flex-auth/workplans
tegwick 6a6464fcc9
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 1s
Answer ops-warden and secrets-engine; open FLEX-WP-0021
Two cross-repo questions arrived in the flex-auth inbox and both are
answered as decision records rather than as prose in a message.

FLEX-DEC-2026-004 answers ops-warden WARDEN-WP-0034-T05. A decision
lifetime shorter than the SSH certificate TTL is meaningful, but only as
authority to issue, never as authority to use an already-issued
certificate. The pre-sign gate is the only consumer of the shorter
lifetime: no replay past expires_at, fresh Check per sign. The lever that
shortens effective access is the requested TTL as a policy input, which
is already deployed as the ttl_out_of_bounds deny. ops-warden's section
9.7.2 window through certificate TTL is correct as written and correctly
owned by the PEP; flex-auth does not want that residue moved to the PDP.

docs/decision-input-freshness.md gains the same boundary as published
contract text, so the ruling is not only in the decision log.

FLEX-DEC-2026-005 answers secrets-engine. A real policy package is
expected and flex-auth authors it here as it does for every consumer; the
reserved coordinate is secrets-engine.catalog-lane.lifecycle v1 and it
does not exist yet. Their choice not to default the pin was correct and
is endorsed explicitly. POST /v1/check is deployed but has no
estate-wide address by design -- per-consumer cluster-local pins with
default-deny ingress -- so their 2026-09-06 probe found the design
working, not an outage.

FLEX-WP-0021 carries that work: obtain the real action vocabulary from
secrets-engine, publish the package with fixtures, confirm the digest
join against a real decision record, then stand up a
flex-auth-secrets-engine pin in warn without moving the other two pins.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JTbVXpEiXA7mNJVpDnEPcB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 412054@bnt-lap001
Assistant-Session: 3968fae1-8d59-4209-9bd6-c22594b8ab19
2026-09-06 01:12:50 +02:00
..
FLEX-WP-0001-repo-intent-and-architecture-baseline.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0002-standalone-policy-as-code-core.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0003-markitect-consumer-integration.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0004-delegated-pdp-and-directory-adapters.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0005-foundations-and-topaz-alignment.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md FLEX-WP-0006: implement ops-warden signing gate policy 2026-06-23 21:17:42 +02:00
FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md Close ops-warden policy gate deployment 2026-06-30 00:52:56 +02:00
FLEX-WP-0008-tenant-engine-consumer-integration.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0009-user-engine-production-policy-service.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0010-tenant-lifecycle-policy-actions.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0011-railiance-staged-promotion-overlay.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0012-credential-grant-authorization-surface.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0014-tenant-guardrail-policy-actions.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0015-tenancy-posture-conformance.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0016-ops-warden-incluster-policy-pin.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0017-action-bound-authorization-contract.md Finish FLEX-WP-0017 2026-09-01 20:21:58 +02:00
FLEX-WP-0018-inbound-auth-corrections.md chore(registrar): assign State Hub identifiers 2026-08-23 13:21:43 +02:00
FLEX-WP-0019-layer-model-conformance.md Finish FLEX-WP-0019 layer-model v0.7 conformance 2026-09-03 23:48:45 +02:00
FLEX-WP-0020-repository-identity-migration.md chore(registrar): assign State Hub identifiers 2026-08-29 18:00:44 +02:00
FLEX-WP-0021-secrets-engine-consumer-policy-gate.md Answer ops-warden and secrets-engine; open FLEX-WP-0021 2026-09-06 01:12:50 +02:00