flex-auth/workplans
tegwick d98323b2bb
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Build and Publish Container Image / build-and-push (push) Successful in 41s
fix(secrets-engine): v2 adds the tenant rule v1 never had
secrets-engine.catalog-lane.lifecycle v1 contained no reference to
input.tenant — not in well_formed, not in the denial ladder, not in a
test. A rotate on lane:glas-primary under tenant:coulomb returned allow
against the deployed package (decision:066e629bbf0c0924).

Found while answering glas-harness's tenant-alignment request, which had
asked for wrong-tenant denial evidence. There was none to return.

Three covers failed the same way: every one of the 29 fixtures carried
tenant:platform, so the suite could not report on the field; T02's own
gate named "wrong-tenant deny" and was recorded done unmet; and the
engine hashes tenant into request_digest but never compares it. Four
other published packages carry the branch — this one was the outlier.

v2 adds wrong_tenant above wrong_system, three Rego tests and three
fixtures (28/28, 32/32). The absent-tenant test caught a second defect
in the first draft: a bare input.tenant != comparison is undefined on a
missing key, so the branch dropped and the ladder reported the wrong
rung. request_tenant := object.get(input, "tenant", "") fixes it.

v2 supersedes rather than amends v1 because the defect failed open: a
consumer pinned to _VERSION=v1 would keep receiving allows with no
signal the rule beneath the version string had changed. The earlier
dual-control correction stayed at v1 because it denied everything.

Replay envelopes regenerated at v2; both request_digest values are
byte-identical, so secrets-engine's digest join needs no re-pinning.

The sweep this prompted found tenant-engine unscoped on tenant as well —
deployed, and verified allowing tenant:coulomb. Not the same fix: its
request tenant names the target rather than the caller, so a constant
would break it. Recorded and carried by FLEX-WP-0022 rather than patched
unilaterally.

FLEX-WP-0021 closes at T05; the pin still serves v1 until a redeploy.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aQMM1dPXaPiXVn6DwwtLd

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715613@bnt-lap001
Assistant-Session: fabd95c1-4c9e-4080-8849-8707ae025f80
2026-09-06 20:38:45 +02:00
..
FLEX-WP-0001-repo-intent-and-architecture-baseline.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0002-standalone-policy-as-code-core.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0003-markitect-consumer-integration.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0004-delegated-pdp-and-directory-adapters.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0005-foundations-and-topaz-alignment.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:25 +02:00
FLEX-WP-0006-ops-warden-ssh-signing-policy-gate.md FLEX-WP-0006: implement ops-warden signing gate policy 2026-06-23 21:17:42 +02:00
FLEX-WP-0007-ops-warden-policy-gate-production-deployment.md Close ops-warden policy gate deployment 2026-06-30 00:52:56 +02:00
FLEX-WP-0008-tenant-engine-consumer-integration.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0009-user-engine-production-policy-service.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0010-tenant-lifecycle-policy-actions.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0011-railiance-staged-promotion-overlay.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0012-credential-grant-authorization-surface.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0013-restore-seven-action-tenant-engine-pin.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0014-tenant-guardrail-policy-actions.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0015-tenancy-posture-conformance.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0016-ops-warden-incluster-policy-pin.md fix(workplans): adopt ADR-007 derived identifiers for unregistered records 2026-08-25 20:10:35 +02:00
FLEX-WP-0017-action-bound-authorization-contract.md Finish FLEX-WP-0017 2026-09-01 20:21:58 +02:00
FLEX-WP-0018-inbound-auth-corrections.md chore(registrar): assign State Hub identifiers 2026-08-23 13:21:43 +02:00
FLEX-WP-0019-layer-model-conformance.md Finish FLEX-WP-0019 layer-model v0.7 conformance 2026-09-03 23:48:45 +02:00
FLEX-WP-0020-repository-identity-migration.md chore(registrar): assign State Hub identifiers 2026-08-29 18:00:44 +02:00
FLEX-WP-0021-secrets-engine-consumer-policy-gate.md fix(secrets-engine): v2 adds the tenant rule v1 never had 2026-09-06 20:38:45 +02:00
FLEX-WP-0022-tenant-scope-coverage.md fix(secrets-engine): v2 adds the tenant rule v1 never had 2026-09-06 20:38:45 +02:00