5a11099d-b492-535c-af88-c334db5e8ee6"
---
@ -54,11 +54,15 @@ reviewer's reading of the rows in it, and the second edition must keep saying so
```task
id: FLEX-WP-0029-T01
status: todo
status: done
priority: high
state_hub_task_id: "5a7ed269-974f-5c6a-8e80-e9aa0077f8aa"
```
Done 2026-09-27: recorded in `docs/stance-register-review-second-edition.md`
Finding 1. Verified against `ops-warden/pep-stance.yaml` that the cell is
unflipped by deliberate assent (0 of 3 signing targets resolve to a zone).
Owner: `flex-auth`.
v0.8 §6.4 obligation 3 states that **`unknown` is not a zone and MUST resolve to
@ -91,11 +95,19 @@ it. No claim that flex-auth's review produced the rule.
```task
id: FLEX-WP-0029-T02
status: todo
status: done
priority: high
state_hub_task_id: "991ebb94-cdc4-574a-ba60-f8960ec885fc"
```
Done 2026-09-27: recorded in the second edition's Finding 2. Reading all five
files directly (not the draft table above) found **three** distinct scope
axes, not two converging to one — `tenant-engine` scopes on
`engine-reachability`, not `security-zone` as assumed here. The alarm
sharpens rather than weakens. `ops-mason`'s absent row judged the more costly
of the two problems: an axis mismatch is at least visible, an absent map is
not even reviewable.
Owner: `flex-auth`.
Finding 2 said the register cannot answer *"what is the estate's stance for a
@ -127,11 +139,15 @@ from the two-row text.
```task
id: FLEX-WP-0029-T03
status: todo
status: done
priority: medium
state_hub_task_id: "6dd2c9fd-8ad9-54d6-8fb1-f24e44189f00"
```
Done 2026-09-27: read `secrets-engine/pep-stance.yaml` directly. It still
cites `ActionAuthorization` (line 35). Recorded in the second edition as an
open item, not re-reported as new and not claimed resolved.
Owner: `flex-auth` to verify; `secrets-engine` owns the file.
Finding 3 reported that `secrets-engine`'s `pep-stance.yaml` defines
@ -151,11 +167,19 @@ reply.
```task
id: FLEX-WP-0029-T04
status: todo
status: done
priority: medium
state_hub_task_id: "4dbadd0b-7670-5837-90c9-6201c10479d7"
```
Done 2026-09-27: `SCOPE.md` already stated five rows accurately (its own G3
row was the only stale sentence, now updated below); no rewrite was needed
there. `INTENT.md` carries no `standard_version` field at all, so the
premise that it declares `"0.7"` was itself stale — nothing was bumped, and
this is noted in the second edition rather than silently corrected. The
first edition is not in `SCOPE.md`'s capability blocks, so no capability was
invented for the second.
Owner: `flex-auth`.
- `SCOPE.md` says §13.1's register *"now has **two rows** rather than the one the

View file

@ -4,7 +4,7 @@ type: workplan
title: "The decision record has a declared emission guarantee and nothing that delivers it"
domain: infotech
repo: flex-auth
status: active
status: blocked
flavor: implementation
owner: claude
topic_slug: netkingdom
@ -14,7 +14,7 @@ related_workplans:
- FLEX-WP-0030
- FLEX-WP-0019
created: "2026-09-21"
updated: "2026-09-23"
updated: "2026-09-27"
state_hub_workstream_id: "84f5d9fe-b4c9-584a-b964-efe3e48af095"
---
@ -82,6 +82,25 @@ which `senders.py` forbids for a load-bearing source. warden route has no
catalog lane for audit-core sender tokens, and audit-core was asked to name one.
Waiting on audit-core.
2026-09-27: audit-core replied (`AUDIT-IN-0006`, thread `6044ed35`), accepted
with corrections: `may_read` must be `false`, not `true` (a writer already
counts its own sources without it); `tenants: ["*"]` accepted on the stated
justification; per-class heartbeats and the `cadence.yaml` correction accepted
(done, see T05); each registration must also carry an `emission_cadence`
declaration (info-tech-canon wire schema 0.1, contract digest
`b08b4d95fc4b0bd3`) with `allow` as expected-rate, or its rate is only
declared and not evaluated. Two envelope corrections land before submission:
the heartbeat event needs its own `correlation_id` (no decision id exists for
it), and `occurred_at` needs an explicit offset. The atomicity ruling
(whether the `FLEX-DEC-2026-018` failure-path release is a `completeness_trade`)
is referred to `gate-house` by audit-core, not decided here — flex-auth agreed
in reply to wait for that referral. The token lane is an attended OpenBao mint
in the founder's terminal (same path `tenant-engine` used,
`AUDIT-WP-0010-T02`); `ops-warden` has no catalog lane for it yet and will add
one when registration opens. flex-auth acknowledged all of this in reply.
Still `wait`: the mint needs the founder, and `ops-warden`'s catalog entry is
not yet in place.
## 3. Durable outbox and the release rule
```task
@ -118,11 +137,19 @@ Done 2026-09-23:
```task
id: FLEX-WP-0031-T05
status: todo
status: wait
priority: high
state_hub_task_id: "14bd6648-11da-53d7-a512-027005bd4772"
```
2026-09-27: `cadence.yaml`'s heartbeat declaration corrected — it now names one
class per rare load-bearing event (`deny`, `redact`, `not_applicable`,
`audit_only`) instead of a single combined `flex-auth.decision.heartbeat`
class. `go build`/`go test ./...` pass unchanged. The remaining scope — the
actual per-class heartbeat sender and the drain to `POST /v1/events` — is
correctly blocked on T02's sender registration with `audit-core`; the task
stays `wait` rather than in progress here.
- Emit a daily `audit-core.heartbeat` event per rare class, with `data.class`
set to the class, following audit-core's `stream_findings` shape.
- Correct `cadence.yaml`, which still names a single
@ -136,11 +163,21 @@ state_hub_task_id: "14bd6648-11da-53d7-a512-027005bd4772"
```task
id: FLEX-WP-0031-T06
status: todo
status: wait
priority: high
state_hub_task_id: "bf92a951-3b69-59dd-8907-f6748c91a264"
```
2026-09-27: reconciliation compare needs `audit-core`'s `GET /v1/reconciliation`,
which does not exist until T02's sender is registered. The profile checker
(`net-kingdom/tools/emission-cadence-profile`) is runnable locally but needs a
`--contract-schema` for the decision-record cadence contract that is not yet
published in this repo or referenced by any sibling's invocation found —
inventing one here would be exactly the kind of schema flex-auth should
publish deliberately, not improvise for a validation run. The PVC chart change
is explicitly a production change needing the founder's go-ahead and was left
undone. Stays `wait`.
- Compare committed counts per class and window with audit-core's
`GET /v1/reconciliation`. Divergence is a finding, and undrained events count
as lag, not divergence.
@ -154,11 +191,15 @@ state_hub_task_id: "bf92a951-3b69-59dd-8907-f6748c91a264"
```task
id: FLEX-WP-0031-T04
status: todo
status: wait
priority: medium
state_hub_task_id: "423b3090-1b72-58fd-9353-5c907c7683bb"
```
2026-09-27: closing G2 requires the silence-finding gate, which requires T05's
sender and T06's reconciliation to actually exist. Both are blocked on T02
(external, `audit-core`). Stays `wait`.
Change `cadence.yaml` `state` to emitting, move G2 out of the gap table with the
evidence, and tell `gate-house`, `audit-core` and `kings-guard`. Gate: a silence
finding is observed on a deliberately withheld heartbeat in a non-production