Reconcile infrastructure workplans and retire stale flex-auth references

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
tegwick 2026-09-28 12:40:03 +02:00
parent 019e8f21a7
commit 9383b94019
12 changed files with 494 additions and 149 deletions

View file

@ -10,7 +10,7 @@ owner: codex
topic_slug: netkingdom
planning_priority: P1
created: "2026-08-23"
updated: "2026-08-23"
updated: "2026-09-28"
state_hub_workstream_id: "9d7b04f9-3803-5613-b7a5-8bd606c77f5a"
---
@ -116,3 +116,20 @@ Verification on 2026-08-23:
Local implementation is complete. The workplan remains blocked only on T04's
externally owned audit-core declaration adoption.
## Infrastructure review — 2026-09-28
`audit-core/tenancy.yaml` still lacks machine-readable authoritative owner
and E2 freshness metadata. Its E2 prose retains the August 22 receipt and
24-hour replacement deadline; report freshness as `unknown` until the required
fields exist, without renewing that evidence from prose. The September 24
receiver/database recreate evidence supports V1 only and cannot refresh E2.
T04 remains `wait`; request the source declaration update and evaluate it with
an explicit current `--as-of` before closure.
The same declaration still describes flex-auth as unauthenticated A0, whereas
today all six live flex-auth Deployments pass `--caller-auth-mode enforce`.
The audit-core owner should reconcile that rationale against actual caller
bindings and policy evidence; deployment flags alone do not prove a new A level.
Evidence and cross-plan priorities: [estate review](../history/2026-09-28-open-workplan-infrastructure-review.md).