Create private evidence directories safely on fsGroup volumes

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-11 12:41:04 +02:00
parent bda9381f07
commit 1a12223574
5 changed files with 57 additions and 2 deletions

View file

@ -45,6 +45,11 @@ actual Flex Auth, Approval Engine and Audit Core with synthetic identity/custody
writer, backup/inspection commands and eight review-only Kubernetes objects.
Network-isolated container restart/restore preserves unresolved submissions.
The 2026-09-11 fsGroup startup correction handles newly created private
directories on Kubernetes volumes; unsafe existing directories still refuse.
Its full local suite passes 335 tests with 39 optional checks skipped. The
earlier local image must be rebuilt with this correction before publication.
Remaining: native policy package/caller/assignment admission, registered human
login and deployed binding, independent production audit custody, image
publication/cutover, platform backup/restore and operator recovery admission.