Record owner replies and verified policy v2 rollout
All checks were successful
ci / validate (push) Successful in 3m29s
All checks were successful
ci / validate (push) Successful in 3m29s
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0726e-5232-73f2-aaca-2c05ceb62efb
This commit is contained in:
parent
f3cdee14cb
commit
59b042e637
6 changed files with 129 additions and 6 deletions
|
|
@ -9,11 +9,12 @@ No credential values belong in responses.
|
|||
|
||||
## Ready infrastructure
|
||||
|
||||
FLEX-WP-0021-T04 deployed flex-auth-secrets-engine revision 1, available 1/1,
|
||||
with five policy fixtures and positive/negative network probes passing.
|
||||
FLEX-WP-0021-T04 deployment now serves flex-auth-secrets-engine revision 2, available 1/1,
|
||||
with six live policy fixtures passing. Positive/negative network probes passed
|
||||
at revision 1; revision 2 retains the same ingress policy.
|
||||
Endpoint: http://flex-auth-secrets-engine.flex-auth.svc.cluster.local:8080.
|
||||
Package: secrets-engine.catalog-lane.lifecycle v1.
|
||||
Image: sha256:89086c02c74a931068423e70937d03df7850fa0db9c63e70be56b3558f1756af.
|
||||
Package: secrets-engine.catalog-lane.lifecycle v2.
|
||||
Image: sha256:db1c4f7e621c7ea119489a321d7db0e05da09afc17be5f69d873b2b3c7f60cfc.
|
||||
Caller-auth is warn. Direct cluster ingress requires namespace secrets-engine
|
||||
and pod label app.kubernetes.io/name=secrets-engine. A workstation process needs
|
||||
an explicitly supported owner access path; Service DNS is not workstation
|
||||
|
|
@ -133,3 +134,19 @@ read access to glas-harness for this packet and the acceptance contract.
|
|||
Sand-boxer also needs rein-aharness as a sibling for runtime packaging/startup.
|
||||
KeyCape/custody/audit preparation and approval-image/runtime preparation can
|
||||
proceed in parallel; final native activation follows the verified prerequisites.
|
||||
|
||||
## Owner returns reviewed — 2026-09-06
|
||||
|
||||
Six acknowledgements received: key-cape, audit-core, approval-engine,
|
||||
secrets-engine, flex-auth and sand-boxer. railiance-platform has not returned
|
||||
a reply in this review. See GLAS-WP-0015 for the receipt summary.
|
||||
|
||||
- v1 lacked tenant enforcement; v2 is now live with wrong_tenant denial.
|
||||
- Tenant values remain incompatible, with no authorized mapping. Operator
|
||||
choice requested before changing registration/store semantics.
|
||||
- Workstation caller access remains open even though FLEX-WP-0021-T05 was
|
||||
marked done; service coordinates are insufficient for the actual consumer.
|
||||
- AUDIT-WP-0009-T03 must precede T09 so load-bearing evidence is represented.
|
||||
- sand-boxer 23d0c2b resolves the exact project as glas-local-proof; its
|
||||
profile.claude-agent-dev-proof v1.1.0 is a source candidate, not a deployed
|
||||
combined runtime. Claude executable pin/startup remains outstanding.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue