flex-auth/workplans
tegwick c3ede0b494
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Review the stance register's second row; record why T04 cannot proceed
TWO FINDINGS, BOTH FROM READING OTHER REPOSITORIES RATHER THAN OURS.

The §13.1 stance register has a second row. secrets-engine published
pep-stance.yaml -- total over catalog stage plus unknown, runtime-read
and pinned to SHIPPED_STANCE by test. SCOPE.md claimed ops-warden's was
the estate's only published map and that the register's single row was
itself the finding; that is no longer true and is corrected.

docs/stance-register-review.md is the first exercise of the
aggregate-divergence capability flex-auth claimed on 2026-08-29 and then
recorded as unexercised because one row cannot diverge from anything.
Three findings:

The two maps take opposite stances on unknown -- ops-warden fail_open by
versioned build profile under ADR-0009, secrets-engine fail_closed. Both
conformant, neither a defect, and they disagree about the one case nobody
planned for. Reported as an observation for gate-house's register, not as
a request that either repository change: a PDP does not set a consumer's
stance, and §9.3's two-owner split is our own finding.

The rows are not comparable. ops-warden scopes by security-zone,
secrets-engine by catalog-stage. §6.4 permits both, but the register
cannot then answer what the estate's stance is for a z2 workload. Worth
recording before a third row arrives.

secrets-engine's map defines fail_closed in terms of a durable
ActionAuthorization record, which GH-DEC-2026-005 shelved. The stance is
unaffected -- only the artifact name is stale -- but the file is read at
runtime and pinned by test, so the stale name outlives a comment.

SEPARATELY, T04 IS BLOCKED AND THE REASON IS STRUCTURAL. The task assumed
the ops-warden/tenant-engine/user-engine pattern, where the pin's
default-deny NetworkPolicy admits one approved consumer workload.
secrets-engine has no Kubernetes deployment at all -- it is a CLI. There
is no pod selector to write, and inventing one would repeat the error
corrected in T02. Three possible shapes recorded in the workplan and
raised with them; callerAuth, not the NetworkPolicy, becomes the real
boundary if an operator CLI is the caller, so the FLEX-WP-0016 precedent
does not transfer unexamined.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JTbVXpEiXA7mNJVpDnEPcB

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 412054@bnt-lap001
Assistant-Session: 3968fae1-8d59-4209-9bd6-c22594b8ab19
2026-09-06 09:31:40 +02:00
..
FLEX-WP-0001-repo-intent-and-architecture-baseline.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0002-standalone-policy-as-code-core.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0003-markitect-consumer-integration.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0004-delegated-pdp-and-directory-adapters.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0005-foundations-and-topaz-alignment.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md FLEX-WP-0006: implement ops-warden signing gate policy 2026-06-23 21:17:42 +02:00
FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md Close ops-warden policy gate deployment 2026-06-30 00:52:56 +02:00
FLEX-WP-0008-tenant-engine-consumer-integration.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0009-user-engine-production-policy-service.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0010-tenant-lifecycle-policy-actions.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0011-railiance-staged-promotion-overlay.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0012-credential-grant-authorization-surface.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0014-tenant-guardrail-policy-actions.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0015-tenancy-posture-conformance.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0016-ops-warden-incluster-policy-pin.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0017-action-bound-authorization-contract.md Finish FLEX-WP-0017 2026-09-01 20:21:58 +02:00
FLEX-WP-0018-inbound-auth-corrections.md chore(registrar): assign State Hub identifiers 2026-08-23 13:21:43 +02:00
FLEX-WP-0019-layer-model-conformance.md Finish FLEX-WP-0019 layer-model v0.7 conformance 2026-09-03 23:48:45 +02:00
FLEX-WP-0020-repository-identity-migration.md chore(registrar): assign State Hub identifiers 2026-08-29 18:00:44 +02:00
FLEX-WP-0021-secrets-engine-consumer-policy-gate.md Review the stance register's second row; record why T04 cannot proceed 2026-09-06 09:31:40 +02:00